Dwgd: Docker WireGuard Driver
github.com
github.com
In order to have the client use the VPN but keep the rest of the system accessible outside the VPN I bind the client IP (VPN IP4 & IP6) in the client config and have WireGuard setup like this:
[Interface]
PrivateKey =
Address = IP4, IP6
DNS =
Table = 12345
PostUp = ip -4 rule add from IP4 table 12345
PostUp = ip -6 rule add from IP6 table 12345
PostUp = iptables -I OUTPUT -s IP4 ! -o %i -j DROP
PostUp = ip6tables -I OUTPUT -s IP6 ! -o %i -j DROP
PostDown = ip -4 rule del from IP4 table 12345
PostDown = ip -6 rule del from IP6 table 12345
PostDown = iptables -D OUTPUT -s IP4 ! -o %i -j DROP
PostDown = ip6tables -D OUTPUT -s IP6 ! -o %i -j DROP
[Peer]
PublicKey =
Endpoint =
AllowedIPs = 0.0.0.0/0, ::/0I can WireGuard to my server and access my home network, meanwhile the torrent client data is all routed through a third party VPN.
If the third party VPN disconnects there is no data leak from the torrent client (basically a kill switch).
if it's public, it's in production somewhere.
I think, right now, with something like mitmproxy, for example, you can't use the wireguard mode unless the other proxy is "elsewhere." With this, perhaps you could use it from the same machine?
[0] https://github.com/qdm12/gluetun/wiki/Wireguard#performance