I know its very minor, but are there ergonomic improvements possible to this setup besides shell aliases/functions around pairing `wg-up host && ssh host && wg-down host`?
I agree that ultimately, with wg in the kernel, this is a much simpler setup.
I agree that ultimately, with wg in the kernel, this is a much simpler setup.
This is why you sometimes have to enable PersistentKeepalive on peers that are behind NAT and are calling in to the server. Without them keeping up the connection NAT would simply close it down and you wouldn't be able to connect.
IOW, why ever down the connection? Why not start your tunnel immediately when the network comes up and leave it running until the network goes down?
Wireguard interfaces are _cheap and easy_ - there's no reason not to set up an interface for normal client traffic that sshd doesn't listen on, and an interface for just sshd with different ACLs and routing logic if you want.