I wish (Linux) WireGuard had a simple way to restrict peer public IPs
utcc.utoronto.ca
utcc.utoronto.ca
Right. So you want to put in IP filtering on top of that, having already had a compromised connection?
The biggest issue I have with wireguard is the tendancy for clients to actually show the private key. It shouldn't generally be visible, there's no needs.
But I think it'd probably be better to alert the administrator rather than simply blocking them.
I'm no expert in Wireguard other than setting it up for personal use at home, so don't quite know more advanced configurations, but this seems like a separate issue relatively easily handled. That said, for my own use case, I wouldn't want to restrict IPs beyond maybe nation restrictions as I expect to connect from untrusted locations.
It sounds like they want the system to somehow know which IP is supposed to be associated with a particular key.
You already can restrict public IPs using iptables…
I wouldn’t lose sleep over not having that. It’d be a nice bonus though.
Say you have a WG server on a VPS that your laptop and your Plex server connect to. Your laptop should be allowed to connect anywhere, but you should be suspicious if your Plex server connects from anywhere other than your home address.
You're probably familiar with this feature if you've ever used MySQL, users have a username and host spec.
At first, I thought this sounded like a bug, but actually reading the documentation [1] it's clearly as-designed. It's referred to as "initial configuration" (their italics) and then explains how it updates.
I see there's an official mailing list for wireguard. Perhaps he should suggest a new feature there to disable that roaming functionality.
[1] https://www.wireguard.com/ in the "Built-in Roaming" section
Other than having an interface per peer of course.
Eg: my SQL server has one WG and I've got N clients. They are each connecting with their key and assigned IP. So firewall rules will do it.
If routing was possible with just the public key, after wg has verified the packets, I would assume it'd be easier to maintain (and more flexible).
For example, I could run a "public" wg peer where peers could just join me without me messing with cidrs and whatnot. I wouldn't care what their vpn ip is, as I may not be their only peer and they could be using any number of internal addressess.
Obviously inside the tunnel that's what the source IP is for.