31
23.7 Legacy Series / Re: IPV6 BGP Wireguard Link Local Issue/Error
« on: September 21, 2023, 11:50:56 pm »
either way, how/where do I get it to add the Link Local to any WG interface? Its not static ipv6 and add it there as thats the GUA address for the interface not the LL one. In local i have disable routes set, and in Allowed IPs (endpoints) i have ::/0 as its going to be all and then whatever BGP routes get added into the route table will work.
I may try adding a LL on the local side under wg tunnel address as you recommend , on each instance near and far opnsense's and see what happens. This works perfectly with V4 as it doenst need LL for V4
If this works cool, but doing this manually sucks as shouldnt each interface automatically get a LL address?
This is what it looks like now,
wg3: flags=80c1<UP,RUNNING,NOARP,MULTICAST> metric 0 mtu 1420
options=80000<LINKSTATE>
inet6 xxxx:xxxx:xxxx::xx prefixlen 126
groups: wg wireguard
nd6 options=101<PERFORMNUD,NO_DAD>
other IPSEC interfaces show nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
thinking maybe thats the issue, dont know where to set it in the config to make that change for WG
Basically trying to do VTI but in WG not IPSEC with BGP providing the routes not the tunnel or static routes.
I may try adding a LL on the local side under wg tunnel address as you recommend , on each instance near and far opnsense's and see what happens. This works perfectly with V4 as it doenst need LL for V4
If this works cool, but doing this manually sucks as shouldnt each interface automatically get a LL address?
This is what it looks like now,
wg3: flags=80c1<UP,RUNNING,NOARP,MULTICAST> metric 0 mtu 1420
options=80000<LINKSTATE>
inet6 xxxx:xxxx:xxxx::xx prefixlen 126
groups: wg wireguard
nd6 options=101<PERFORMNUD,NO_DAD>
other IPSEC interfaces show nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
thinking maybe thats the issue, dont know where to set it in the config to make that change for WG
Basically trying to do VTI but in WG not IPSEC with BGP providing the routes not the tunnel or static routes.