____________________________________________________________________| || |---------------- Internal Clients || | | | | | ------- ISP Router-------------------- OPNsense Box-----VPN Clients | | | | | | | | |----------------- DNS & Server || ||____________________________________________________________________
interface: wg0 public key: (hidden) private key: (hidden) listening port: 51820peer: (hidden) endpoint: ip:55916 allowed ips: 10.0.10.4/32 latest handshake: 32 seconds ago transfer: 76.46 KiB received, 78.96 KiB sentpeer: (hidden) endpoint: ip:8886 allowed ips: 10.0.10.2/32, fd01::10/128 latest handshake: 1 minute, 55 seconds ago transfer: 235.91 KiB received, 2.03 MiB sentpeer: (hidden) endpoint: ip:34636 allowed ips: 10.0.10.3/32, fd01::30/128 latest handshake: 4 minutes, 51 seconds ago transfer: 213.72 KiB received, 1.31 MiB sent
[Interface]Address = 10.0.10.2/24, fd01::10/64PrivateKey = [mobile.seckey]DNS = 192.168.178.2, fd00::2[Peer]PublicKey = [vpn-server.pubkey]PresharedKey = [vpn.psk] AllowedIPs = 0.0.0.0/0, ::/0Endpoint = endpoint_domain:51820
peer: (hidden) endpoint: ip:8886 allowed ips: 10.0.10.2/32, fd01::10/128 latest handshake: 1 minute, 55 seconds ago transfer: 235.91 KiB received, 2.03 MiB sentpeer: (hidden) endpoint: ip:34636 allowed ips: 10.0.10.3/32, fd01::30/128 latest handshake: 4 minutes, 51 seconds ago transfer: 213.72 KiB received, 1.31 MiB sent
The favouring of the ULA over the GUA has also popped up in other contexts, eg diagnostics tools. Franco is looking at that, although I am not sure whether in the outbound NAT context
Is there a good reason, wireguard does not allow DHCP?