JonathanCasey / mullvad-ubuntu

My Mullvad config; using wireguard, network namespaces and libpam-net
0 stars 0 forks source link

Still route local traffic? #7

Open JonathanCasey opened 3 years ago

JonathanCasey commented 3 years ago

It would be convenient if LAN traffic could still work unchanged. On quick test, there were some issues with the existing setup.

This should be reviewed if actually a problem, how to fix it, and whether this makes an unreasonable risks / leaks.

JonathanCasey commented 3 years ago

Not addressing further than #11 at this time -- it is covering my immediate needs, and need a lot more thought put in before opening up the further risks this could create.

Probably just need iptable routing for a given LAN subnet, but want to exclude router to avoid DNS leaks maybe? Don't really know.

Also could maybe review other existing vpn setups as allowing LAN is a common feature (and does seem to be based on IP addresses, as IP address work, but local net name resolution does not).