passtos patch

Matthias Urlichs matthias at urlichs.de
Thu Jan 18 14:03:56 CET 2018


On 18.01.2018 12:56, Kalin KOZHUHAROV wrote:
> a workaround would be to bunch a
> few wg tunnels (even bridge them at both ends?), use fwmark and mangle
> the TOS with iptables/ift...

So instead of outside information being visible by way of the TOS field
it's now visible by way of different UDP ports we're talking to.

I don't see any advantage here.

In fact I don't see much advantage of passing TOS out in the first
place. Either you have a reliable transit network with short queues, or
you don't. In the former case TOS is useless. In the latter case you
have other problems which a TOS field cannot fix anyway. (OK, this is a
bit more black+white than the Real World, but …)

-- 
-- Matthias Urlichs



More information about the WireGuard mailing list