Routing to a network behind a node

M. Dietrich mdt at emdete.de
Sat Sep 8 11:06:33 CEST 2018


Hi,

i have setup a wg vpn with several nodes, lets say in a
network 172.16.215.0/24. one of the boxes (ip 172.16.215.2) in
that network has an interface to a different network with
additional boxes, lets say 172.16.0.0/24. i would like to
reach the boxes in that network directly so i established a
route on another node in the wg network (172.16.215.1) like
this:

	ip route add 172.16.0.0/24 via 172.16.215.2

but once i ping 172.16.0.1 i get the error

	From 172.16.215.1 icmp_seq=1 Destination Host Unreachable
	ping: sendmsg: Required key not available

it seems the package reaches wireguard but wireguard doesnt
know the "via" and tells it has no key to route to 172.16.0.1
which is fine. but why doesn wg honour the via and send it to
the router 172.16.215.2?

i think its more or less whats done if you route all your
traffic through wg so i assume i do a terrible stupid mistake
(i am no network or kernel routing expert which may be an
excuse), can someone help?

best regards,
M. Dietrich
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.zx2c4.com/pipermail/wireguard/attachments/20180908/6300c49b/attachment-0001.asc>


More information about the WireGuard mailing list