fix: include selected networks in dataplane NAT
This commit is contained in:
1 parent
5599e1b5c8
commit
34227efd2b
10 files changed
+545
-54
No files matched your search
@@ -53,7 +53,7 @@ The `port_range` field supports three RFC-compliant formats:
|
||||
NAT masquerading is governed by key-value appliance settings in SQLite:
|
||||
|
||||
- **`enable_nat`**: Boolean string (`"true"` / `"false"`). When enabled, all active managed WireGuard subnets are masqueraded outbound to the host WAN interface.
|
||||
- **Dynamic Subnet Calculation**: The reconciliation engine queries all enabled interfaces (`Interface.address_v4`) and generates dedicated masquerade rules for each unique subnet.
|
||||
- **Dynamic Subnet Calculation**: The reconciliation engine queries enabled Interface address CIDRs and enabled Subnet Network CIDRs, then generates dedicated masquerade rules for each unique subnet. Interface addresses remain the WireGuard transport identity; Network CIDRs are the peer allocation domains.
|
||||
|
||||
---
|
||||
|
||||
|
||||
+2
-1
@@ -66,8 +66,9 @@ table inet nx9_wg {
|
||||
|
||||
Outbound NAT masquerading is dynamically scoped exclusively to managed WireGuard client subnets:
|
||||
1. **Subnet Deduplication**: Overlapping subnets are merged to prevent redundant rules.
|
||||
2. **Interface Exclusion**: Traffic routing back into the WireGuard interface (`oifname != "wg0"`) is not masqueraded to preserve true source IPs for site-to-site tunnels.
|
||||
2. **Interface Exclusion**: Traffic routing back into the WireGuard interface (`oifname != "wg*"`) is not masqueraded to preserve true source IPs for site-to-site tunnels.
|
||||
3. **No Catch-All Masquerade**: `nx9-wg` never creates a catch-all `masquerade` rule that affects non-WireGuard traffic on the host.
|
||||
4. **Interface and Subnet Network CIDRs**: Masquerade sources include each enabled Interface address CIDR and each enabled Subnet Network CIDR. A peer allocated from a selected Network (for example outside the WireGuard interface `/24`) is masqueraded from that Network CIDR; the Interface address itself is unchanged.
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in new issue
Block a user