fix: include selected networks in dataplane NAT

This commit is contained in:
thakares committed 2026-09-01 18:21:58 +05:30
1 parent 5599e1b5c8
commit 34227efd2b
10 files changed
+545 -54

No files matched your search

+1 -1
View File
@@ -53,7 +53,7 @@ The `port_range` field supports three RFC-compliant formats:
NAT masquerading is governed by key-value appliance settings in SQLite:
- **`enable_nat`**: Boolean string (`"true"` / `"false"`). When enabled, all active managed WireGuard subnets are masqueraded outbound to the host WAN interface.
- **Dynamic Subnet Calculation**: The reconciliation engine queries all enabled interfaces (`Interface.address_v4`) and generates dedicated masquerade rules for each unique subnet.
- **Dynamic Subnet Calculation**: The reconciliation engine queries enabled Interface address CIDRs and enabled Subnet Network CIDRs, then generates dedicated masquerade rules for each unique subnet. Interface addresses remain the WireGuard transport identity; Network CIDRs are the peer allocation domains.
---