https://netmaker.org logo
Netclient Overwriting AllowedIPs
# client
a
I have a ingress & egress setup on the same node for an ext client to route all traffic to the netclient node (full tunnel VPN). I would like to access routes behind the ext client and set a custom iptables rule for the interface. I'm currently manually editing the wireguard config, performing
wg-quick down/up
. Netclient eventually overwrites all changes when it pulls the config. Is there a way to prevent this?
Or is there a way to set AllowedIPs to ext clients from a netclient generated config. "Overwriting" would just be manually creating a wireguard network I guess. I do want to try and use Netmaker for it at least.
j
> Netclient eventually overwrites all changes when it pulls the config. Is there a way to prevent this?
Netclient is overwriting the ext client config?
a
No, on the egress node. Ext client is on OPNsense. I have 10.100.0.0/16 behind OPNsense that I want to expose through the egress node. On the egress, i add 10.100.0.0/16 to AllowedIPs of the peer (OPNsense) manually. This is eventually overwritten by netclient when it pulls. Is there somewhere in Netmaker I can set AllowedIPs for ext client peers?
j
not currently no; we'll allow editing ext client settings in about a month
you can add arbitrary AllowedIPs to a node, but i dont think that helps you
a
I figured. Good to see it's in the works though. Thanks!
3 Views