From 22b9a7ca01eb508dcfdc7493c7c6191afa9bbf58 Mon Sep 17 00:00:00 2001 From: Kjetil Orbekk Date: Sat, 7 Oct 2023 16:30:56 -0400 Subject: drop fwmark for wireguard --- modules/router.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/modules/router.nix b/modules/router.nix index 29de644..d7cc3a0 100644 --- a/modules/router.nix +++ b/modules/router.nix @@ -109,8 +109,8 @@ let ip -6 rule add fwmark ${toString heMark} table he || true ip -6 route replace default dev he0 table he - ip rule add fwmark ${toString vpnMark} table vpn || true - ip -6 rule add fwmark ${toString vpnMark} table vpn || true + # ip rule add fwmark ${toString vpnMark} table vpn || true + # ip -6 rule add fwmark ${toString vpnMark} table vpn || true ip rule add fwmark ${toString mullvadMark} table mullvad || true ip -6 rule add fwmark ${toString mullvadMark} table mullvad || true @@ -334,7 +334,7 @@ in { age.secrets.dragon-wireguard-key.file = ./. + "/../secrets/dragon-wireguard-key.age"; networking.wireguard.interfaces.wg-vpn = { - fwMark = "${toString vpnMark}"; + # fwMark = "${toString vpnMark}"; socketNamespace = "router"; interfaceNamespace = "router"; ips = [ "${vpnPrefix}::1/128" ]; -- cgit v1.2.3