Hacker News
new
past
comments
ask
show
jobs
points
by
zx2c4
9 hours ago
|
comments
by
Sesse__
8 hours ago
|
[-]
I use Wireguard rarely enough that the AllowedIPs concept gets me every time. It gets easier when I replace it mentally with “Route=” :-)
reply
by
zx2c4
7 hours ago
|
parent
|
[-]
It's like a routing table on the way out and an ACL on the way in. Maybe an easier way to think of it.
reply
by
Sesse__
6 hours ago
|
parent
|
[-]
Sure, but how does this differ from a routing table with RPF (which is default in Linux already)?
reply
by
zx2c4
6 hours ago
|
parent
|
[-]
It's associated per-peer, so it assures a cryptographic mapping between src ip and public key.
reply