Subj : Route48
To : Alexey Vissarionov
From : Victor Sudakov
Date : Tue Apr 04 2023 11:50 am
Dear Alexey,
04 Apr 23 02:08, you wrote to me:
>>>> I am not familiar with Wireguard.
TK>>> One of the best available VPN software. I have a wireguard
TK>>> server running at home for remote access. See
TK>>>
https://www.wireguard.com/
VS>> It has a major drawback as compared to GRE or IPIP. You cannot
VS>> bind your side of the tunnel to a specific IP address (external
VS>> address as related to the tunnel).
AV> Whether you need to set up multiple tunnels with different links (I
AV> guess this is the case), you may use VRF to keep them apart.
AV> Linux does that just fine.
Yes, I implied a case with two upstream ISPs when you want two tunnels to pass
via different ISPs.
I'm sure there exist some clever solutions, but with GRE or IPIP you could just
use simple policy routing because the external src address is fixed.
Do you suggest placing the two upstream ISPs into different VRFs?
Victor Sudakov, VAS4-RIPE, VAS47-RIPN
--- GoldED+/BSD 1.1.5-b20170303-b20170303
* Origin: Ulthar (2:5005/49)