logoalt Hacker News

Frotagyesterday at 9:33 PM1 replyview on HN

> The gateway device performs 1:1 NAT. Traffic arriving for 100.97.14.3 is destination-translated to 192.168.1.100, and the source is masqueraded to the gateway's own LAN address.

Couldn't you tell the WG devices that 192.168.2.0/24 refers to the 192.168.1.0/24 network at customer A, such that 192.168.2.55 is routed to 192.168.1.55. Same for 192.168.3.0/24 referring to customer B.

I think this is what the article is getting at but I don't see the value in manually assigning an alias to each non-wg device, versus assigning an alias to the entire LAN.


Replies

direwolf20yesterday at 9:53 PM

It's not enough to set fake routes. You have to edit the addresses in the packets, so the end devices will receive them.

show 2 replies