wireguard
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revision | |||
| wireguard [2026/08/17 21:19] – djgalloway | wireguard [2026/08/24 15:23] (current) – djgalloway | ||
|---|---|---|---|
| Line 207: | Line 207: | ||
| - | ===== More about DNS Configuration on Linux ===== | + | ===== DNS Configuration |
| If you're using systemd-resolved, | If you're using systemd-resolved, | ||
| Line 255: | Line 255: | ||
| Now lookups of shortname or shortname.front or shortname.ipmi should work. Note that dig does not respect the search domains in / | Now lookups of shortname or shortname.front or shortname.ipmi should work. Note that dig does not respect the search domains in / | ||
| + | ===== Split DNS on systemd-resolved distros (Fedora, recent Ubuntu, etc.) ===== | ||
| + | If all web browsing / external DNS stops working while connected to the Sepia VPN, but works again after '' | ||
| + | |||
| + | Do **not** use '' | ||
| + | |||
| + | - Edit ''/ | ||
| + | - **Remove** (or comment out) the '' | ||
| + | - Add the following lines under '' | ||
| + | |||
| + | < | ||
| + | PostUp = resolvectl dns %i 10.20.192.13 | ||
| + | PostUp = resolvectl domain %i ~sepia.ceph.com ~front.sepia.ceph.com ~ipmi.sepia.ceph.com | ||
| + | PostUp = resolvectl default-route %i false | ||
| + | </ | ||
| + | |||
| + | Then restart the tunnel: | ||
| + | |||
| + | < | ||
| + | sudo wg-quick down sepia && sudo wg-quick up sepia | ||
| + | </ | ||
| + | |||
| + | Verify: | ||
| + | |||
| + | < | ||
| + | resolvectl status sepia | ||
| + | </ | ||
| + | |||
| + | You should see '' | ||
| + | |||
| + | ==== Alternative: | ||
| + | |||
| + | On Fedora you can instead import the tunnel into NetworkManager, | ||
| + | |||
| + | < | ||
| + | sudo nmcli connection import type wireguard file / | ||
| + | sudo nmcli connection modify sepia ipv4.dns-search " | ||
| + | sudo nmcli connection up sepia | ||
| + | </ | ||
| + | |||
| + | Only use one method — don't run wg-quick and the NetworkManager connection at the same time. | ||
wireguard.1787001566.txt.gz · Last modified: by djgalloway
