Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It’s kindly explained on the actual WireGuard page as well:

https://www.wireguard.com/netns/



I prefer flagging packets from cgroup. But since cgroupv2 it can only be done with systemd/slices, it's not easy and stable. (The slice must exist before iptables rule, and if it stops, i experiment kernel crashes etc.)


and it is mentioned on the blogpost as well. :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: