Re: wireguard-windows: Wireguard does not start a previously activated tunnel from time to time

2022-09-28 Thread Jan Petrischkeit
Hi, thank you for this information, I will take a look at that. Now I know where to look. However, I am using the "endpoint-by-dns" for a specific reason: In my area there is an internet provider which uses carrier grade nat in a strange way, so that no rdp session can be created over a

Re: Wireguard does not work in Iran

2022-09-28 Thread Houman
David, Thanks for sharing this. That's an impressive list of ways to connect with Wireguard that I wasn't even aware of. With the exception of shadowsocks, would the other obfuscations that you listed here such as "Iptables extension'' or "swgp-go" also work with the Wireguard iOS library? As I

Re: Wireguard does not work in Iran

2022-09-28 Thread David Fifield
On Wed, Sep 28, 2022 at 09:32:04AM +, Mehdi Haghgoo wrote: > It seems that Wireguard does not work at all in Iran. > I used to use it with nmcli on Linux, but recently it just does not work, > even with ADSL Internet (Mobile internet is mainly shut down). > > I suspect it is not because UDP

Re: Iptables WireGuard obfuscation extension

2022-09-28 Thread Jean-Philippe Aumasson
ChaCha6 is probably enough crypto-wise here. On Wed 28 Sep 2022 at 18:35 Jason A. Donenfeld wrote: > Hey Wei, > > On Sat, Sep 10, 2022 at 06:34:42AM -0500, Wei Chen wrote: > > Hi, > > > > Jason once suggested use a netfilter module for obfuscation[1]. Here is > one. > > > >

Re: APK outside of Play Store?

2022-09-28 Thread tempforever
wiregu...@bulletin.elitemail.org wrote: > For users who prefer to avoid Play Store as a delivery channel, is there an > official pre-built APK available? Such users are typically steered towards > APKPure/APKMirror/F-Droid with questionabl authenticity and (in the case of > F-Droid) the

RE: wireguard-windows: Wireguard does not start a previously activated tunnel from time to time

2022-09-28 Thread Simon Rozman
Hi, > Event 7023, ServiceControlManager: The service "WireGuardTunnel$HOST- > WG2" was terminated with the following error: The requested name is valid, > but no data of the requested type was found. The error message you are mentioning is WSANO_DATA 11004 which is related to DNS resolution

Re: Iptables WireGuard obfuscation extension

2022-09-28 Thread Jason A. Donenfeld
Hey Wei, On Sat, Sep 10, 2022 at 06:34:42AM -0500, Wei Chen wrote: > Hi, > > Jason once suggested use a netfilter module for obfuscation[1]. Here is one. > > https://github.com/infinet/xt_wgobfs > > It uses SipHash 1-2 to generate pseudo-random numbers in a reproducible way. > Sender and

WireGuard invalid MAC

2022-09-28 Thread coot
Hello, I configured wireguard so I can access my home server from a laptop. When the laptop is using its eth0 interface to transport wireguard protocol messages it works fine, but when I switch it off and use wlan0 (which is using a different ISP), on the server side the kernel logs: Keypair

Re: MacOS app update needed

2022-09-28 Thread Ken Case
> On Sep 22, 2022, at 04:48, Jason A. Donenfeld wrote: > > On Wed, Sep 21, 2022 at 9:31 AM Simon Karberg > wrote: >> >> Hi, >> >> I've been testing the Domain Search functionality on all 3 OS' >> (Windows, Mac & Linux) and the setting: >> >> DNS=, >> Is only being applied on Windows &

Re: MacOS app update needed

2022-09-28 Thread Lewis Donzis
- On Sep 22, 2022, at 6:43 AM, Jason A. Donenfeld ja...@zx2c4.com wrote: > On Wed, Sep 21, 2022 at 10:22 AM Bruno wrote: >> >> Hi, >> >> Windows Client project don't feel alive either. Last commit has 6 months >> and last release is 9 month old. >> >> Same, here

APK outside of Play Store?

2022-09-28 Thread wireguard
For users who prefer to avoid Play Store as a delivery channel, is there an official pre-built APK available? Such users are typically steered towards APKPure/APKMirror/F-Droid with questionabl authenticity and (in the case of F-Droid) the prospect of old build dependencies built on an EOL OS

wireguard-windows: Wireguard does not start a previously activated tunnel from time to time

2022-09-28 Thread Jan Petrischkeit
Dear Wireguard Community, I have the problem that Wireguard on some systems and there only from time to time forgets to activate the tunnel at system startup. Mainly this happens after an update of the wireguard client or changes to the client config. If an admin then reactivates the tunnel,

Android: Support for Material You Themed Icon?

2022-09-28 Thread wireguard
This would be useful for my partial color blindness (and others who are similarly color vision deficient) as it would provide a base to improve the contrast of the icon against a light/dark theme background (a monochromatic icon layer and a touch of XML):

Possible performance impact of queuing?

2022-09-28 Thread marcel
Hi there, I was just testing wireguard performance on a new server machine (with lots of cores) and got lower performance than expected. However a lot of kernel processes were spawned only using CPUs up to 20% (but not higher). That got me thinking about a possible cause. I remembered, that

Iptables WireGuard obfuscation extension

2022-09-28 Thread Wei Chen
Hi, Jason once suggested use a netfilter module for obfuscation[1]. Here is one. https://github.com/infinet/xt_wgobfs It uses SipHash 1-2 to generate pseudo-random numbers in a reproducible way. Sender and receiver share a siphash secret key. Sender creates and receiver re-creates identical

Constant stream of handshake for peer did not complete

2022-09-28 Thread Michael Brookes
Hi I have one wg endpoint which is CentOS 7.9.2009 (3.10.0-1160.71.1.el7.x86_64) with kmod-wireguard 9:1.0.20220627-1.el7_9.elrepo installed. Has about 300ish peers. We have one, there could be more, cases of wireguard logging on the other peer (typically laptops, I've seen this happen on Mac

Wireguard does not work in Iran

2022-09-28 Thread Mehdi Haghgoo
Hi, It seems that Wireguard does not work at all in Iran. I used to use it with nmcli on Linux, but recently it just does not work, even with ADSL Internet (Mobile internet is mainly shut down). I suspect it is not because UDP is completely blocked, because I see some other VPNs are working