Bypass network entries get routed into a bypass VPN tunnel #221

Closed
opened 2026-09-16 22:41:53 -04:00 by mysticalsoap · 0 comments
Owner

Network entries (bypass.set_network_rules) mark forwarded traffic with the same fwmark the app cgroup uses, so it resolves through the same table 11. That table's default is the physical link only until a bypass VPN tunnel comes up - then the tunnel replaces it (bypass_up.sh for OpenVPN, the table-11 route for WireGuard, #216), and every listed network's traffic is redirected into the bypass tunnel: forwarded, so not masqueraded, so rejected by the server, retransmitted at line rate.

That inverts the feature: network entries exist to route forwarded traffic past the tunnel (#168's case - a container running its own VPN must not be double-tunnelled). Hit live 2026-09-16 with gluetun's subnet listed and a WireGuard bypass up: 43 GiB pushed into wg_aqomui_b in ten minutes, and the per-peer queue starvation hung every bypassed app's connection too. An OpenVPN bypass tunnel misroutes the same way, just without the starvation making it obvious.

Fix: give network entries their own mark and routing table, defaulting to the physical link and never touched by a bypass tunnel. Apps keep table 11 (tunnel if present); networks get table 12 (always physical).

Network entries (bypass.set_network_rules) mark forwarded traffic with the same fwmark the app cgroup uses, so it resolves through the same table 11. That table's default is the physical link only until a bypass VPN tunnel comes up - then the tunnel replaces it (bypass_up.sh for OpenVPN, the table-11 route for WireGuard, #216), and every listed network's traffic is redirected into the bypass tunnel: forwarded, so not masqueraded, so rejected by the server, retransmitted at line rate. That inverts the feature: network entries exist to route forwarded traffic *past* the tunnel (#168's case - a container running its own VPN must not be double-tunnelled). Hit live 2026-09-16 with gluetun's subnet listed and a WireGuard bypass up: 43 GiB pushed into wg_aqomui_b in ten minutes, and the per-peer queue starvation hung every bypassed app's connection too. An OpenVPN bypass tunnel misroutes the same way, just without the starvation making it obvious. Fix: give network entries their own mark and routing table, defaulting to the physical link and never touched by a bypass tunnel. Apps keep table 11 (tunnel if present); networks get table 12 (always physical).
Sign in to join this conversation.
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
mysticalsoap/aqomui#221
No description provided.