Wanna use #Wireguard with #VRFs? Need a clean solution for separating local and "public" routing domain?

Wrote something down (with examples for #systemd-networkd):
https://margau.net/posts/2024-01-12-wireguard-vrf/

WireGuard and Linux VRFs

TL;DR Using WireGuard with VRFs under systemd-networkd. The concept When using VPNs for all of your traffic, you usually have a “private” network part (inside VPN), and a public one (public/direct internet, not trusted), which needs separation. From a practical perspective, you might want to have a Linux-based router with an “inner” default network, transported by WireGuard tunnels, and an external network for the internet, over which the VPN data is transported. The Public routing domain shall be routed completely separated from the private routing domain, so no packets can leak between them. No Layer 2 is used, packets in both domains are isolated and shall be routed differently.

margau.net
1 person injured, 10 others displaced following Vancouver fire

Vancouver Fire Rescue Services said crews were called at 9:12 a.m. Tuesday to reports of a fire at a residential-detached house on the 3600 block of SW Marine Drive.

Global News