enforce WireGuard persistent-keepalive 25 (NAT expiry fix)

This commit is contained in:
Antigravity Agent
2026-10-03 10:01:13 -04:00
parent 94e1e94062
commit 8d11925fe1
+6
View File
@@ -50,6 +50,12 @@ STRIPPED=$(mktemp)
grep -vE '^\s*(Address|DNS|MTU|Table|PreUp|PreDown|PostUp|PostDown|SaveConfig)\s*=' "$CONF" > "$STRIPPED" grep -vE '^\s*(Address|DNS|MTU|Table|PreUp|PreDown|PostUp|PostDown|SaveConfig)\s*=' "$CONF" > "$STRIPPED"
nsexec wg setconf "$WG" "$STRIPPED" nsexec wg setconf "$WG" "$STRIPPED"
rm -f "$STRIPPED" rm -f "$STRIPPED"
# Persistent keepalive: without it, NAT mapping expires after 1-2 min of
# inactivity and the tunnel silently dies (page loads, then network fails).
PEER_PK=$(grep -oP '^\s*PublicKey\s*=\s*\K\S+' "$CONF" | head -1)
if [ -n "$PEER_PK" ]; then
nsexec wg set "$WG" peer "$PEER_PK" persistent-keepalive 25 2>/dev/null || true
fi
MTU=$(grep -oP '^\s*MTU\s*=\s*\K\d+' "$CONF" | head -1); MTU=${MTU:-1280} MTU=$(grep -oP '^\s*MTU\s*=\s*\K\d+' "$CONF" | head -1); MTU=${MTU:-1280}
nsexec ip link set "$WG" mtu "$MTU" nsexec ip link set "$WG" mtu "$MTU"
for a in $(grep -oP '^\s*Address\s*=\s*\K\S+' "$CONF" | tr ',' ' '); do for a in $(grep -oP '^\s*Address\s*=\s*\K\S+' "$CONF" | tr ',' ' '); do