enforce WireGuard persistent-keepalive 25 (NAT expiry fix)
This commit is contained in:
@@ -50,6 +50,12 @@ STRIPPED=$(mktemp)
|
||||
grep -vE '^\s*(Address|DNS|MTU|Table|PreUp|PreDown|PostUp|PostDown|SaveConfig)\s*=' "$CONF" > "$STRIPPED"
|
||||
nsexec wg setconf "$WG" "$STRIPPED"
|
||||
rm -f "$STRIPPED"
|
||||
# Persistent keepalive: without it, NAT mapping expires after 1-2 min of
|
||||
# inactivity and the tunnel silently dies (page loads, then network fails).
|
||||
PEER_PK=$(grep -oP '^\s*PublicKey\s*=\s*\K\S+' "$CONF" | head -1)
|
||||
if [ -n "$PEER_PK" ]; then
|
||||
nsexec wg set "$WG" peer "$PEER_PK" persistent-keepalive 25 2>/dev/null || true
|
||||
fi
|
||||
MTU=$(grep -oP '^\s*MTU\s*=\s*\K\d+' "$CONF" | head -1); MTU=${MTU:-1280}
|
||||
nsexec ip link set "$WG" mtu "$MTU"
|
||||
for a in $(grep -oP '^\s*Address\s*=\s*\K\S+' "$CONF" | tr ',' ' '); do
|
||||
|
||||
Reference in New Issue
Block a user