summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorNeale Ranns <nranns@cisco.com>2020-09-14 08:29:05 +0000
committerNeale Ranns <nranns@cisco.com>2020-09-16 09:43:21 +0000
commit58db34c2ca491cb949ab046cccbd73be14b90647 (patch)
tree9c1cb729807e1621f0dcf23a85c731e5c1a8d29e
parentc71dad4a2dd06aa379ed2ad02df3327622bfea80 (diff)
wireguard: increase FIB source priority
Type: fix Signed-off-by: Neale Ranns <nranns@cisco.com> Change-Id: Icc1c458474d357c7d9b3b4df1897500de0c314a1 (cherry picked from commit a26b0d11e91e9abca6220e50f0240ab6ae09c6d3)
-rwxr-xr-xsrc/plugins/wireguard/wireguard_peer.c9
1 files changed, 7 insertions, 2 deletions
diff --git a/src/plugins/wireguard/wireguard_peer.c b/src/plugins/wireguard/wireguard_peer.c
index 0dcc4e20e41..3985f4347b4 100755
--- a/src/plugins/wireguard/wireguard_peer.c
+++ b/src/plugins/wireguard/wireguard_peer.c
@@ -401,8 +401,13 @@ format_wg_peer (u8 * s, va_list * va)
static clib_error_t *
wg_peer_module_init (vlib_main_t * vm)
{
- wg_fib_source = fib_source_allocate ("wireguard", 0xb0, //
- FIB_SOURCE_BH_SIMPLE);
+ /*
+ * use a priority better than interface source, so that
+ * if the same subnet is added to the wg interface and is
+ * used as an allowed IP, then the wireguard soueced prefix
+ * wins and traffic is routed to the endpoint rather than dropped
+ */
+ wg_fib_source = fib_source_allocate ("wireguard", 0x2, FIB_SOURCE_BH_API);
return (NULL);
}