refer to: https://wiki.archlinux.org/title/WireGuard

section 2.4.3 systemd-networkd: routing all traffic over WireGuard

special attention to exempt the endpoints public ip.

works, zero iptables used.

Reply to this note

Please Login to reply.

Discussion

well, zero on the client, simple masquerade on the exit node