关于WireGuard隧道IP子网掩码作用的技术问询
最近折腾WireGuard的时候发现个有意思的点——哪怕不设置隧道IP地址,只配好AllowedIPs、端点地址还有公私钥,WireGuard居然也能正常跑起来。但像OpnSense和pfSense这类防火墙的文档里,却对隧道IP的子网掩码有明确要求,这就让我有点摸不着头脑了,想跟大家唠唠这事儿。
先看看相关文档里的说法:
OpnSense的警告
Note: The tunnel address must be in CIDR notation and must be a unique IP
and subnet for your network. [..] Do not use a tunnel
address that is a /32 (IPv4) or a /128 (IPv6)
pfSense的相关解释
Note: Routes are not automatically created in the system routing table.
Routes for networks other than the tunnel network itself must be
configured separately using static or dynamic routes.
我在网上搜了半天,找到的相关讨论大多是基础的子网掩码疑问,比如Reddit上的「子网掩码困惑」、「VPN服务器中/24和/32的区别」、「/8、/16这些掩码到底用来干嘛」,都没找到直接针对WireGuard隧道IP子网掩码作用的清晰答案。
为了搞明白,我自己也做了些测试,结果发现子网掩码好像没什么实际功能:
- 和本地流量路由无关:不管子网掩码是否包含所有连接的节点,路由到第二个peer都能正常工作
- 和「流量留在接口」还是「走内核转发」无关:两种情况下我都能用防火墙规则正常控制流量
所以想请教各位大佬,WireGuard隧道IP里的子网掩码到底有什么作用?
备注:内容来源于stack exchange,提问作者Georg Schölly

