Issue with wireguard container. All containers loose connection

  • Hi :)


    It's days i'm trying to figure out this issue but without luck.


    On my Odroid HC2 i tried to setup wireguard container with this compose:



    As soon as i start the container, the whole network of the containers breaks. If i try to "curl 1.1.1.1" from inside a container, i have no response. Basically all the containers lose their network.


    An user from linuxserver community reproduced my same config on OMV in an x86:64 VM and had no issue. All parameters where the same.


    Do you have any idea why?

  • Actually i did some tests, with tcpdump, doing a "curl 1.1.1.1" from the inside of another container".


    192.169.1.197 is my Odroid HC2 eth ip post-nat.

    172.18.0.4 = container IP no-nat


    The following with wireguard up, so not working:


    Code
    root@DK:/srv/dev-disk-by-label-HC2/DockerCompose/wireguard# tcpdump -i enx001e06328f28 -c 100 -n src 1.1.1.1 or dst 1.1.1.1
    tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
    listening on enx001e06328f28, link-type EN10MB (Ethernet), capture size 262144 bytes
    22:36:27.134741 IP 172.18.0.4.55440 > 1.1.1.1.80: Flags [S], seq 3880654192, win 29200, options [mss 1460,sackOK,TS val 3856157367 ecr 0,nop,wscale 7], length 0
    22:36:28.153752 IP 172.18.0.4.55440 > 1.1.1.1.80: Flags [S], seq 3880654192, win 29200, options [mss 1460,sackOK,TS val 3856158386 ecr 0,nop,wscale 7], length 0
    22:36:30.169768 IP 172.18.0.4.55440 > 1.1.1.1.80: Flags [S], seq 3880654192, win 29200, options [mss 1460,sackOK,TS val 3856160402 ecr 0,nop,wscale 7], length 0
    22:36:33.722209 IP 172.18.0.4.55448 > 1.1.1.1.80: Flags [S], seq 277366197, win 29200, options [mss 1460,sackOK,TS val 3856163955 ecr 0,nop,wscale 7], length 0
    22:36:34.671531 IP 172.18.0.4.55452 > 1.1.1.1.80: Flags [S], seq 3704919641, win 29200, options [mss 1460,sackOK,TS val 3856164904 ecr 0,nop,wscale 7], length 0
    22:36:35.473943 IP 172.18.0.4.55454 > 1.1.1.1.80: Flags [S], seq 267325050, win 29200, options [mss 1460,sackOK,TS val 3856165706 ecr 0,nop,wscale 7], length 0

    The following without wireguard, so connection restored:


    The 172... address should be nat'ed to the 192... one.

    Any idea?

Participate now!

Don’t have an account yet? Register yourself now and be a part of our community!