wireguard disallow a lot of geo subnets

i have a ton of all russian subnets which i doesnt want route through vpn due vpn monitoring on rzzian faschist services, and services which blocking all non-rzzian ips

also since i wanna use wireguard(amneziawg obsurfication fork, since plain wg is blocked) on a openwrt system soooo maybe there are way to route all traffic thru wg interface but subnet list thru plain interface

aaaaaaaaa i dont have much openwrt stuff knowledge,

2 points · 5 comments · view on lemmy.world

5 Comments

okwhateverdude@lemmy.world · 3 pts · 64d (1 reply)

This is doable, just tedious by hand. Your favorite clanker can walk you through the steps to find a geoip datasource (eg. bootleg maxmind, ASN lists, etc), and either directly write the routes, or a script that will generate it from that source.

erinmeow@piefed.blahaj.zone · 2 pts · 64d

https://github.com/C24Be/AS_Network_List, this repo give me idea make a script which generating a routes

stratself@lemdro.id · 2 pts · 64d (2 replies)

You're probably interested in creating a firewall on openwrt that blocks all traffic from/to certain IPs

erinmeow@piefed.blahaj.zone · 1 pts · 64d (1 reply)

as i understand i can do by one subnet separatly but the problem that there are 1000+ subnets, maybe i dont know some feature to load an ipset file also uguguhguhg isnt parsing 1000+ subnets are load on cpu?

SteveTech@aussie.zone · 2 pts · 63d

I'm not sure how a firewall would help, you'd definately want to do this from the routing table.

isnt parsing 1000+ subnets are load on cpu?

IPv4 addresses are basically just 32bit numbers, any somewhat modern CPU can check through 1000 routes in nanoseconds.

Also 1000+ seems a bit excessive, you should be able to aggregate some of those subnets into a few bigger ones. There are calculators online for this, or you can script it.