Post #2741395
2026-03-16 02:18 UTC
@hugo@social.treehouse.systems @arichtman@eigenmagic.net agreed with two minor details that may combine here.
Endpoint is optional. It can be discovered and change based on received traffic. So only one party needs an endpoint configured for the other peer to get things started.
If you're a remote access endpoint for lots of roaming users, you won't have configured endpoints for them, only discovered ones once they're connected. Also, you may be asked to provide the config for those to just "install", which means priv key as well.
I suspect this is the server/client distinction being made. It's a valid and common use case for commodity devices. But I've seen gui configurations that encode more than that (ubiquiti was terrible at first) like implied firewall rules and default routes. So I'm wary of the lack of clarity.
Replies (1)
-
@arichtman@eigenmagic.net 2026-03-16 02:43
@uep@timeloop.cafe @hugo@social.treehouse.systems thanks Dan and Hugo - this does clear up my confusion about the setup! I'll have another bash at it this week. I think the peering is good to go I just need to iron out what's stopping traffic from site A to site B, vice versa is working