summary |
shortlog |
log |
commit | commitdiff |
review |
tree
raw |
patch |
inline | side by side (from parent 1:
9459d65)
Type: fix
Signed-off-by: Neale Ranns <nranns@cisco.com>
Change-Id: Icc1c458474d357c7d9b3b4df1897500de0c314a1
static clib_error_t *
wg_peer_module_init (vlib_main_t * vm)
{
static clib_error_t *
wg_peer_module_init (vlib_main_t * vm)
{
- wg_fib_source = fib_source_allocate ("wireguard", 0xb0, //
- FIB_SOURCE_BH_SIMPLE);
+ /*
+ * use a priority better than interface source, so that
+ * if the same subnet is added to the wg interface and is
+ * used as an allowed IP, then the wireguard soueced prefix
+ * wins and traffic is routed to the endpoint rather than dropped
+ */
+ wg_fib_source = fib_source_allocate ("wireguard", 0x2, FIB_SOURCE_BH_API);