0.0.0.0/0 as allowed IPs on both ends
-
0.0.0.0/0 as allowed IPs on both ends of one tunnel between two pfsenses works. But is it a good idea or is there a risk.
Opinions? -
@Bob-Dig IMHO I don't see the use or if that's even a correct setting. As 0.0.0.0/0 would simply route everything through wireguard - what's there to gain? You can't route everything from A to the internet via B and vice versa - then no site has WAN/internet for themselves as both set default routes to the other side of the tunnel. So the whole setup makes no sense to me.
Cheers
-
My use-case is Site-to-Site VPN where I have added networks later on and did forget to change the allowed IPs in the configuration. And this happened to me more than once.
And pfSense itself is not using those allowed IPs for its routing so right now I am using this on a tunnel on both ends. I like the freedom of not having to touch this tunnel ever again.