summary refs log tree commit diff
path: root/docs/api/html/settings-wireguard.html
diff options
context:
space:
mode:
Diffstat (limited to 'docs/api/html/settings-wireguard.html')
-rw-r--r--docs/api/html/settings-wireguard.html30
1 files changed, 20 insertions, 10 deletions
diff --git a/docs/api/html/settings-wireguard.html b/docs/api/html/settings-wireguard.html
index c5c3fe23..685061fb 100644
--- a/docs/api/html/settings-wireguard.html
+++ b/docs/api/html/settings-wireguard.html
@@ -38,7 +38,7 @@
             Properties
         </h2>
 <div class="table">
-<a name="id-1.3.3.46.2.2.1"></a><p class="title"><b>Table 92. </b></p>
+<a name="id-1.3.3.46.2.2.1"></a><p class="title"><b>Table 80. </b></p>
 <div class="table-contents"><table class="table" border="1">
 <colgroup>
 <col>
@@ -57,55 +57,65 @@
 <td><pre class="screen">fwmark</pre></td>
 <td><pre class="screen">uint32</pre></td>
 <td><pre class="screen">0</pre></td>
-<td> </td>
+<td>The use of fwmark is optional and is by default off. Setting it to 0 disables it. Otherwise, it is a 32-bit fwmark for outgoing packets.
+
+Note that "ip4-auto-default-route" or "ip6-auto-default-route" enabled, implies to automatically choose a fwmark.</td>
 </tr>
 <tr>
 <td><pre class="screen">ip4-auto-default-route</pre></td>
 <td><pre class="screen">NMTernary (int32)</pre></td>
 <td><pre class="screen"></pre></td>
-<td> </td>
+<td>Whether to enable special handling of the IPv4 default route. If enabled, the IPv4 default route from wireguard.peer-routes will be placed to a dedicated routing-table and two policy routing rules will be added. The fwmark number is also used as routing-table for the default-route, and if fwmark is zero, an unused fwmark/table is chosen automatically. This corresponds to what wg-quick does with Table=auto and what WireGuard calls "Improved Rule-based Routing".
+
+Note that for this automatism to work, you usually don't want to set ipv4.gateway, because that will result in a conflicting default route.
+
+Leaving this at the default will enable this option automatically if ipv4.never-default is not set and there are any peers that use a default-route as allowed-ips. Since this automatism only makes sense if you also have a peer with an /0 allowed-ips, it is usually not necessary to enable this explicitly. However, you can disable it if you want to configure your own routing and rules.</td>
 </tr>
 <tr>
 <td><pre class="screen">ip6-auto-default-route</pre></td>
 <td><pre class="screen">NMTernary (int32)</pre></td>
 <td><pre class="screen"></pre></td>
-<td> </td>
+<td>Like ip4-auto-default-route, but for the IPv6 default route.</td>
 </tr>
 <tr>
 <td><pre class="screen">listen-port</pre></td>
 <td><pre class="screen">uint32</pre></td>
 <td><pre class="screen">0</pre></td>
-<td> </td>
+<td>The listen-port. If listen-port is not specified, the port will be chosen randomly when the interface comes up.</td>
 </tr>
 <tr>
 <td><pre class="screen">mtu</pre></td>
 <td><pre class="screen">uint32</pre></td>
 <td><pre class="screen">0</pre></td>
-<td> </td>
+<td>If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple fragments.
+
+If zero a default MTU is used. Note that contrary to wg-quick's MTU setting, this does not take into account the current routes at the time of activation.</td>
 </tr>
 <tr>
 <td><pre class="screen">peer-routes</pre></td>
 <td><pre class="screen">boolean</pre></td>
 <td><pre class="screen">TRUE</pre></td>
-<td> </td>
+<td>Whether to automatically add routes for the AllowedIPs ranges of the peers. If TRUE (the default), NetworkManager will automatically add routes in the routing tables according to ipv4.route-table and ipv6.route-table. Usually you want this automatism enabled. If FALSE, no such routes are added automatically. In this case, the user may want to configure static routes in ipv4.routes and ipv6.routes, respectively.
+
+Note that if the peer's AllowedIPs is "0.0.0.0/0" or "::/0" and the profile's ipv4.never-default or ipv6.never-default setting is enabled, the peer route for this peer won't be added automatically.</td>
 </tr>
 <tr>
 <td><pre class="screen">peers</pre></td>
 <td><pre class="screen">array of 'a{sv}'</pre></td>
 <td><pre class="screen"></pre></td>
-<td> </td>
+<td>Array of dictionaries for the WireGuard peers.</td>
 </tr>
 <tr>
 <td><pre class="screen">private-key</pre></td>
 <td><pre class="screen">string</pre></td>
 <td><pre class="screen"></pre></td>
-<td> </td>
+<td>The 256 bit private-key in base64 encoding.</td>
 </tr>
 <tr>
 <td><pre class="screen">private-key-flags</pre></td>
 <td><pre class="screen">NMSettingSecretFlags (uint32)</pre></td>
 <td><pre class="screen"></pre></td>
-<td> </td>
+<td>Flags indicating how to handle the "private-key" property.</td>
 </tr>
 </tbody>
 </table></div>