2026 WireGuard Split-Tunnel AllowedIPs, MTU & PostUp Routing Table
2026 Verified ReferenceIn WireGuard (`wg0.conf`), the client `[Peer] AllowedIPs` directive acts as both a routing table selector and an ingress source-IP filter: set `AllowedIPs = 0.0.0.0/0, ::/0` for a full-tunnel VPN, or specify internal CIDRs (`10.8.0.0/24, 192.168.1.0/24`) for split tunneling where internet traffic bypasses the VPN.
WireGuard Overhead = 60B (IPv4) or 80B (IPv6) → Optimal Ethernet MTU = 1420 (PPPoE/LTE MTU = 1380)| WireGuard Routing Scenario | Config Directive / CIDR Value | Traffic Flow Behavior | Operational & Security Best Practice |
|---|---|---|---|
| Full Tunnel VPN (All Traffic) | AllowedIPs = 0.0.0.0/0, ::/0 | Routes 100% of IPv4 & IPv6 packets via WG server | Pair with DNS = 1.1.1.1 to prevent ISP DNS leaks |
| Corporate / Homelab Split Tunnel | AllowedIPs = 10.66.66.0/24, 192.168.10.0/24 | Only private subnet traffic enters encrypted tunnel | Direct internet speed remains untouched (zero VPN lag) |
| Full Tunnel Excluding Local LAN | AllowedIPs = 0.0.0.0/1, 128.0.0.0/1 (plus LAN bypass) | Routes internet via VPN while keeping local printers/NAS | Avoids 0.0.0.0/0 kill-switch overriding local subnet |
| MTU Fragmentation & MSS Fix | MTU = 1420 (or MTU = 1380 on 5G/PPPoE) | Prevents PMTUD blackholes on TLS handshakes | Use 1380 if websites hang or video streams stall |
| Server NAT Masquerade (PostUp) | PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE | Enables IPv4 packet forwarding out server NIC | Requires net.ipv4.ip_forward=1 in /etc/sysctl.conf |
| Post-Quantum PSK & CGNAT Keepalive | PresharedKey = <wg genpsk> | PersistentKeepalive = 25 | Adds 256-bit symmetric layer + keeps NAT port open | Defends Curve25519 against harvest-now-decrypt-later |
