In reply to: https://lemmy.sdf.org/post/51020621
Maybe you already figured this out but I think it’s a common gotcha:
Wireguard AllowedIPs means just that: IPs that are allowed to be routed over the tunnel.
There is nothing that says that you need to have 1-to-1 mapping between that and actual routes. Most of the time it’s what you want but there are situations where you want it different.
wg-quick additionally adds corresponding ip routes as a convenience. systemd-networkd did at some point but don’t anymore. I’m not sure what NetworkManager does there these days.
Anyway, it’s an understandable source of confusion and the tools don’t always help.