SCHEMA=wg-paid-vm100-readonly-audit-v1 MACHINE=VM100 AUDIT_UTC=2026-08-02T10:15:05Z HOSTNAME= ===== SYSTEM ===== { "kernel": "6.6.93", "hostname": "OpenWrt", "system": "Intel(R) Core(TM) i7-6950X CPU @ 3.00GHz", "model": "QEMU Standard PC (i440FX + PIIX, 1996)", "board_name": "qemu-standard-pc-i440fx-piix-1996", "rootfs_type": "ext4", "release": { "distribution": "OpenWrt", "version": "24.10.2", "revision": "r28739-d9340319c6", "target": "x86/64", "description": "OpenWrt 24.10.2 r28739-d9340319c6", "builddate": "1750711236" } } Linux OpenWrt 6.6.93 #0 SMP Mon Jun 23 20:40:36 2025 x86_64 GNU/Linux 10:15:05 up 8 days, 13:39, load average: 0.00, 0.00, 0.00 Filesystem Size Used Available Use% Mounted on /dev/root 1.1G 84.9M 1011.7M 8% / /dev/root 1.1G 84.9M 1011.7M 8% / ===== MACHINE GIT ===== >>> [vm100-git] precheck MODE=--check PROFILE=/etc/router-machine-git-source.conf PROFILE_VERSION=2 PROFILE_SHA256=ee2c3b5366d8eb4c4ebf9766c07f6926ecc927e9c38a3766d870fc7397ab2743 MACHINE_ID=vm100 GIT_DIR=/root/.vm100-source.git WORK_TREE=/ BRANCH=main REMOTE_URL=git@github.com:DChuvelev/wg-paid-vm100.git LOCAL_HEAD=a8b7337674b931c2e73f9b4bd7ebe76866e6a81f >>> [vm100-git] verify remote branch REMOTE_HEAD=a8b7337674b931c2e73f9b4bd7ebe76866e6a81f >>> [vm100-git] build current project allowlist >>> [vm100-git] read paths already tracked by git CURRENT_ALLOWED_COUNT=30 TRACKED_COUNT=30 MANAGED_UNION_COUNT=30 >>> [vm100-git] strict path validation STRICT_PATH_VALIDATION=true >>> [vm100-git] show tracked files now missing from machine TRACKED_PATH_MISSING_COUNT=0 >>> [vm100-git] build simulated git index STAGED_CHANGE_COUNT=0 STAGED_PATHS=NONE >>> [vm100-git] validate simulated staged paths STAGED_PATH_VALIDATION=true SIMULATED_TREE_SHA=9bf4d21d4088629d5469c8f5659391c96e150fc5 SIMULATED_TREE_FILE_COUNT=30 >>> [vm100-git] high-confidence secret scan of simulated tree HIGH_CONFIDENCE_SECRET_MATCHES=0 >>> [vm100-git] keyword review scan KEYWORD_REVIEW_FILES=NONE RESULT=PASS_vm100_GIT_PUBLISH_CHECK MACHINE_ID=vm100 GIT_COMMIT=a8b7337674b931c2e73f9b4bd7ebe76866e6a81f GIT_TREE=9bf4d21d4088629d5469c8f5659391c96e150fc5 GIT_FILE_COUNT=30 COMMIT_CREATED=false PUSH_PERFORMED=false VM100_GIT_CHECK=PASS ===== COMMANDS AND PACKAGES ===== WG_CLI_PRESENT=true AMNEZIAWG_CLI_PRESENT=true amneziawg-tools - 1.0.20240213-r1 kmod-amneziawg - 6.6.93-r1 kmod-wireguard - 6.6.93-r1 luci-app-amneziawg - 25.176.66860~0c726ca luci-proto-wireguard - 26.101.22949~8aafcdf wireguard-tools - 1.0.20210914-r4 AMNEZIAWG_PACKAGE_COUNT=3 wireguard 65536 0 - Live 0xffffffffa06c8000 libchacha20poly1305 16384 1 wireguard, Live 0xffffffffa0564000 curve25519_x86_64 32768 1 wireguard, Live 0xffffffffa0554000 libcurve25519_generic 49152 2 wireguard,curve25519_x86_64, Live 0xffffffffa04c8000 ip6_udp_tunnel 12288 1 wireguard, Live 0xffffffffa0342000 udp_tunnel 16384 1 wireguard, Live 0xffffffffa0337000 ===== NETWORK SUMMARY ===== lo UNKNOWN 00:00:00:00:00:00 eth0 UP bc:24:11:94:bb:fb eth1 UP bc:24:11:ee:7d:14 eth2 UP bc:24:11:e4:6c:fb br-lan UP bc:24:11:ee:7d:14 wg_paid UNKNOWN wg_remote UNKNOWN lo UNKNOWN 127.0.0.1/8 eth0 UP 10.201.0.1/24 eth2 UP 10.200.0.1/24 br-lan UP 10.71.100.1/24 wg_paid UNKNOWN 10.253.1.1/16 wg_remote UNKNOWN 10.250.100.1/24 default via 10.201.0.2 dev eth0 proto static metric 10 default via 10.200.0.2 dev eth2 proto static metric 20 10.71.100.0/24 dev br-lan proto kernel scope link src 10.71.100.1 10.200.0.0/24 dev eth2 proto static scope link metric 20 10.201.0.0/24 dev eth0 proto static scope link metric 10 10.250.100.0/24 dev wg_remote proto kernel scope link src 10.250.100.1 10.250.100.2 dev wg_remote proto static scope link 10.250.100.3 dev wg_remote proto static scope link 10.250.100.4 dev wg_remote proto static scope link 10.250.100.5 dev wg_remote proto static scope link 10.250.100.121 dev wg_remote proto static scope link 10.253.0.0/16 dev wg_paid proto kernel scope link src 10.253.1.1 --- UCI network redacted --- network.loopback=interface network.loopback.device='lo' network.loopback.proto='static' network.loopback.ipaddr='127.0.0.1' network.loopback.netmask='255.0.0.0' network.globals=globals network.globals.packet_steering='1' network.@device[0]=device network.@device[0].name='br-lan' network.@device[0].type='bridge' network.@device[0].ports='eth1' network.lan=interface network.lan.device='br-lan' network.lan.proto='static' network.lan.ipaddr='10.71.100.1' network.lan.netmask='255.255.255.0' network.device=eth2 network.proto=static network.ipaddr=10.200.0.1 network.transit_direct=interface network.transit_direct.proto='static' network.transit_direct.device='eth0' network.transit_direct.ipaddr='10.201.0.1/24' network.transit_direct.gateway='10.201.0.2' network.transit_direct.dns='10.201.0.2' network.transit_direct.metric='10' network.transit_vpn=interface network.transit_vpn.proto='static' network.transit_vpn.device='eth2' network.transit_vpn.ipaddr='10.200.0.1' network.transit_vpn.netmask='255.255.255.0' network.transit_vpn.gateway='10.200.0.2' network.transit_vpn.metric='20' network.wg_remote=interface network.wg_remote.proto='wireguard' network.wg_remote.private_key= network.wg_remote.listen_port='51820' network.wg_remote.addresses='10.250.100.1/24' network.@wireguard_wg_remote[0]=wireguard_wg_remote network.@wireguard_wg_remote[0].description='support-mgts' network.@wireguard_wg_remote[0].public_key= network.@wireguard_wg_remote[0].private_key= network.@wireguard_wg_remote[0].allowed_ips='10.250.100.2/32' network.@wireguard_wg_remote[0].route_allowed_ips='1' network.@wireguard_wg_remote[1]=wireguard_wg_remote network.@wireguard_wg_remote[1].description='owner-mgts' network.@wireguard_wg_remote[1].public_key= network.@wireguard_wg_remote[1].private_key= network.@wireguard_wg_remote[1].allowed_ips='10.250.100.3/32' network.@wireguard_wg_remote[1].route_allowed_ips='1' network.@wireguard_wg_remote[2]=wireguard_wg_remote network.@wireguard_wg_remote[2].description='router-ops-mgts' network.@wireguard_wg_remote[2].public_key= network.@wireguard_wg_remote[2].allowed_ips='10.250.100.4/32' network.@wireguard_wg_remote[2].route_allowed_ips='1' network.wg_paid=interface network.wg_paid.proto='wireguard' network.wg_paid.private_key= network.wg_paid.listen_port='51830' network.wg_paid.addresses='10.253.1.1/16' network.@wireguard_wg_remote[3]=wireguard_wg_remote network.@wireguard_wg_remote[3].description='VM121 wg-access-dev direct admin' network.@wireguard_wg_remote[3].public_key= network.@wireguard_wg_remote[3].allowed_ips='10.250.100.121/32' network.@wireguard_wg_remote[3].route_allowed_ips='1' network.@wireguard_wg_remote[4]=wireguard_wg_remote network.@wireguard_wg_remote[4].public_key= network.@wireguard_wg_remote[4].private_key= network.@wireguard_wg_remote[4].description='MityaMgtsRemotePhone' network.@wireguard_wg_remote[4].route_allowed_ips='1' network.@wireguard_wg_remote[4].allowed_ips='10.250.100.5/32' --- interface dump --- { "interface": [ { "interface": "lan", "up": true, "pending": false, "available": true, "autostart": true, "dynamic": false, "uptime": 740391, "l3_device": "br-lan", "proto": "static", "device": "br-lan", "updated": [ "addresses" ], "metric": 0, "dns_metric": 0, "delegation": true, "ipv4-address": [ { "address": "10.71.100.1", "mask": 24 } ], "ipv6-address": [ ], "ipv6-prefix": [ ], "ipv6-prefix-assignment": [ ], "route": [ ], "dns-server": [ ], "dns-search": [ ], "neighbors": [ ], "inactive": { "ipv4-address": [ ], "ipv6-address": [ ], "route": [ ], "dns-server": [ ], "dns-search": [ ], "neighbors": [ ] }, "data": { } }, { "interface": "loopback", "up": true, "pending": false, "available": true, "autostart": true, "dynamic": false, "uptime": 740391, "l3_device": "lo", "proto": "static", "device": "lo", "updated": [ "addresses" ], "metric": 0, "dns_metric": 0, "delegation": true, "ipv4-address": [ { "address": "127.0.0.1", "mask": 8 } ], "ipv6-address": [ ], "ipv6-prefix": [ ], "ipv6-prefix-assignment": [ ], "route": [ ], "dns-server": [ ], "dns-search": [ ], "neighbors": [ ], "inactive": { "ipv4-address": [ ], "ipv6-address": [ ], "route": [ ], "dns-server": [ ], "dns-search": [ ], "neighbors": [ ] }, "data": { } }, { "interface": "transit_direct", "up": true, "pending": false, "available": true, "autostart": true, "dynamic": false, "uptime": 740391, "l3_device": "eth0", "proto": "static", "device": "eth0", "updated": [ "addresses", "routes" ], "metric": 10, "dns_metric": 0, "delegation": true, "ipv4-address": [ { "address": "10.201.0.1", "mask": 24 } ], "ipv6-address": [ ], "ipv6-prefix": [ ], "ipv6-prefix-assignment": [ ], "route": [ { "target": "0.0.0.0", "mask": 0, "nexthop": "10.201.0.2", "source": "0.0.0.0/0" } ], "dns-server": [ "10.201.0.2" ], "dns-search": [ ], "neighbors": [ ], "inactive": { "ipv4-address": [ ], "ipv6-address": [ ], "route": [ ], "dns-server": [ ], "dns-search": [ ], "neighbors": [ ] }, "data": { } }, { "interface": "transit_vpn", "up": true, "pending": false, "available": true, "autostart": true, "dynamic": false, "uptime": 740391, "l3_device": "eth2", "proto": "static", "device": "eth2", "updated": [ "addresses", "routes" ], "metric": 20, "dns_metric": 0, "delegation": true, "ipv4-address": [ { "address": "10.200.0.1", "mask": 24 } ], "ipv6-address": [ ], "ipv6-prefix": [ ], "ipv6-prefix-assignment": [ ], "route": [ { "target": "0.0.0.0", "mask": 0, "nexthop": "10.200.0.2", "source": "0.0.0.0/0" } ], "dns-server": [ ], "dns-search": [ ], "neighbors": [ ], "inactive": { "ipv4-address": [ ], "ipv6-address": [ ], "route": [ ], "dns-server": [ ], "dns-search": [ ], "neighbors": [ ] }, "data": { } }, { "interface": "wg_paid", "up": true, "pending": false, "available": true, "autostart": true, "dynamic": false, "uptime": 740390, "l3_device": "wg_paid", "proto": "wireguard", "updated": [ "addresses" ], "metric": 0, "dns_metric": 0, "delegation": true, "ipv4-address": [ { "address": "10.253.1.1", "mask": 16 } ], "ipv6-address": [ ], "ipv6-prefix": [ ], "ipv6-prefix-assignment": [ ], "route": [ ], "dns-server": [ ], "dns-search": [ ], "neighbors": [ ], "inactive": { "ipv4-address": [ ], "ipv6-address": [ ], "route": [ ], "dns-server": [ ], "dns-search": [ ], "neighbors": [ ] }, "data": { } }, { "interface": "wg_remote", "up": true, "pending": false, "available": true, "autostart": true, "dynamic": false, "uptime": 48737, "l3_device": "wg_remote", "proto": "wireguard", "updated": [ "addresses", "routes" ], "metric": 0, "dns_metric": 0, "delegation": true, "ipv4-address": [ { "address": "10.250.100.1", "mask": 24 } ], "ipv6-address": [ ], "ipv6-prefix": [ ], "ipv6-prefix-assignment": [ ], "route": [ { "target": "10.250.100.2", "mask": 32, "nexthop": "0.0.0.0", "source": "0.0.0.0/0" }, { "target": "10.250.100.3", "mask": 32, "nexthop": "0.0.0.0", "source": "0.0.0.0/0" }, { "target": "10.250.100.4", "mask": 32, "nexthop": "0.0.0.0", "source": "0.0.0.0/0" }, { "target": "10.250.100.5", "mask": 32, "nexthop": "0.0.0.0", "source": "0.0.0.0/0" }, { "target": "10.250.100.121", "mask": 32, "nexthop": "0.0.0.0", "source": "0.0.0.0/0" } ], "dns-server": [ ], "dns-search": [ ], "neighbors": [ ], "inactive": { "ipv4-address": [ ], "ipv6-address": [ ], "route": [ ], "dns-server": [ ], "dns-search": [ ], "neighbors": [ ] }, "data": { } } ] } WG_PAID_PRESENT=true WG_PAID_LISTEN_PORT=51830 WG_PAID_PUBLIC_KEY_SHA256=442e3c1e4ed1a3bb371b03bb16ed75158bba311f513c72fa67396ee6010ea343 WG_PAID_PEER_COUNT=5 AWG_PAID_INTERFACE_PRESENT=false ===== SELECTOR AND TOPOLOGY ===== 46d41783effb8d80ea1b09895f829b98a0946e0edbff1e29e7651eb3ef9b036a /etc/router-wgpay-selector.d/peers.conf SELECTOR_FILE=/etc/router-wgpay-selector.d/peers.conf ACTIVE_ENTRY_COUNT=5 46d41783effb8d80ea1b09895f829b98a0946e0edbff1e29e7651eb3ef9b036a /etc/router-wgpay-selector.d/canonical.conf SELECTOR_FILE=/etc/router-wgpay-selector.d/canonical.conf ACTIVE_ENTRY_COUNT=5 SELECTOR_ENTRY_COUNT=5 schema=router-wgpay-slot-topology-ack-v1 result=PASS direct_policy_enabled=0 healthy_slot_count=5 min_healthy_slots_to_exit_direct=3 direct_active_before=false direct_probe_result=PASS_DIRECT_MODE_PROBE direct_transition=NOT_REQUIRED direct_action=NOT_REQUIRED direct_action_result=NOT_REQUESTED direct_request_result=NOT_REQUESTED selector_transaction_suppressed=false accepted_generation=000000000016 applied_generation=000000000016 apply_performed=true payload_sha256=98273ca7df91ba4ddfad6e002acadef74d24d1d29584fbea103bdcc591c0f5f6 selector_sha256_before=8e75b7ab9b3a9d223c4cfe07dd7f9963d4c9abfeb980f7a1391eea8b686f8ac3 selector_sha256=46d41783effb8d80ea1b09895f829b98a0946e0edbff1e29e7651eb3ef9b036a plan_sha256=2bb7228ed391811bef20a7e08024fe9ed0fab573a8e779a7a3f4041dfdcbc6c4 peer_count=5 moved_peer_count=1 exhausted_rows_remaining=0 rollback_performed=false rollback_result=NOT_REQUIRED counts.cs1=1 counts.cs2=1 counts.cs3=1 counts.cs4=1 counts.cs5=1 schema=router-wgpay-slot-topology-state-v2 accepted_generation=000000000016 applied_generation=000000000016 payload_sha256=98273ca7df91ba4ddfad6e002acadef74d24d1d29584fbea103bdcc591c0f5f6 mode=NORMAL source_vm101_generation=WATCHER_bridge_clear_egress1_1785605342 healthy_slots=egress1,egress2,egress3,egress4,egress5 exhausted_slots= allowed_selectors=cs1,cs2,cs3,cs4,cs5 exhausted_selectors= created_epoch=1785605342 received_epoch=1785605342 apply_result=PASS direct_policy_enabled=0 healthy_slot_count=5 min_healthy_slots_to_exit_direct=3 direct_active_before=false direct_probe_result=PASS_DIRECT_MODE_PROBE direct_transition=NOT_REQUIRED direct_action=NOT_REQUIRED direct_action_result=NOT_REQUESTED direct_request_result=NOT_REQUESTED selector_transaction_suppressed=false apply_performed=true selector_sha256_before=8e75b7ab9b3a9d223c4cfe07dd7f9963d4c9abfeb980f7a1391eea8b686f8ac3 selector_sha256=46d41783effb8d80ea1b09895f829b98a0946e0edbff1e29e7651eb3ef9b036a peer_count=5 moved_peer_count=1 exhausted_rows_remaining=0 plan_sha256=2bb7228ed391811bef20a7e08024fe9ed0fab573a8e779a7a3f4041dfdcbc6c4 counts.cs1=1 counts.cs2=1 counts.cs3=1 counts.cs4=1 counts.cs5=1 ===== FIREWALL PBR DIRECT ACTIVITY ===== firewall.@zone[1].name='transit_direct' firewall.@zone[1].network='transit_direct' firewall.@forwarding[0].dest='transit_direct' firewall.@zone[2].name='transit_vpn' firewall.@zone[2].network='transit_vpn' firewall.@forwarding[1].dest='transit_vpn' firewall.@forwarding[3].dest='transit_direct' firewall.@forwarding[4].dest='transit_vpn' firewall.@rule[0].src='transit_direct' firewall.wg_paid=zone firewall.wg_paid.name='wg_paid' firewall.wg_paid.input='ACCEPT' firewall.wg_paid.output='ACCEPT' firewall.wg_paid.forward='REJECT' firewall.wg_paid.network='wg_paid' firewall.wg_paid_to_transit_direct=forwarding firewall.wg_paid_to_transit_direct.src='wg_paid' firewall.wg_paid_to_transit_direct.dest='transit_direct' firewall.wg_paid_to_transit_vpn=forwarding firewall.wg_paid_to_transit_vpn.src='wg_paid' firewall.wg_paid_to_transit_vpn.dest='transit_vpn' firewall.allow_wg_paid_51830=rule firewall.allow_wg_paid_51830.name='Allow-WG-Paid-51830' firewall.allow_wg_paid_51830.proto='udp' firewall.allow_wg_paid_51830.dest_port='51830' firewall.allow_wg_paid_51830.target='ACCEPT' pbr.config.webui_show_ignore_target='1' pbr.config.supported_interface='transit_direct' 'transit_vpn' pbr.@policy[0].name='IGNORE_ADMIN_WG_TO_LAN' pbr.@policy[0].interface='ignore' /etc/pbr.d/default_lan_to_vpn.sh:6:nft add element inet fw4 pbr_transit_vpn_4_src_ip_user "{ 10.71.100.0/24, 10.250.100.0/24, 10.252.100.0/24, 10.253.0.0/16 }" 2>/dev/null || true /usr/local/sbin/router-wgpay-direct-mode.sh:18:PAID_CIDR="${ROUTER_WGPAY_DIRECT_PAID_SOURCE_CIDR:-${TOPOLOGY_DIRECT_PAID_SOURCE_CIDR:-10.253.0.0/16}}" /etc/router-egress-activity/router_egress_activity.nft:16: iifname "wg_paid" oifname "eth2" ip saddr 10.253.1.10/32 counter name peer_10_253_1_10_out_vpn comment "activity_out 10.253.1.10/32 cs1 cs1_vpn3" /etc/router-egress-activity/router_egress_activity.nft:17: iifname "eth2" oifname "wg_paid" ip daddr 10.253.1.10/32 counter name peer_10_253_1_10_in_vpn comment "activity_in 10.253.1.10/32 cs1 cs1_vpn3" /etc/router-egress-activity/router_egress_activity.nft:18: iifname "wg_paid" oifname "eth2" ip saddr 10.253.1.11/32 counter name peer_10_253_1_11_out_vpn comment "activity_out 10.253.1.11/32 cs2 cs2_vpn4" /etc/router-egress-activity/router_egress_activity.nft:19: iifname "eth2" oifname "wg_paid" ip daddr 10.253.1.11/32 counter name peer_10_253_1_11_in_vpn comment "activity_in 10.253.1.11/32 cs2 cs2_vpn4" /etc/router-egress-activity/router_egress_activity.nft:20: iifname "wg_paid" oifname "eth2" ip saddr 10.253.1.12/32 counter name peer_10_253_1_12_out_vpn comment "activity_out 10.253.1.12/32 cs3 cs3_vpn5" /etc/router-egress-activity/router_egress_activity.nft:21: iifname "eth2" oifname "wg_paid" ip daddr 10.253.1.12/32 counter name peer_10_253_1_12_in_vpn comment "activity_in 10.253.1.12/32 cs3 cs3_vpn5" /etc/router-egress-activity/router_egress_activity.nft:22: iifname "wg_paid" oifname "eth2" ip saddr 10.253.1.13/32 counter name peer_10_253_1_13_out_vpn comment "activity_out 10.253.1.13/32 cs4 cs4_vpn1" /etc/router-egress-activity/router_egress_activity.nft:23: iifname "eth2" oifname "wg_paid" ip daddr 10.253.1.13/32 counter name peer_10_253_1_13_in_vpn comment "activity_in 10.253.1.13/32 cs4 cs4_vpn1" /etc/router-egress-activity/router_egress_activity.nft:24: iifname "wg_paid" oifname "eth2" ip saddr 10.253.1.14/32 counter name peer_10_253_1_14_out_vpn comment "activity_out 10.253.1.14/32 cs5 cs5_vpn2" /etc/router-egress-activity/router_egress_activity.nft:25: iifname "eth2" oifname "wg_paid" ip daddr 10.253.1.14/32 counter name peer_10_253_1_14_in_vpn comment "activity_in 10.253.1.14/32 cs5 cs5_vpn2" iifname "wg_paid" jump input_wg_paid comment "!fw4: Handle wg_paid IPv4/IPv6 input traffic" iifname "wg_paid" jump forward_wg_paid comment "!fw4: Handle wg_paid IPv4/IPv6 forward traffic" udp dport 51830 counter packets 0 bytes 0 accept comment "!fw4: Allow-WG-Paid-51830" oifname "wg_paid" jump output_wg_paid comment "!fw4: Handle wg_paid IPv4/IPv6 output traffic" iifname "wg_paid" jump helper_wg_paid comment "!fw4: Handle wg_paid IPv4/IPv6 helper assignment" chain input_wg_paid { jump accept_from_wg_paid chain output_wg_paid { jump accept_to_wg_paid chain forward_wg_paid { jump accept_to_transit_direct comment "!fw4: Accept wg_paid to transit_direct forwarding" jump accept_to_transit_vpn comment "!fw4: Accept wg_paid to transit_vpn forwarding" jump reject_to_wg_paid chain helper_wg_paid { chain accept_from_wg_paid { iifname "wg_paid" counter packets 0 bytes 0 accept comment "!fw4: accept wg_paid IPv4/IPv6 traffic" chain accept_to_wg_paid { oifname "wg_paid" counter packets 0 bytes 0 accept comment "!fw4: accept wg_paid IPv4/IPv6 traffic" chain reject_to_wg_paid { oifname "wg_paid" counter packets 0 bytes 0 jump handle_reject comment "!fw4: reject wg_paid IPv4/IPv6 traffic" iifname "wg_remote" ip dscp set cs4 counter packets 78881 bytes 12405643 comment "WG_REMOTE_DEFAULT_SELECTOR_CS4" iifname "wg_paid" oifname "eth2" ip saddr 10.253.1.10 counter name "peer_10_253_1_10_out_vpn" comment "activity_out 10.253.1.10/32 cs1 cs1_vpn3" iifname "eth2" oifname "wg_paid" ip daddr 10.253.1.10 counter name "peer_10_253_1_10_in_vpn" comment "activity_in 10.253.1.10/32 cs1 cs1_vpn3" iifname "wg_paid" oifname "eth2" ip saddr 10.253.1.11 counter name "peer_10_253_1_11_out_vpn" comment "activity_out 10.253.1.11/32 cs2 cs2_vpn4" iifname "eth2" oifname "wg_paid" ip daddr 10.253.1.11 counter name "peer_10_253_1_11_in_vpn" comment "activity_in 10.253.1.11/32 cs2 cs2_vpn4" iifname "wg_paid" oifname "eth2" ip saddr 10.253.1.12 counter name "peer_10_253_1_12_out_vpn" comment "activity_out 10.253.1.12/32 cs3 cs3_vpn5" iifname "eth2" oifname "wg_paid" ip daddr 10.253.1.12 counter name "peer_10_253_1_12_in_vpn" comment "activity_in 10.253.1.12/32 cs3 cs3_vpn5" iifname "wg_paid" oifname "eth2" ip saddr 10.253.1.13 counter name "peer_10_253_1_13_out_vpn" comment "activity_out 10.253.1.13/32 cs4 cs4_vpn1" iifname "eth2" oifname "wg_paid" ip daddr 10.253.1.13 counter name "peer_10_253_1_13_in_vpn" comment "activity_in 10.253.1.13/32 cs4 cs4_vpn1" iifname "wg_paid" oifname "eth2" ip saddr 10.253.1.14 counter name "peer_10_253_1_14_out_vpn" comment "activity_out 10.253.1.14/32 cs5 cs5_vpn2" iifname "eth2" oifname "wg_paid" ip daddr 10.253.1.14 counter name "peer_10_253_1_14_in_vpn" comment "activity_in 10.253.1.14/32 cs5 cs5_vpn2" iifname "wg_paid" ip saddr 10.253.1.10 ip dscp set cs5 counter packets 0 bytes 0 comment "STEP_035B_SELECTOR_WGPAY_canary_vpn2_10.253.1.10_cs5" iifname "wg_paid" ip saddr 10.253.1.11 ip dscp set cs2 counter packets 0 bytes 0 comment "STEP_035B_SELECTOR_WGPAY_canary_vpn4_10.253.1.11_cs2" iifname "wg_paid" ip saddr 10.253.1.12 ip dscp set cs3 counter packets 0 bytes 0 comment "STEP_035B_SELECTOR_WGPAY_canary_vpn5_10.253.1.12_cs3" iifname "wg_paid" ip saddr 10.253.1.13 ip dscp set cs4 counter packets 0 bytes 0 comment "STEP_035B_SELECTOR_WGPAY_canary_vpn1_10.253.1.13_cs4" iifname "wg_paid" ip saddr 10.253.1.14 ip dscp set cs1 counter packets 0 bytes 0 comment "STEP_035B_SELECTOR_WGPAY_canary_vpn3_10.253.1.14_cs1" ===== UDP LISTENERS AND CANDIDATES ===== Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name udp 0 0 0.0.0.0:51820 0.0.0.0:* - udp 0 0 0.0.0.0:51830 0.0.0.0:* - udp 0 0 10.250.100.1:53 0.0.0.0:* 4600/dnsmasq udp 0 0 127.0.0.1:53 0.0.0.0:* 4600/dnsmasq udp 0 0 10.201.0.1:53 0.0.0.0:* 4600/dnsmasq udp 0 0 10.200.0.1:53 0.0.0.0:* 4600/dnsmasq udp 0 0 10.71.100.1:53 0.0.0.0:* 4600/dnsmasq udp 0 0 10.253.1.1:53 0.0.0.0:* 4600/dnsmasq udp 0 0 0.0.0.0:67 0.0.0.0:* 4600/dnsmasq udp 0 0 :::51820 :::* - udp 0 0 :::51830 :::* - udp 0 0 ::1:53 :::* 4600/dnsmasq udp 0 0 fe80::be24:11ff:fe94:bbfb:53 :::* 4600/dnsmasq udp 0 0 fe80::be24:11ff:fee4:6cfb:53 :::* 4600/dnsmasq udp 0 0 fe80::be24:11ff:feee:7d14:53 :::* 4600/dnsmasq CANDIDATE_AWG_PORT=51831 CANDIDATE_AWG_PORT_COLLISION=false CANDIDATE_AWG_POOL=10.254.0.0/16 CANDIDATE_AWG_POOL_CONFLICT=false RESULT=PASS_R20QW_VM100_READONLY_AUDIT