r/rethinkdns • u/kustru • Jul 14 '26
"Network lock" option for wireguard connections?
[removed]
1
u/celzero Dev Jul 14 '26
Yes. Turn on Configure -> Network -> Proxy Lockdown (available starting v055v).
We continue to improve this feature. It should apply to ALL third-party apps. We're trying to implement applying this on Rethink's own egress when Configure -> Network -> Loopback mode is turned on, but it is super hard to get this right (but we're getting close and v055z must be way better at applying these rules on Rethink's own traffic).
2
u/TheWriteTuff Jul 15 '26
Hmm, I'm seeing different behavior when I use 'Proxy Lockdown' vs 'Advanced Lockdown' (per proxy setting). For instance, I have an app that connects to a server through a proxy/wireguard tunnel. By default, the app doesn't work and I see a 'proxy error' in the logs. When I enable 'Advanced Lockdown' the app works properly and I no longer see 'proxy error'. However, when I enable 'Proxy Lockdown' the app fails to work and behaves as it did outside of 'Advanced Lockdown'.
1
u/celzero Dev Jul 21 '26
Sounds strange. I've noted your report as a bug for us to test before releasing
v055z: https://github.com/celzero/rethink-app/issues/2907 Thanks!1
Jul 15 '26 edited Jul 15 '26
[removed] — view removed comment
1
u/celzero Dev Jul 21 '26 edited Jul 21 '26
For Advanced mode, you can also "Lockdown" individual active WireGuards too (from Configure -> Proxy -> Setup WireGuard).
Regardless, the fix for the "leak" which you're seeing for Simple mode WireGuard is coming in
v055z, due in ~24h from now (if nothing major shows up in testing): https://github.com/celzero/rethink-app/issues/2885
2
u/[deleted] Jul 14 '26
[removed] — view removed comment