Hi, i use at my wireguard 'server' ndp_proxy to announce - thats the reason why i could use the same interface address subnet, then the endpoint is in. Example client configuration: [Interface] Address = 2a01:1337::3/64 [Peer] AllowedIPs = 0.0.0.0/0,::/0 PersistentKeepalive = 25 Endpoint = [2a01:1337::2]:48574 Is there a solution for this 'bug' - there should be a validation and exclude of endpoint addresses on the routing table fwmark A nice day Geno