How do you prove a WireGuard endpoint is unused before retiring its old address?
Moving a WireGuard gateway to a new public address can appear complete while an offline laptop, a peer behind persistent NAT, or a configuration distributed outside the normal management path still points at the old endpoint. Active handshakes show who is using the new address, but silence does not distinguish a migrated peer from one that simply has not connected yet.
What evidence do you collect before removing the old address? I am considering keeping both endpoints reachable during a bounded overlap, mapping every peer public key to its intended configuration revision, recording latest handshakes and transfer counters on the new gateway, and alerting on any packet reaching the old UDP socket. The observation window would cover the longest expected offline period, not just the usual keepalive interval.
How do roaming peers, DNS endpoints, persistent keepalives, and mobile devices change the check? Is there a practical way to issue a migration receipt per peer, and what final failure test can show that no current configuration still depends on the old address without stranding a device that has been offline?
https://redd.it/1wrn8ga
@r_wireguard
Post #9795
14