A client CIDR with nonzero host bits (e.g. 10.66.120.1/30 instead of the network 10.66.120.0/30) is tolerated by wg's own AllowedIPs/setconf, which just warns, but plain iproute2 rejects it with "Invalid prefix for given prefix length" and aborts the whole PostUp chain, taking the interface down on start. Added a routeNet template func that clears host bits via net.ParseCIDR before generating each PostUp route line. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ATVUwTa4Pqwq26orW5BcDW