This shows you the differences between two versions of the page.
| Misc:Wireguard_je64nr567asjkef34nsfrg:start [2025/10/23 10:49] – created err404 | Misc:Wireguard_je64nr567asjkef34nsfrg:start [2025/10/23 10:49] (current) – removed err404 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | source: https:// | ||
| - | ====== sur le nœud de sortie ====== | ||
| - | ==== Configurer le nœud de sortie ==== | ||
| - | |||
| - | |||
| - | Fixer les adresses ip publiques dans le fichier interfaces - Set public ip addresses in the interfaces file | ||
| - | (actuelement un proxmox avec un bridge en vmbr0) | ||
| - | |||
| - | '' | ||
| - | |||
| - | Le fichier doit ressembler à ça - The file should look like this : | ||
| - | <code bash> | ||
| - | auto lo | ||
| - | iface lo inet loopback | ||
| - | |||
| - | #auto vmbr0 | ||
| - | #iface vmbr0 inet static | ||
| - | # | ||
| - | # | ||
| - | # | ||
| - | # | ||
| - | # | ||
| - | |||
| - | #iface wlp2s0 inet manual | ||
| - | |||
| - | auto usb0 | ||
| - | iface usb0 inet manual | ||
| - | iface usb0 inet6 manual | ||
| - | |||
| - | auto enp1s0 | ||
| - | iface enp1s0 inet manual | ||
| - | iface enp1s0 inet6 manual | ||
| - | |||
| - | auto enp2s0f0 | ||
| - | iface ensp2s0f0 inet manual | ||
| - | iface enp2s0f0 inet6 manual | ||
| - | |||
| - | #dell i5 | ||
| - | auto eno1 | ||
| - | iface eno1 inet manual | ||
| - | iface eno1 inet6 manual | ||
| - | |||
| - | #R5 | ||
| - | auto enp37s0 | ||
| - | iface enp37s0 inet manual | ||
| - | iface enp37s0 inet6 manual | ||
| - | |||
| - | #fujitsu siemens i7 | ||
| - | auto enp0s25 | ||
| - | iface enp0s25 inet manual | ||
| - | iface enp0s25 inet6 manual | ||
| - | |||
| - | |||
| - | auto vmbr0 | ||
| - | iface vmbr0 inet dhcp | ||
| - | bridge-ports enp1s0 enp2s0f0 enp0s25 enp37s0 eno1 usb0 | ||
| - | bridge-stp off | ||
| - | bridge-fd 0 | ||
| - | post-up ip a a 192.168.1.5/ | ||
| - | post-up ip a a 2a02: | ||
| - | post-up ip r a default via fe80:: | ||
| - | post-up echo " | ||
| - | post-up nft -f / | ||
| - | |||
| - | </ | ||
| - | # Save and quit (CTRL+O, CTRL+X) | ||
| - | |||
| - | Redémarrer le réseau restart the network | ||
| - | |||
| - | ''/ | ||
| - | |||
| - | Autoriser la redirections des paquets IPV4 et IPV6 Allow forwarding of IPV4 and IPV6 packets | ||
| - | |||
| - | '' | ||
| - | <code bash> | ||
| - | # Uncomment the following lines: | ||
| - | net.ipv4.ip_forward = 1 | ||
| - | net.ipv6.conf.all.forwarding = 1 | ||
| - | </ | ||
| - | # Save and quit (CTRL+O, CTRL+X) | ||
| - | |||
| - | '' | ||
| - | |||
| - | ==== Installation et configuration de Wireguard - installation and configuration of Wireguard : ===== | ||
| - | |||
| - | Installer Wireguard sur le VPS et sur le serveur YunoHost (Les utilisateurs ayant des versions de Debian plus anciennes que Bullseye doivent d’abord activer les rétroportages) Install Wireguard on the VPS and on the YunoHost server (Users with Debian releases older than Bullseye should first enable backports) | ||
| - | |||
| - | '' | ||
| - | |||
| - | WireGuard nécessite des clés publiques et privées codées en base64. Celles-ci peuvent être générées en utilisant l’utilitaire wg. Des deux côtés, faites WireGuard requires base64-encoded public and private keys. These can be generated using the wg utility. On both side do : | ||
| - | |||
| - | '' | ||
| - | '' | ||
| - | |||
| - | ==== Configurer Wireguard sur le nœud de sortie - Configure Wireguard on the exit node : ==== | ||
| - | |||
| - | '' | ||
| - | |||
| - | Remplir le fichier '' | ||
| - | |||
| - | <code bash> | ||
| - | [Interface] | ||
| - | Address = 10.6.0.1/24 | ||
| - | Address = fd42: | ||
| - | #SaveConfig = true | ||
| - | PostUp = bash / | ||
| - | PostDown = bash / | ||
| - | ListenPort = 51820 | ||
| - | PrivateKey = XXXXXXXXXXXXXXXXXXXXXX | ||
| - | |||
| - | |||
| - | [Peer] | ||
| - | PublicKey = YYYYYYYYYYYYYYYYYYYYYYY | ||
| - | AllowedIPs = 10.6.0.2/ | ||
| - | Endpoint = [2a02: | ||
| - | |||
| - | |||
| - | </ | ||
| - | # Save and quit (CTRL+O, CTRL+X) | ||
| - | |||
| - | Puis créer et remplir les fichiers PostUp.sh et PostDown.sh comme suit Then create and fill the PostUp.sh and PostDown.sh files as follows : | ||
| - | |||
| - | '' | ||
| - | |||
| - | Remplir le fichier PostUp.sh comme ceci - Fill in the PostUp.sh file like this | ||
| - | <code bash> | ||
| - | # PostUp.sh | ||
| - | |||
| - | IP_CLIENT=" | ||
| - | |||
| - | nft -f / | ||
| - | |||
| - | logger Wireguard " | ||
| - | |||
| - | iptables -A FORWARD -i wg-hive -j ACCEPT; | ||
| - | iptables -t nat -A POSTROUTING -o vmbr0 -j MASQUERADE; | ||
| - | ip6tables -A FORWARD -i wg-hive -j ACCEPT; | ||
| - | ip6tables -t nat -A POSTROUTING -o vmbr0 -j MASQUERADE; | ||
| - | |||
| - | # icmp | ||
| - | iptables -A INPUT -p icmp -j ACCEPT; | ||
| - | ip6tables -A INPUT -p ipv6-icmp -j ACCEPT; | ||
| - | |||
| - | # Routing TCP port 25 and 587 from Yunohost Server to internet | ||
| - | #for j in 25 587 | ||
| - | #do | ||
| - | # | ||
| - | # | ||
| - | # | ||
| - | # | ||
| - | #done | ||
| - | |||
| - | # Routing TCP port required from VPN server to Yunohost server | ||
| - | #for i in 25 80 140 443 587 993 5222 5269 | ||
| - | #do | ||
| - | # | ||
| - | # | ||
| - | # | ||
| - | # | ||
| - | #done | ||
| - | |||
| - | |||
| - | </ | ||
| - | # Save and quit (CTRL+O, CTRL+X) | ||
| - | |||
| - | Remplir le fichier PostDown.sh comme ceci Fill in the PostDown.sh file like this | ||
| - | (sachant que chez moi j'ai déjà des règles nftables pour faire du NAT Masquerade) | ||
| - | '' | ||
| - | <code bash> | ||
| - | # PostDown.sh | ||
| - | |||
| - | |||
| - | IP_CLIENT=" | ||
| - | |||
| - | nft -f / | ||
| - | |||
| - | logger Wireguard " | ||
| - | |||
| - | |||
| - | iptables -D FORWARD -i wg-hive -j ACCEPT; | ||
| - | iptables -t nat -D POSTROUTING -o vmbr0 -j MASQUERADE; | ||
| - | ip6tables -D FORWARD -i wg-hive -j ACCEPT; | ||
| - | ip6tables -t nat -D POSTROUTING -o vmbr0 -j MASQUERADE; | ||
| - | |||
| - | # icmp | ||
| - | iptables -D INPUT -p icmp -j ACCEPT; | ||
| - | ip6tables -D INPUT -p ipv6-icmp -j ACCEPT; | ||
| - | |||
| - | # Routing TCP port 25 and 587 from Yunohost Server to internet | ||
| - | #for j in 25 587 | ||
| - | #do | ||
| - | # | ||
| - | # | ||
| - | # | ||
| - | # | ||
| - | #done | ||
| - | # | ||
| - | # Routing TCP port required from VPN server to Yunohost server | ||
| - | #for i in 25 80 140 443 587 993 5222 5269 | ||
| - | #do | ||
| - | # | ||
| - | # | ||
| - | # | ||
| - | # | ||
| - | #done | ||
| - | |||
| - | |||
| - | </ | ||
| - | # Save and quit (CTRL+O, CTRL+X) | ||
| - | |||
| - | pour infor, mon fichier / | ||
| - | |||
| - | <code bash> | ||
| - | # | ||
| - | flush ruleset | ||
| - | |||
| - | # replace these | ||
| - | define if_wan = vmbr0 | ||
| - | define if_lan2 = enp2s0 | ||
| - | define if_lan3 = enp3s0 | ||
| - | # define if_services = br0 | ||
| - | |||
| - | define ip4_blocked_ports = { 514, 3000 } | ||
| - | define ip6_blocked_ports = { 22, 53, 514, 3000, 8006 } | ||
| - | |||
| - | # define tinc_t30 = 10.0.30.0/ | ||
| - | # define tinc_port_t30 = 2345 | ||
| - | # define tinc_net_t30 = " | ||
| - | |||
| - | | ||
| - | | ||
| - | | ||
| - | |||
| - | | ||
| - | | ||
| - | | ||
| - | |||
| - | | ||
| - | | ||
| - | | ||
| - | |||
| - | | ||
| - | | ||
| - | | ||
| - | | ||
| - | |||
| - | |||
| - | # cette chaine fonctionne pour ipv4 et ipv6, or j'ai besoin de faire la différence entre les ports à ouvrir | ||
| - | #table inet filter { | ||
| - | ## # ... other sections ... | ||
| - | # chain incoming { | ||
| - | ## type filter hook input priority 0; policy drop; | ||
| - | # type filter hook input priority 0; policy accept; | ||
| - | # | ||
| - | # # Accept any localhost traffic: | ||
| - | # iif lo accept | ||
| - | # | ||
| - | # # ... other rules for other services that are running in this server ... | ||
| - | # tcp dport { $blocked_ports } iif $if_wan drop | ||
| - | # udp dport { $blocked_ports } iif $if_wan drop | ||
| - | # } | ||
| - | # chain outgoing { | ||
| - | # type filter hook output priority 0; policy accept; | ||
| - | # } | ||
| - | # chain forward { | ||
| - | # type filter hook forward priority 0; policy accept; | ||
| - | # } | ||
| - | #} | ||
| - | |||
| - | |||
| - | table ip filter { | ||
| - | chain incoming { | ||
| - | type filter hook input priority 0; policy accept; | ||
| - | tcp dport { $ip4_blocked_ports } iif $if_wan drop | ||
| - | udp dport { $ip4_blocked_ports } iif $if_wan drop | ||
| - | } | ||
| - | |||
| - | chain FORWARD { | ||
| - | type filter hook forward priority 0; policy accept; | ||
| - | } | ||
| - | |||
| - | chain outgoing { | ||
| - | type filter hook output priority 0; policy accept; | ||
| - | } | ||
| - | } | ||
| - | |||
| - | |||
| - | table ip6 filter { | ||
| - | chain incoming { | ||
| - | type filter hook input priority 0; policy accept; | ||
| - | udp dport { $ip6_blocked_ports } iif $if_wan drop | ||
| - | tcp dport { $ip6_blocked_ports } iif $if_wan drop | ||
| - | } | ||
| - | chain FORWARD { | ||
| - | type filter hook forward priority 0; policy accept; | ||
| - | } | ||
| - | chain outgoing { | ||
| - | type filter hook output priority 0; policy accept; | ||
| - | } | ||
| - | } | ||
| - | # Finally, NAT! | ||
| - | table ip firewall { | ||
| - | # chain prerouting { | ||
| - | # type nat hook prerouting priority 0; | ||
| - | |||
| - | # Port forward tcp 80/443 to our internal webserver | ||
| - | # iifname $if_wan tcp dport { http, https } dnat to " | ||
| - | # } | ||
| - | |||
| - | #### POSTROUTING | ||
| - | chain postrouting { | ||
| - | type nat hook postrouting priority 100; | ||
| - | |||
| - | |||
| - | # ip saddr $net_lan2 | ||
| - | # ip saddr $net_lan3 | ||
| - | # iif $if_lan2 | ||
| - | # iif $if_lan3 | ||
| - | |||
| - | # iif $tinc_net_err404_routed oifname $if_wan masquerade | ||
| - | # iif $tinc_net_t42 | ||
| - | iif $tinc_net_hive | ||
| - | iif $wg_net_hive | ||
| - | |||
| - | } | ||
| - | |||
| - | </ | ||
| - | |||
| - | Rendre les deux scripts exécutables Make both scripts executable | ||
| - | |||
| - | '' | ||
| - | '' | ||
| - | |||
| - | ====== sur le client nomade ====== | ||
| - | ==== Configurer Wireguard sur le client nomade - Configure Wireguard on the nomade client : ==== | ||
| - | |||
| - | '' | ||
| - | (j'ai pas encore testé la config DNS vu que je force la config dns dans le fichier PostUp.sh) | ||
| - | Remplir le fichier wg-hive.conf comme ceci Fill in the wg-hive.conf file like this | ||
| - | <code bash> | ||
| - | [Interface] | ||
| - | Address = 10.6.0.1/24 | ||
| - | Address = fd42: | ||
| - | #SaveConfig = true | ||
| - | PostUp = bash / | ||
| - | PostDown = bash / | ||
| - | ListenPort = 51820 | ||
| - | PrivateKey = ZZZZZZZZZZZZZZZZZZZZZZZZ | ||
| - | # choose your DNS - for instance FDN DNS resolver | ||
| - | #DNS = 80.67.169.12, | ||
| - | |||
| - | [Peer] | ||
| - | #miou2 | ||
| - | PublicKey = WWWWWWWWWWWWWWWWWWWWWWWWW | ||
| - | AllowedIPs = 10.6.0.2/ | ||
| - | Endpoint = [2a02: | ||
| - | |||
| - | </ | ||
| - | # Save and quit (CTRL+O, CTRL+X) | ||
| - | |||
| - | Remplir le fichier PostUp.sh comme ceci Fill in the PostUp.sh file like this | ||
| - | |||
| - | '' | ||
| - | <code bash> | ||
| - | # PostUp.sh | ||
| - | |||
| - | metric=100 | ||
| - | |||
| - | VPN_GATEWAY_ip4=10.6.0.1 | ||
| - | VPN_GATEWAY_ip6=fd42: | ||
| - | |||
| - | # take the first server' | ||
| - | REMOTEADDRESS_ip4=" | ||
| - | REMOTEADDRESS_ip6=" | ||
| - | ORIGINAL_GATEWAY_ip4=" | ||
| - | ORIGINAL_GATEWAY_ip6=" | ||
| - | INTERFACE=" | ||
| - | |||
| - | ip route add $REMOTEADDRESS_ip4 $ORIGINAL_GATEWAY_ip4 | ||
| - | ip route add $VPN_GATEWAY_ip4 dev $INTERFACE | ||
| - | ip route add 0.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric | ||
| - | ip route add 128.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric | ||
| - | |||
| - | #ip -6 route add $REMOTEADDRESS_ip6 $ORIGINAL_GATEWAY_ip6 | ||
| - | #ip -6 route add $VPN_GATEWAY_ip6 dev $INTERFACE | ||
| - | #ip -6 route add ::/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric | ||
| - | #ip -6 route add ::1/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric | ||
| - | |||
| - | |||
| - | echo " | ||
| - | echo " | ||
| - | chattr +i / | ||
| - | |||
| - | logger Wireguard " | ||
| - | |||
| - | |||
| - | |||
| - | </ | ||
| - | # Save and quit (CTRL+O, CTRL+X) | ||
| - | |||
| - | Remplir le fichier PostDown.sh comme ceci Fill in the PostDown.sh file like this | ||
| - | |||
| - | '' | ||
| - | <code bash> | ||
| - | # PostDown.sh | ||
| - | |||
| - | metric=100 | ||
| - | |||
| - | VPN_GATEWAY_ip4=10.6.0.1 | ||
| - | VPN_GATEWAY_ip6=fd42: | ||
| - | |||
| - | |||
| - | # take the first server' | ||
| - | REMOTEADDRESS_ip4=" | ||
| - | REMOTEADDRESS_ip6=" | ||
| - | ORIGINAL_GATEWAY_ip4=" | ||
| - | ORIGINAL_GATEWAY_ip6=" | ||
| - | INTERFACE=" | ||
| - | |||
| - | ip route del $REMOTEADDRESS_ip4 $ORIGINAL_GATEWAY_ip4 | ||
| - | ip route del $VPN_GATEWAY_ip4 dev $INTERFACE | ||
| - | ip route del 0.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric | ||
| - | ip route del 128.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric | ||
| - | |||
| - | #ip -6 route del $REMOTEADDRESS_ip6 $ORIGINAL_GATEWAY_ip6 | ||
| - | #ip -6 route del $VPN_GATEWAY_ip6 dev $INTERFACE | ||
| - | #ip -6 route del ::/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric | ||
| - | #ip -6 route del ::1/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric | ||
| - | |||
| - | |||
| - | echo " | ||
| - | echo " | ||
| - | chattr -i / | ||
| - | |||
| - | logger Wireguard " | ||
| - | |||
| - | </ | ||
| - | # Save and quit (CTRL+O, CTRL+X) | ||
| - | |||
| - | Rendre les deux scripts exécutables Make both scripts executable | ||
| - | |||
| - | '' | ||
| - | '' | ||
| - | |||
| - | ====== Activer le VPN sur les deux serveurs, Enable VPN on both sides : ====== | ||
| - | |||
| - | Sur le VPS puis sur le serveur YunoHost exécuter les commandes suivantes On the VPS and then on the YunoHost server run the following commands : | ||
| - | |||
| - | '' | ||
| - | '' | ||
| - | |||
| - | Afin de permettre la génération automatique des certificats Let’s Encrypt des domaines/ | ||
| - | <code bash> | ||
| - | ::1 | ||
| - | 127.0.0.1 | ||
| - | </ | ||
| - | |||
| - | ====== Test et déploiement Testing and deployment: ====== | ||
| - | |||
| - | |||
| - | * Assurer vous que votre zone DNS est configurer de sorte que le champs A pointe vers l’IPV4 de votre VPS et le champs AAAA pointe vers l’IPV6 de votre VPS. | ||
| - | * Une fois la propagation DNS effective, vous pouvez configurer les reverse DNS des IPV4 et IPV6 du VPS vers votre nom de domaine sur le site du fournisseur du VPS. | ||
| - | * Faite un diagnostique sur l’API d’administration YunoHost, normalement tout est vert ! | ||
| - | * Make sure that your DNS zone is configured so that the A field points to the IPV4 of your VPS and the AAAA field points to the IPV6 of your VPS. | ||
| - | * Once the DNS propagation is effective, you can configure the reverse DNS of the VPS IPV4 and IPV6 to your domain name on the VPS provider’s website. | ||
| - | * Do a diagnostic on the YunoHost administration API, normally everything is green! | ||
| - | |||
| - | |||
| - | |||