Site Tools


Misc:Wireguard_je64nr567asjkef34nsfrg:start

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Misc:Wireguard_je64nr567asjkef34nsfrg:start [2025/10/23 10:49] – created err404 Misc:Wireguard_je64nr567asjkef34nsfrg:start [2025/10/23 10:49] (current) – removed err404
Line 1: Line 1:
-source: https://forum.yunohost.org/t/homemade-wireguard-vpn-on-a-vps-server 
-====== sur le nœud de sortie ====== 
-==== Configurer le nœud de sortie ==== 
- 
- 
-Fixer les adresses ip publiques dans le fichier interfaces - Set public ip addresses in the interfaces file 
-(actuelement un proxmox avec un bridge en vmbr0) 
- 
-''sudo nano /etc/network/interfaces'' 
- 
-Le fichier doit ressembler à ça - The file should look like this : 
-<code bash> 
-auto lo 
-iface lo inet loopback 
- 
-#auto vmbr0 
-#iface vmbr0 inet static 
-#       address 192.168.1.242/24 
-#       gateway 192.168.1.1 
-#       bridge-ports enp0s25 
-#       bridge-stp off 
-#       bridge-fd 0 
- 
-#iface wlp2s0 inet manual 
- 
-auto usb0 
-iface usb0 inet manual 
-iface usb0 inet6 manual 
- 
-auto enp1s0 
-iface enp1s0 inet manual 
-iface enp1s0 inet6 manual 
- 
-auto enp2s0f0 
-iface ensp2s0f0 inet manual 
-iface enp2s0f0 inet6 manual 
- 
-#dell i5 
-auto eno1 
-iface eno1 inet manual 
-iface eno1 inet6 manual 
- 
-#R5 
-auto enp37s0 
-iface enp37s0 inet manual 
-iface enp37s0 inet6 manual 
- 
-#fujitsu siemens i7 
-auto enp0s25 
-iface enp0s25 inet manual 
-iface enp0s25 inet6 manual 
- 
- 
-auto vmbr0 
-iface vmbr0 inet dhcp 
-        bridge-ports enp1s0 enp2s0f0 enp0s25 enp37s0 eno1 usb0 
-        bridge-stp off 
-        bridge-fd 0 
-        post-up ip a a 192.168.1.5/24 dev vmbr0 
-        post-up ip a a 2a02:8428:753:5002:97dc:9048:620e:0242/64 dev vmbr0 
-        post-up ip r a default via fe80::ce2d:1bff:feb2:7b38 dev vmbr0 
-        post-up echo "2a02:8428:753:5002:97dc:9048:0:53" >> /etc/resolv.conf 
-        post-up nft -f /etc/nftables.conf 
- 
-</code>        
-# Save and quit (CTRL+O, CTRL+X) 
- 
-Redémarrer le réseau restart the network 
- 
-''/etc/init.d/networking restart'' 
- 
-Autoriser la redirections des paquets IPV4 et IPV6 Allow forwarding of IPV4 and IPV6 packets 
- 
-''sudo nano /etc/sysctl.conf'' 
-<code bash> 
-# Uncomment the following lines: 
-net.ipv4.ip_forward = 1 
-net.ipv6.conf.all.forwarding = 1 
-</code> 
-# Save and quit (CTRL+O, CTRL+X) 
- 
-''sudo sysctl -p'' 
- 
-==== Installation et configuration de Wireguard - installation and configuration of Wireguard : ===== 
- 
-Installer Wireguard sur le VPS et sur le serveur YunoHost (Les utilisateurs ayant des versions de Debian plus anciennes que Bullseye doivent d’abord activer les rétroportages) Install Wireguard on the VPS and on the YunoHost server (Users with Debian releases older than Bullseye should first enable backports) 
- 
-''sudo apt install wireguard'' 
- 
-WireGuard nécessite des clés publiques et privées codées en base64. Celles-ci peuvent être générées en utilisant l’utilitaire wg. Des deux côtés, faites WireGuard requires base64-encoded public and private keys. These can be generated using the wg utility. On both side do : 
- 
-''cd /etc/wireguard'' 
-''sudo wg genkey | tee privatekey | wg pubkey > publickey'' 
- 
-==== Configurer Wireguard sur le nœud de sortie - Configure Wireguard on the exit node : ==== 
- 
-''sudo nano /etc/wireguard/wg-hive.conf'' 
- 
-Remplir le fichier ''wg-hive.conf'' comme ceci - Fill in the ''wg-hive.conf'' file like this 
- 
-<code bash> 
-[Interface] 
-Address = 10.6.0.1/24 
-Address = fd42:42:42::1/64 
-#SaveConfig = true 
-PostUp = bash /etc/wireguard/PostUp.sh 
-PostDown = bash /etc/wireguard/PostDown.sh 
-ListenPort = 51820 
-PrivateKey = XXXXXXXXXXXXXXXXXXXXXX 
- 
- 
-[Peer] 
-PublicKey = YYYYYYYYYYYYYYYYYYYYYYY 
-AllowedIPs = 10.6.0.2/32, fd42:42:42::2/128 
-Endpoint = [2a02:8428:753:5001:cc58:d409:b945:ec40]:51820 
- 
- 
-</code> 
-# Save and quit (CTRL+O, CTRL+X) 
- 
-Puis créer et remplir les fichiers PostUp.sh et PostDown.sh comme suit Then create and fill the PostUp.sh and PostDown.sh files as follows : 
- 
-''sudo nano /etc/wireguard/PostUp.sh'' 
- 
-Remplir le fichier PostUp.sh comme ceci - Fill in the PostUp.sh file like this 
-<code bash> 
-# PostUp.sh 
- 
-IP_CLIENT="10.6.0.1/24" 
- 
-nft -f /etc/nftables.conf 
- 
-logger Wireguard "miou2@wg-hive ($IP_CLIENT)" UP 
- 
-iptables -A FORWARD -i wg-hive -j ACCEPT; 
-iptables -t nat -A POSTROUTING -o vmbr0 -j MASQUERADE; 
-ip6tables -A FORWARD -i wg-hive -j ACCEPT; 
-ip6tables -t nat -A POSTROUTING -o vmbr0 -j MASQUERADE; 
- 
-# icmp 
-iptables -A INPUT -p icmp -j ACCEPT; 
-ip6tables -A INPUT -p ipv6-icmp -j ACCEPT; 
- 
-# Routing TCP port 25 and 587 from Yunohost Server to internet 
-#for j in 25 587 
-#do 
-#       iptables -t nat -A POSTROUTING -s 10.6.0.2 -p tcp --dport $j -j SNAT --to [insert public IPV4 of the VPS]; 
-#       iptables -A FORWARD -s 10.6.0.2 -p tcp --dport $j -j ACCEPT; 
-#       ip6tables -t nat -A POSTROUTING -s fd42:42:42::2 -p tcp --dport $j -j SNAT --to [insert public IPV6 of the VPS]; 
-#       ip6tables -A FORWARD -s fd42:42:42::2 -p tcp --dport $j -j ACCEPT; 
-#done 
- 
-# Routing TCP port required from VPN server to Yunohost server 
-#for i in 25 80 140 443 587 993 5222 5269 
-#do 
-#       iptables -t nat -A PREROUTING -i vmbr0 -p tcp --dport $i -j DNAT --to-destination 10.6.0.2; 
-#       iptables -A FORWARD -d 10.6.0.2 -p tcp --dport $i -j ACCEPT; 
-#       ip6tables -t nat -A PREROUTING -i vmbr0 -p tcp --dport $i -j DNAT --to-destination fd42:42:42::2; 
-#       ip6tables -A FORWARD -d fd42:42:42::2 -p tcp --dport $i -j ACCEPT; 
-#done 
- 
- 
-</code> 
-# Save and quit (CTRL+O, CTRL+X) 
- 
-Remplir le fichier PostDown.sh comme ceci Fill in the PostDown.sh file like this 
-(sachant que chez moi j'ai déjà des règles nftables pour faire du NAT Masquerade) 
-''sudo nano /etc/wireguard/PostDown.sh'' 
-<code bash> 
-# PostDown.sh 
- 
- 
-IP_CLIENT="10.6.0.1/24" 
- 
-nft -f /etc/nftables.conf 
- 
-logger Wireguard "miou2@wg-hive ($IP_CLIENT)" down 
- 
- 
-iptables -D FORWARD -i wg-hive -j ACCEPT; 
-iptables -t nat -D POSTROUTING -o vmbr0 -j MASQUERADE; 
-ip6tables -D FORWARD -i wg-hive -j ACCEPT; 
-ip6tables -t nat -D POSTROUTING -o vmbr0 -j MASQUERADE; 
- 
-# icmp 
-iptables -D INPUT -p icmp -j ACCEPT; 
-ip6tables -D INPUT -p ipv6-icmp -j ACCEPT; 
- 
-# Routing TCP port 25 and 587 from Yunohost Server to internet 
-#for j in 25 587 
-#do 
-#       iptables -t nat -D POSTROUTING -s 10.6.0.2 -p tcp --dport $j -j SNAT --to [insert public IPV4 of the VPS]; 
-#       iptables -D FORWARD -s 10.6.0.2 -p tcp --dport $j -j ACCEPT; 
-#       ip6tables -t nat -D POSTROUTING -s fd42:42:42::2 -p tcp --dport $j -j SNAT --to [insert public IPV6 of the VPS]; 
-#       ip6tables -D FORWARD -s fd42:42:42::2 -p tcp --dport $j -j ACCEPT; 
-#done 
-# 
-# Routing TCP port required from VPN server to Yunohost server 
-#for i in 25 80 140 443 587 993 5222 5269 
-#do 
-#       iptables -t nat -D PREROUTING -i ens192 -p tcp --dport $i -j DNAT --to-destination 10.6.0.2; 
-#       iptables -D FORWARD -d 10.6.0.2 -p tcp --dport $i -j ACCEPT; 
-#       ip6tables -t nat -D PREROUTING -i ens192 -p tcp --dport $i -j DNAT --to-destination fd42:42:42::2; 
-#       ip6tables -D FORWARD -d fd42:42:42::2 -p tcp --dport $i -j ACCEPT; 
-#done 
- 
- 
-</code> 
-# Save and quit (CTRL+O, CTRL+X) 
- 
-pour infor, mon fichier /etc/nftables.conf 
- 
-<code bash> 
-#!/usr/sbin/nft -f 
-flush ruleset 
- 
-  # replace these 
-  define if_wan = vmbr0 
-  define if_lan2 = enp2s0 
-  define if_lan3 = enp3s0 
-#  define if_services = br0 
- 
-define ip4_blocked_ports = { 514, 3000 } 
-define ip6_blocked_ports = { 22, 53, 514, 3000, 8006 } 
- 
-# define tinc_t30 = 10.0.30.0/24 
-# define tinc_port_t30 = 2345 
-# define tinc_net_t30 = "t30" 
- 
- define tinc_t42 = 10.42.0.0/24 
- define tinc_port_t42 = 2346 
- define tinc_net_t42 = "t42" 
- 
- define tinc_hive = 172.18.42.0/24 
- define tinc_port_hive = 2347 
- define tinc_net_hive = "hive" 
- 
- define tinc_err404_routed = 10.27.0.0/24 
- define tinc_port_err404_routed = 8345 
- define tinc_net_err404_routed = "err404_routed" 
- 
- define wg_hive_ip4 = 10.6.0.0/24 
- define wg_hive_ip6 = fd42:42:42::/64 
- define wg_port_hive = 51820 
- define wg_net_hive = "wg-hive" 
- 
- 
-# cette chaine fonctionne pour ipv4 et ipv6, or j'ai besoin de faire la différence entre les ports à ouvrir 
-#table inet filter { 
-##        # ... other sections ... 
-#        chain incoming { 
-##                type filter hook input priority 0; policy drop; 
-#                type filter hook input priority 0; policy accept; 
-# 
-#                # Accept any localhost traffic: 
-#                iif lo accept 
-# 
-#                # ... other rules for other services that are running in this server ... 
-#                tcp dport { $blocked_ports } iif $if_wan drop 
-#                udp dport { $blocked_ports } iif $if_wan drop 
-#        } 
-#        chain outgoing { 
-#                type filter hook output priority 0; policy accept; 
-#        } 
-#        chain forward { 
-#                type filter hook forward priority 0; policy accept; 
-#        } 
-#} 
- 
- 
-table ip filter { 
-        chain incoming { 
-                type filter hook input priority 0; policy accept; 
-                tcp dport { $ip4_blocked_ports } iif $if_wan drop 
-                udp dport { $ip4_blocked_ports } iif $if_wan drop 
-        } 
- 
-        chain FORWARD { 
-                type filter hook forward priority 0; policy accept; 
-        } 
- 
-        chain outgoing { 
-                type filter hook output priority 0; policy accept; 
-        } 
-} 
- 
- 
-table ip6 filter { 
-        chain incoming { 
-                type filter hook input priority 0; policy accept; 
-                udp dport { $ip6_blocked_ports } iif $if_wan drop 
-                tcp dport { $ip6_blocked_ports } iif $if_wan drop 
-        } 
-        chain FORWARD { 
-                type filter hook forward priority 0; policy accept; 
-        } 
-        chain outgoing { 
-                type filter hook output priority 0; policy accept; 
-        } 
-} 
-# Finally, NAT! 
-table ip firewall { 
-#    chain prerouting { 
-#      type nat hook prerouting priority 0; 
- 
-      # Port forward tcp 80/443 to our internal webserver 
-#      iifname $if_wan tcp dport { http, https } dnat to "192.168.1.100" comment "DNAT to webserver" 
-#    } 
- 
-  #### POSTROUTING 
-  chain postrouting { 
-    type nat hook postrouting priority 100; 
- 
- 
-#    ip saddr $net_lan2         oifname $if_wan masquerade 
-#    ip saddr $net_lan3         oifname $if_wan masquerade 
-#    iif $if_lan2                oifname $if_wan masquerade 
-#    iif $if_lan3                oifname $if_wan masquerade 
- 
-#    iif $tinc_net_err404_routed oifname $if_wan masquerade 
-#    iif $tinc_net_t42           oifname $if_wan masquerade 
-    iif $tinc_net_hive          oifname $if_wan masquerade 
-    iif $wg_net_hive            oifname $if_wan masquerade 
- 
-  } 
- 
-</code> 
- 
-Rendre les deux scripts exécutables Make both scripts executable 
- 
-''sudo chmod +x /etc/wireguard/PostUp.sh'' 
-''sudo chmod +x /etc/wireguard/PostDown.sh'' 
- 
-====== sur le client nomade ====== 
-==== Configurer Wireguard sur le client nomade - Configure Wireguard on the nomade client : ==== 
- 
-''sudo nano /etc/wireguard/wg-hive.conf'' 
-(j'ai pas encore testé la config DNS vu que je force la config dns dans le fichier PostUp.sh) 
-Remplir le fichier wg-hive.conf comme ceci Fill in the wg-hive.conf file like this 
-<code bash> 
-[Interface] 
-Address = 10.6.0.1/24 
-Address = fd42:42:42::1/64 
-#SaveConfig = true 
-PostUp = bash /etc/wireguard/PostUp.sh 
-PostDown = bash /etc/wireguard/PostDown.sh 
-ListenPort = 51820 
-PrivateKey = ZZZZZZZZZZZZZZZZZZZZZZZZ 
-# choose your DNS - for instance FDN DNS resolver 
-#DNS = 80.67.169.12, 2001:910:800::12 
- 
-[Peer] 
-#miou2 
-PublicKey = WWWWWWWWWWWWWWWWWWWWWWWWW 
-AllowedIPs = 10.6.0.2/32, fd42:42:42::2/128 
-Endpoint = [2a02:8428:753:5001:cc58:d409:b945:ec40]:51820 
- 
-</code> 
-# Save and quit (CTRL+O, CTRL+X) 
- 
-Remplir le fichier PostUp.sh comme ceci Fill in the PostUp.sh file like this 
- 
-''sudo nano /etc/wireguard/PostUp.sh'' 
-<code bash> 
-# PostUp.sh 
- 
-metric=100 
- 
-VPN_GATEWAY_ip4=10.6.0.1 
-VPN_GATEWAY_ip6=fd42:42:42::1 
- 
-# take the first server's tinc_ip as vpn gateway 
-REMOTEADDRESS_ip4="$(ip route show | grep ^default | cut -d ' ' -f 3)" 
-REMOTEADDRESS_ip6="$(ip -6 route show | grep ^default | cut -d ' ' -f 3)" 
-ORIGINAL_GATEWAY_ip4="$(ip route show | grep ^default | cut -d ' ' -f 2-5)" 
-ORIGINAL_GATEWAY_ip6="$(ip -6 route show | grep ^default | cut -d ' ' -f 2-5)" 
-INTERFACE="wg-hive" 
- 
-ip route add $REMOTEADDRESS_ip4 $ORIGINAL_GATEWAY_ip4 
-ip route add $VPN_GATEWAY_ip4 dev $INTERFACE 
-ip route add 0.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric 
-ip route add 128.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric 
- 
-#ip -6 route add $REMOTEADDRESS_ip6 $ORIGINAL_GATEWAY_ip6 
-#ip -6 route add $VPN_GATEWAY_ip6 dev $INTERFACE 
-#ip -6 route add ::/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric 
-#ip -6 route add ::1/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric 
- 
- 
-echo "nameserver 10.6.0.1" > /etc/resolv.conf  
-echo "nameserver fd42:42:42::1" >> /etc/resolv.conf  
-chattr +i /etc/resolv.conf 
- 
-logger Wireguard "e17@wg-hive" UP metric $metric 
- 
- 
- 
-</code> 
-# Save and quit (CTRL+O, CTRL+X) 
- 
-Remplir le fichier PostDown.sh comme ceci Fill in the PostDown.sh file like this 
- 
-''sudo nano /etc/wireguard/PostDown.sh'' 
-<code bash> 
-# PostDown.sh 
- 
-metric=100 
- 
-VPN_GATEWAY_ip4=10.6.0.1 
-VPN_GATEWAY_ip6=fd42:42:42::1 
- 
- 
-# take the first server's tinc_ip as vpn gateway 
-REMOTEADDRESS_ip4="$(ip route show | grep ^default | cut -d ' ' -f 3)" 
-REMOTEADDRESS_ip6="$(ip -6 route show | grep ^default | cut -d ' ' -f 3)" 
-ORIGINAL_GATEWAY_ip4="$(ip route show | grep ^default | cut -d ' ' -f 2-5)" 
-ORIGINAL_GATEWAY_ip6="$(ip -6 route show | grep ^default | cut -d ' ' -f 2-5)" 
-INTERFACE="wg-hive" 
- 
-ip route del $REMOTEADDRESS_ip4 $ORIGINAL_GATEWAY_ip4 
-ip route del $VPN_GATEWAY_ip4 dev $INTERFACE 
-ip route del 0.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric 
-ip route del 128.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric 
- 
-#ip -6 route del $REMOTEADDRESS_ip6 $ORIGINAL_GATEWAY_ip6 
-#ip -6 route del $VPN_GATEWAY_ip6 dev $INTERFACE 
-#ip -6 route del ::/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric 
-#ip -6 route del ::1/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric 
- 
- 
-echo "nameserver 10.6.0.1" > /etc/resolv.conf 
-echo "nameserver fd42:42:42::1" >> /etc/resolv.conf 
-chattr -i /etc/resolv.conf 
- 
-logger Wireguard "e17@wg-hive" down metric $metric 
- 
-</code> 
-# Save and quit (CTRL+O, CTRL+X) 
- 
-Rendre les deux scripts exécutables Make both scripts executable 
- 
-''sudo chmod +x /etc/wireguard/PostUp.sh'' 
-''sudo chmod +x /etc/wireguard/PostDown.sh'' 
- 
-====== Activer le VPN sur les deux serveurs, Enable VPN on both sides : ====== 
- 
-Sur le VPS puis sur le serveur YunoHost exécuter les commandes suivantes On the VPS and then on the YunoHost server run the following commands : 
- 
-''sudo systemctl start wg-quick@wg-hive.service'' 
-''sudo systemctl enable wg-quick@wg-hive.service'' 
- 
-Afin de permettre la génération automatique des certificats Let’s Encrypt des domaines/sous-domaines associés à votre serveur YunoHost, vous devez ajouter les lignes suivantes à votre fichier Hosts sur le serveur YunoHost (sudo nano /etc/hosts) In order to enable automatic generation of Let’s Encrypt certificates for domains/subdomains associated with your YunoHost server, you must add the following lines to your Hosts file on the YunoHost server (sudo nano /etc/hosts): 
-<code bash> 
-::1         domain.tld 
-127.0.0.1   domain.tld 
-</code> 
- 
-====== Test et déploiement Testing and deployment: ====== 
- 
- 
-  * Assurer vous que votre zone DNS est configurer de sorte que le champs A pointe vers l’IPV4 de votre VPS et le champs AAAA pointe vers l’IPV6 de votre VPS. 
-  * Une fois la propagation DNS effective, vous pouvez configurer les reverse DNS des IPV4 et IPV6 du VPS vers votre nom de domaine sur le site du fournisseur du VPS. 
-  * Faite un diagnostique sur l’API d’administration YunoHost, normalement tout est vert ! 
-  * Make sure that your DNS zone is configured so that the A field points to the IPV4 of your VPS and the AAAA field points to the IPV6 of your VPS. 
-  * Once the DNS propagation is effective, you can configure the reverse DNS of the VPS IPV4 and IPV6 to your domain name on the VPS provider’s website. 
-  * Do a diagnostic on the YunoHost administration API, normally everything is green! 
- 
- 
-