This is an old revision of the document!
source: https://forum.yunohost.org/t/homemade-wireguard-vpn-on-a-vps-server
Fixer les adresses ip publiques dans le fichier interfaces - Set public ip addresses in the interfaces file
(actuelement un proxmox avec un bridge en vmbr0)
sudo nano /etc/network/interfaces
Le fichier doit ressembler à ça - The file should look like this :
auto lo iface lo inet loopback #auto vmbr0 #iface vmbr0 inet static # address 192.168.1.242/24 # gateway 192.168.1.1 # bridge-ports enp0s25 # bridge-stp off # bridge-fd 0 #iface wlp2s0 inet manual auto usb0 iface usb0 inet manual iface usb0 inet6 manual auto enp1s0 iface enp1s0 inet manual iface enp1s0 inet6 manual auto enp2s0f0 iface ensp2s0f0 inet manual iface enp2s0f0 inet6 manual #dell i5 auto eno1 iface eno1 inet manual iface eno1 inet6 manual #R5 auto enp37s0 iface enp37s0 inet manual iface enp37s0 inet6 manual #fujitsu siemens i7 auto enp0s25 iface enp0s25 inet manual iface enp0s25 inet6 manual auto vmbr0 iface vmbr0 inet dhcp bridge-ports enp1s0 enp2s0f0 enp0s25 enp37s0 eno1 usb0 bridge-stp off bridge-fd 0 post-up ip a a 192.168.1.5/24 dev vmbr0 post-up ip a a 2a02:8428:753:5002:97dc:9048:620e:0242/64 dev vmbr0 post-up ip r a default via fe80::ce2d:1bff:feb2:7b38 dev vmbr0 post-up echo "2a02:8428:753:5002:97dc:9048:0:53" >> /etc/resolv.conf post-up nft -f /etc/nftables.conf
# Save and quit (CTRL+O, CTRL+X)
Redémarrer le réseau restart the network
/etc/init.d/networking restart
Autoriser la redirections des paquets IPV4 et IPV6 Allow forwarding of IPV4 and IPV6 packets
sudo nano /etc/sysctl.conf
# Uncomment the following lines: net.ipv4.ip_forward = 1 net.ipv6.conf.all.forwarding = 1
# Save and quit (CTRL+O, CTRL+X)
sudo sysctl -p
Installer Wireguard sur le VPS et sur le serveur YunoHost (Les utilisateurs ayant des versions de Debian plus anciennes que Bullseye doivent d’abord activer les rétroportages) Install Wireguard on the VPS and on the YunoHost server (Users with Debian releases older than Bullseye should first enable backports)
sudo apt install wireguard
WireGuard nécessite des clés publiques et privées codées en base64. Celles-ci peuvent être générées en utilisant l’utilitaire wg. Des deux côtés, faites WireGuard requires base64-encoded public and private keys. These can be generated using the wg utility. On both side do :
cd /etc/wireguard
sudo wg genkey | tee privatekey | wg pubkey > publickey
sudo nano /etc/wireguard/wg-hive.conf
Remplir le fichier wg-hive.conf comme ceci - Fill in the wg-hive.conf file like this
[Interface] Address = 10.6.0.1/24 Address = fd42:42:42::1/64 #SaveConfig = true PostUp = bash /etc/wireguard/PostUp.sh PostDown = bash /etc/wireguard/PostDown.sh ListenPort = 51820 PrivateKey = XXXXXXXXXXXXXXXXXXXXXX [Peer] PublicKey = YYYYYYYYYYYYYYYYYYYYYYY AllowedIPs = 10.6.0.2/32, fd42:42:42::2/128 Endpoint = [2a02:8428:753:5001:cc58:d409:b945:ec40]:51820
# Save and quit (CTRL+O, CTRL+X)
Puis créer et remplir les fichiers PostUp.sh et PostDown.sh comme suit Then create and fill the PostUp.sh and PostDown.sh files as follows :
sudo nano /etc/wireguard/PostUp.sh
Remplir le fichier PostUp.sh comme ceci - Fill in the PostUp.sh file like this
# PostUp.sh IP_CLIENT="10.6.0.1/24" nft -f /etc/nftables.conf logger Wireguard "miou2@wg-hive ($IP_CLIENT)" UP iptables -A FORWARD -i wg-hive -j ACCEPT; iptables -t nat -A POSTROUTING -o vmbr0 -j MASQUERADE; ip6tables -A FORWARD -i wg-hive -j ACCEPT; ip6tables -t nat -A POSTROUTING -o vmbr0 -j MASQUERADE; # icmp iptables -A INPUT -p icmp -j ACCEPT; ip6tables -A INPUT -p ipv6-icmp -j ACCEPT; # Routing TCP port 25 and 587 from Yunohost Server to internet #for j in 25 587 #do # iptables -t nat -A POSTROUTING -s 10.6.0.2 -p tcp --dport $j -j SNAT --to [insert public IPV4 of the VPS]; # iptables -A FORWARD -s 10.6.0.2 -p tcp --dport $j -j ACCEPT; # ip6tables -t nat -A POSTROUTING -s fd42:42:42::2 -p tcp --dport $j -j SNAT --to [insert public IPV6 of the VPS]; # ip6tables -A FORWARD -s fd42:42:42::2 -p tcp --dport $j -j ACCEPT; #done # Routing TCP port required from VPN server to Yunohost server #for i in 25 80 140 443 587 993 5222 5269 #do # iptables -t nat -A PREROUTING -i vmbr0 -p tcp --dport $i -j DNAT --to-destination 10.6.0.2; # iptables -A FORWARD -d 10.6.0.2 -p tcp --dport $i -j ACCEPT; # ip6tables -t nat -A PREROUTING -i vmbr0 -p tcp --dport $i -j DNAT --to-destination fd42:42:42::2; # ip6tables -A FORWARD -d fd42:42:42::2 -p tcp --dport $i -j ACCEPT; #done
# Save and quit (CTRL+O, CTRL+X)
Remplir le fichier PostDown.sh comme ceci Fill in the PostDown.sh file like this
(sachant que chez moi j'ai déjà des règles nftables pour faire du NAT Masquerade)
sudo nano /etc/wireguard/PostDown.sh
# PostDown.sh IP_CLIENT="10.6.0.1/24" nft -f /etc/nftables.conf logger Wireguard "miou2@wg-hive ($IP_CLIENT)" down iptables -D FORWARD -i wg-hive -j ACCEPT; iptables -t nat -D POSTROUTING -o vmbr0 -j MASQUERADE; ip6tables -D FORWARD -i wg-hive -j ACCEPT; ip6tables -t nat -D POSTROUTING -o vmbr0 -j MASQUERADE; # icmp iptables -D INPUT -p icmp -j ACCEPT; ip6tables -D INPUT -p ipv6-icmp -j ACCEPT; # Routing TCP port 25 and 587 from Yunohost Server to internet #for j in 25 587 #do # iptables -t nat -D POSTROUTING -s 10.6.0.2 -p tcp --dport $j -j SNAT --to [insert public IPV4 of the VPS]; # iptables -D FORWARD -s 10.6.0.2 -p tcp --dport $j -j ACCEPT; # ip6tables -t nat -D POSTROUTING -s fd42:42:42::2 -p tcp --dport $j -j SNAT --to [insert public IPV6 of the VPS]; # ip6tables -D FORWARD -s fd42:42:42::2 -p tcp --dport $j -j ACCEPT; #done # # Routing TCP port required from VPN server to Yunohost server #for i in 25 80 140 443 587 993 5222 5269 #do # iptables -t nat -D PREROUTING -i ens192 -p tcp --dport $i -j DNAT --to-destination 10.6.0.2; # iptables -D FORWARD -d 10.6.0.2 -p tcp --dport $i -j ACCEPT; # ip6tables -t nat -D PREROUTING -i ens192 -p tcp --dport $i -j DNAT --to-destination fd42:42:42::2; # ip6tables -D FORWARD -d fd42:42:42::2 -p tcp --dport $i -j ACCEPT; #done
# Save and quit (CTRL+O, CTRL+X)
pour infor, mon fichier /etc/nftables.conf
#!/usr/sbin/nft -f flush ruleset # replace these define if_wan = vmbr0 define if_lan2 = enp2s0 define if_lan3 = enp3s0 # define if_services = br0 define ip4_blocked_ports = { 514, 3000 } define ip6_blocked_ports = { 22, 53, 514, 3000, 8006 } # define tinc_t30 = 10.0.30.0/24 # define tinc_port_t30 = 2345 # define tinc_net_t30 = "t30" define tinc_t42 = 10.42.0.0/24 define tinc_port_t42 = 2346 define tinc_net_t42 = "t42" define tinc_hive = 172.18.42.0/24 define tinc_port_hive = 2347 define tinc_net_hive = "hive" define tinc_err404_routed = 10.27.0.0/24 define tinc_port_err404_routed = 8345 define tinc_net_err404_routed = "err404_routed" define wg_hive_ip4 = 10.6.0.0/24 define wg_hive_ip6 = fd42:42:42::/64 define wg_port_hive = 51820 define wg_net_hive = "wg-hive" # cette chaine fonctionne pour ipv4 et ipv6, or j'ai besoin de faire la différence entre les ports à ouvrir #table inet filter { ## # ... other sections ... # chain incoming { ## type filter hook input priority 0; policy drop; # type filter hook input priority 0; policy accept; # # # Accept any localhost traffic: # iif lo accept # # # ... other rules for other services that are running in this server ... # tcp dport { $blocked_ports } iif $if_wan drop # udp dport { $blocked_ports } iif $if_wan drop # } # chain outgoing { # type filter hook output priority 0; policy accept; # } # chain forward { # type filter hook forward priority 0; policy accept; # } #} table ip filter { chain incoming { type filter hook input priority 0; policy accept; tcp dport { $ip4_blocked_ports } iif $if_wan drop udp dport { $ip4_blocked_ports } iif $if_wan drop } chain FORWARD { type filter hook forward priority 0; policy accept; } chain outgoing { type filter hook output priority 0; policy accept; } } table ip6 filter { chain incoming { type filter hook input priority 0; policy accept; udp dport { $ip6_blocked_ports } iif $if_wan drop tcp dport { $ip6_blocked_ports } iif $if_wan drop } chain FORWARD { type filter hook forward priority 0; policy accept; } chain outgoing { type filter hook output priority 0; policy accept; } } # Finally, NAT! table ip firewall { # chain prerouting { # type nat hook prerouting priority 0; # Port forward tcp 80/443 to our internal webserver # iifname $if_wan tcp dport { http, https } dnat to "192.168.1.100" comment "DNAT to webserver" # } #### POSTROUTING chain postrouting { type nat hook postrouting priority 100; # ip saddr $net_lan2 oifname $if_wan masquerade # ip saddr $net_lan3 oifname $if_wan masquerade # iif $if_lan2 oifname $if_wan masquerade # iif $if_lan3 oifname $if_wan masquerade # iif $tinc_net_err404_routed oifname $if_wan masquerade # iif $tinc_net_t42 oifname $if_wan masquerade iif $tinc_net_hive oifname $if_wan masquerade iif $wg_net_hive oifname $if_wan masquerade }
Rendre les deux scripts exécutables Make both scripts executable
sudo chmod +x /etc/wireguard/PostUp.sh
sudo chmod +x /etc/wireguard/PostDown.sh
sudo nano /etc/wireguard/wg-hive.conf
(j'ai pas encore testé la config DNS vu que je force la config dns dans le fichier PostUp.sh)
Remplir le fichier wg-hive.conf comme ceci Fill in the wg-hive.conf file like this
[Interface] Address = 10.6.0.1/24 Address = fd42:42:42::1/64 #SaveConfig = true PostUp = bash /etc/wireguard/PostUp.sh PostDown = bash /etc/wireguard/PostDown.sh ListenPort = 51820 PrivateKey = ZZZZZZZZZZZZZZZZZZZZZZZZ # choose your DNS - for instance FDN DNS resolver #DNS = 80.67.169.12, 2001:910:800::12 [Peer] #miou2 PublicKey = WWWWWWWWWWWWWWWWWWWWWWWWW AllowedIPs = 10.6.0.2/32, fd42:42:42::2/128 Endpoint = [2a02:8428:753:5001:cc58:d409:b945:ec40]:51820
# Save and quit (CTRL+O, CTRL+X)
Remplir le fichier PostUp.sh comme ceci Fill in the PostUp.sh file like this
sudo nano /etc/wireguard/PostUp.sh
# PostUp.sh metric=100 VPN_GATEWAY_ip4=10.6.0.1 VPN_GATEWAY_ip6=fd42:42:42::1 # take the first server's tinc_ip as vpn gateway REMOTEADDRESS_ip4="$(ip route show | grep ^default | cut -d ' ' -f 3)" REMOTEADDRESS_ip6="$(ip -6 route show | grep ^default | cut -d ' ' -f 3)" ORIGINAL_GATEWAY_ip4="$(ip route show | grep ^default | cut -d ' ' -f 2-5)" ORIGINAL_GATEWAY_ip6="$(ip -6 route show | grep ^default | cut -d ' ' -f 2-5)" INTERFACE="wg-hive" ip route add $REMOTEADDRESS_ip4 $ORIGINAL_GATEWAY_ip4 ip route add $VPN_GATEWAY_ip4 dev $INTERFACE ip route add 0.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric ip route add 128.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric #ip -6 route add $REMOTEADDRESS_ip6 $ORIGINAL_GATEWAY_ip6 #ip -6 route add $VPN_GATEWAY_ip6 dev $INTERFACE #ip -6 route add ::/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric #ip -6 route add ::1/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric echo "nameserver 10.6.0.1" > /etc/resolv.conf echo "nameserver fd42:42:42::1" >> /etc/resolv.conf chattr +i /etc/resolv.conf logger Wireguard "e17@wg-hive" UP metric $metric
# Save and quit (CTRL+O, CTRL+X)
Remplir le fichier PostDown.sh comme ceci Fill in the PostDown.sh file like this
sudo nano /etc/wireguard/PostDown.sh
# PostDown.sh metric=100 VPN_GATEWAY_ip4=10.6.0.1 VPN_GATEWAY_ip6=fd42:42:42::1 # take the first server's tinc_ip as vpn gateway REMOTEADDRESS_ip4="$(ip route show | grep ^default | cut -d ' ' -f 3)" REMOTEADDRESS_ip6="$(ip -6 route show | grep ^default | cut -d ' ' -f 3)" ORIGINAL_GATEWAY_ip4="$(ip route show | grep ^default | cut -d ' ' -f 2-5)" ORIGINAL_GATEWAY_ip6="$(ip -6 route show | grep ^default | cut -d ' ' -f 2-5)" INTERFACE="wg-hive" ip route del $REMOTEADDRESS_ip4 $ORIGINAL_GATEWAY_ip4 ip route del $VPN_GATEWAY_ip4 dev $INTERFACE ip route del 0.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric ip route del 128.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric #ip -6 route del $REMOTEADDRESS_ip6 $ORIGINAL_GATEWAY_ip6 #ip -6 route del $VPN_GATEWAY_ip6 dev $INTERFACE #ip -6 route del ::/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric #ip -6 route del ::1/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric echo "nameserver 10.6.0.1" > /etc/resolv.conf echo "nameserver fd42:42:42::1" >> /etc/resolv.conf chattr -i /etc/resolv.conf logger Wireguard "e17@wg-hive" down metric $metric
# Save and quit (CTRL+O, CTRL+X)
Rendre les deux scripts exécutables Make both scripts executable
sudo chmod +x /etc/wireguard/PostUp.sh
sudo chmod +x /etc/wireguard/PostDown.sh
Sur le VPS puis sur le serveur YunoHost exécuter les commandes suivantes On the VPS and then on the YunoHost server run the following commands :
sudo systemctl start wg-quick@wg-hive.service
sudo systemctl enable wg-quick@wg-hive.service
Afin de permettre la génération automatique des certificats Let’s Encrypt des domaines/sous-domaines associés à votre serveur YunoHost, vous devez ajouter les lignes suivantes à votre fichier Hosts sur le serveur YunoHost (sudo nano /etc/hosts) In order to enable automatic generation of Let’s Encrypt certificates for domains/subdomains associated with your YunoHost server, you must add the following lines to your Hosts file on the YunoHost server (sudo nano /etc/hosts):
::1 domain.tld
127.0.0.1 domain.tld