Site Tools


Misc:Wireguard_je64nr567asjkef34nsfrg:start

This is an old revision of the document!


source: https://forum.yunohost.org/t/homemade-wireguard-vpn-on-a-vps-server

sur le nœud de sortie

Configurer le nœud de sortie

Fixer les adresses ip publiques dans le fichier interfaces - Set public ip addresses in the interfaces file
(actuelement un proxmox avec un bridge en vmbr0)

sudo nano /etc/network/interfaces

Le fichier doit ressembler à ça - The file should look like this :

auto lo
iface lo inet loopback
 
#auto vmbr0
#iface vmbr0 inet static
#       address 192.168.1.242/24
#       gateway 192.168.1.1
#       bridge-ports enp0s25
#       bridge-stp off
#       bridge-fd 0
 
#iface wlp2s0 inet manual
 
auto usb0
iface usb0 inet manual
iface usb0 inet6 manual
 
auto enp1s0
iface enp1s0 inet manual
iface enp1s0 inet6 manual
 
auto enp2s0f0
iface ensp2s0f0 inet manual
iface enp2s0f0 inet6 manual
 
#dell i5
auto eno1
iface eno1 inet manual
iface eno1 inet6 manual
 
#R5
auto enp37s0
iface enp37s0 inet manual
iface enp37s0 inet6 manual
 
#fujitsu siemens i7
auto enp0s25
iface enp0s25 inet manual
iface enp0s25 inet6 manual
 
 
auto vmbr0
iface vmbr0 inet dhcp
        bridge-ports enp1s0 enp2s0f0 enp0s25 enp37s0 eno1 usb0
        bridge-stp off
        bridge-fd 0
        post-up ip a a 192.168.1.5/24 dev vmbr0
        post-up ip a a 2a02:8428:753:5002:97dc:9048:620e:0242/64 dev vmbr0
        post-up ip r a default via fe80::ce2d:1bff:feb2:7b38 dev vmbr0
        post-up echo "2a02:8428:753:5002:97dc:9048:0:53" >> /etc/resolv.conf
        post-up nft -f /etc/nftables.conf


# Save and quit (CTRL+O, CTRL+X)

Redémarrer le réseau restart the network

/etc/init.d/networking restart

Autoriser la redirections des paquets IPV4 et IPV6 Allow forwarding of IPV4 and IPV6 packets

sudo nano /etc/sysctl.conf

# Uncomment the following lines:
net.ipv4.ip_forward = 1
net.ipv6.conf.all.forwarding = 1

# Save and quit (CTRL+O, CTRL+X)

sudo sysctl -p

Installation et configuration de Wireguard - installation and configuration of Wireguard :

Installer Wireguard sur le VPS et sur le serveur YunoHost (Les utilisateurs ayant des versions de Debian plus anciennes que Bullseye doivent d’abord activer les rétroportages) Install Wireguard on the VPS and on the YunoHost server (Users with Debian releases older than Bullseye should first enable backports)

sudo apt install wireguard

WireGuard nécessite des clés publiques et privées codées en base64. Celles-ci peuvent être générées en utilisant l’utilitaire wg. Des deux côtés, faites WireGuard requires base64-encoded public and private keys. These can be generated using the wg utility. On both side do :

cd /etc/wireguard
sudo wg genkey | tee privatekey | wg pubkey > publickey

Configurer Wireguard sur le nœud de sortie - Configure Wireguard on the exit node :

sudo nano /etc/wireguard/wg-hive.conf

Remplir le fichier wg-hive.conf comme ceci - Fill in the wg-hive.conf file like this

[Interface]
Address = 10.6.0.1/24
Address = fd42:42:42::1/64
#SaveConfig = true
PostUp = bash /etc/wireguard/PostUp.sh
PostDown = bash /etc/wireguard/PostDown.sh
ListenPort = 51820
PrivateKey = XXXXXXXXXXXXXXXXXXXXXX
 
 
[Peer]
PublicKey = YYYYYYYYYYYYYYYYYYYYYYY
AllowedIPs = 10.6.0.2/32, fd42:42:42::2/128
Endpoint = [2a02:8428:753:5001:cc58:d409:b945:ec40]:51820

# Save and quit (CTRL+O, CTRL+X)

Puis créer et remplir les fichiers PostUp.sh et PostDown.sh comme suit Then create and fill the PostUp.sh and PostDown.sh files as follows :

sudo nano /etc/wireguard/PostUp.sh

Remplir le fichier PostUp.sh comme ceci - Fill in the PostUp.sh file like this

# PostUp.sh
 
IP_CLIENT="10.6.0.1/24"
 
nft -f /etc/nftables.conf
 
logger Wireguard "miou2@wg-hive ($IP_CLIENT)" UP
 
iptables -A FORWARD -i wg-hive -j ACCEPT;
iptables -t nat -A POSTROUTING -o vmbr0 -j MASQUERADE;
ip6tables -A FORWARD -i wg-hive -j ACCEPT;
ip6tables -t nat -A POSTROUTING -o vmbr0 -j MASQUERADE;
 
# icmp
iptables -A INPUT -p icmp -j ACCEPT;
ip6tables -A INPUT -p ipv6-icmp -j ACCEPT;
 
# Routing TCP port 25 and 587 from Yunohost Server to internet
#for j in 25 587
#do
#       iptables -t nat -A POSTROUTING -s 10.6.0.2 -p tcp --dport $j -j SNAT --to [insert public IPV4 of the VPS];
#       iptables -A FORWARD -s 10.6.0.2 -p tcp --dport $j -j ACCEPT;
#       ip6tables -t nat -A POSTROUTING -s fd42:42:42::2 -p tcp --dport $j -j SNAT --to [insert public IPV6 of the VPS];
#       ip6tables -A FORWARD -s fd42:42:42::2 -p tcp --dport $j -j ACCEPT;
#done
 
# Routing TCP port required from VPN server to Yunohost server
#for i in 25 80 140 443 587 993 5222 5269
#do
#       iptables -t nat -A PREROUTING -i vmbr0 -p tcp --dport $i -j DNAT --to-destination 10.6.0.2;
#       iptables -A FORWARD -d 10.6.0.2 -p tcp --dport $i -j ACCEPT;
#       ip6tables -t nat -A PREROUTING -i vmbr0 -p tcp --dport $i -j DNAT --to-destination fd42:42:42::2;
#       ip6tables -A FORWARD -d fd42:42:42::2 -p tcp --dport $i -j ACCEPT;
#done

# Save and quit (CTRL+O, CTRL+X)

Remplir le fichier PostDown.sh comme ceci Fill in the PostDown.sh file like this
(sachant que chez moi j'ai déjà des règles nftables pour faire du NAT Masquerade)
sudo nano /etc/wireguard/PostDown.sh

# PostDown.sh
 
 
IP_CLIENT="10.6.0.1/24"
 
nft -f /etc/nftables.conf
 
logger Wireguard "miou2@wg-hive ($IP_CLIENT)" down
 
 
iptables -D FORWARD -i wg-hive -j ACCEPT;
iptables -t nat -D POSTROUTING -o vmbr0 -j MASQUERADE;
ip6tables -D FORWARD -i wg-hive -j ACCEPT;
ip6tables -t nat -D POSTROUTING -o vmbr0 -j MASQUERADE;
 
# icmp
iptables -D INPUT -p icmp -j ACCEPT;
ip6tables -D INPUT -p ipv6-icmp -j ACCEPT;
 
# Routing TCP port 25 and 587 from Yunohost Server to internet
#for j in 25 587
#do
#       iptables -t nat -D POSTROUTING -s 10.6.0.2 -p tcp --dport $j -j SNAT --to [insert public IPV4 of the VPS];
#       iptables -D FORWARD -s 10.6.0.2 -p tcp --dport $j -j ACCEPT;
#       ip6tables -t nat -D POSTROUTING -s fd42:42:42::2 -p tcp --dport $j -j SNAT --to [insert public IPV6 of the VPS];
#       ip6tables -D FORWARD -s fd42:42:42::2 -p tcp --dport $j -j ACCEPT;
#done
#
# Routing TCP port required from VPN server to Yunohost server
#for i in 25 80 140 443 587 993 5222 5269
#do
#       iptables -t nat -D PREROUTING -i ens192 -p tcp --dport $i -j DNAT --to-destination 10.6.0.2;
#       iptables -D FORWARD -d 10.6.0.2 -p tcp --dport $i -j ACCEPT;
#       ip6tables -t nat -D PREROUTING -i ens192 -p tcp --dport $i -j DNAT --to-destination fd42:42:42::2;
#       ip6tables -D FORWARD -d fd42:42:42::2 -p tcp --dport $i -j ACCEPT;
#done

# Save and quit (CTRL+O, CTRL+X)

pour infor, mon fichier /etc/nftables.conf

#!/usr/sbin/nft -f
flush ruleset
 
  # replace these
  define if_wan = vmbr0
  define if_lan2 = enp2s0
  define if_lan3 = enp3s0
#  define if_services = br0
 
define ip4_blocked_ports = { 514, 3000 }
define ip6_blocked_ports = { 22, 53, 514, 3000, 8006 }
 
# define tinc_t30 = 10.0.30.0/24
# define tinc_port_t30 = 2345
# define tinc_net_t30 = "t30"
 
 define tinc_t42 = 10.42.0.0/24
 define tinc_port_t42 = 2346
 define tinc_net_t42 = "t42"
 
 define tinc_hive = 172.18.42.0/24
 define tinc_port_hive = 2347
 define tinc_net_hive = "hive"
 
 define tinc_err404_routed = 10.27.0.0/24
 define tinc_port_err404_routed = 8345
 define tinc_net_err404_routed = "err404_routed"
 
 define wg_hive_ip4 = 10.6.0.0/24
 define wg_hive_ip6 = fd42:42:42::/64
 define wg_port_hive = 51820
 define wg_net_hive = "wg-hive"
 
 
# cette chaine fonctionne pour ipv4 et ipv6, or j'ai besoin de faire la différence entre les ports à ouvrir
#table inet filter {
##        # ... other sections ...
#        chain incoming {
##                type filter hook input priority 0; policy drop;
#                type filter hook input priority 0; policy accept;
#
#                # Accept any localhost traffic:
#                iif lo accept
#
#                # ... other rules for other services that are running in this server ...
#                tcp dport { $blocked_ports } iif $if_wan drop
#                udp dport { $blocked_ports } iif $if_wan drop
#        }
#        chain outgoing {
#                type filter hook output priority 0; policy accept;
#        }
#        chain forward {
#                type filter hook forward priority 0; policy accept;
#        }
#}
 
 
table ip filter {
        chain incoming {
                type filter hook input priority 0; policy accept;
                tcp dport { $ip4_blocked_ports } iif $if_wan drop
                udp dport { $ip4_blocked_ports } iif $if_wan drop
        }
 
        chain FORWARD {
                type filter hook forward priority 0; policy accept;
        }
 
        chain outgoing {
                type filter hook output priority 0; policy accept;
        }
}
 
 
table ip6 filter {
        chain incoming {
                type filter hook input priority 0; policy accept;
                udp dport { $ip6_blocked_ports } iif $if_wan drop
                tcp dport { $ip6_blocked_ports } iif $if_wan drop
        }
        chain FORWARD {
                type filter hook forward priority 0; policy accept;
        }
        chain outgoing {
                type filter hook output priority 0; policy accept;
        }
}
# Finally, NAT!
table ip firewall {
#    chain prerouting {
#      type nat hook prerouting priority 0;
 
      # Port forward tcp 80/443 to our internal webserver
#      iifname $if_wan tcp dport { http, https } dnat to "192.168.1.100" comment "DNAT to webserver"
#    }
 
  #### POSTROUTING
  chain postrouting {
    type nat hook postrouting priority 100;
 
 
#    ip saddr $net_lan2         oifname $if_wan masquerade
#    ip saddr $net_lan3         oifname $if_wan masquerade
#    iif $if_lan2                oifname $if_wan masquerade
#    iif $if_lan3                oifname $if_wan masquerade
 
#    iif $tinc_net_err404_routed oifname $if_wan masquerade
#    iif $tinc_net_t42           oifname $if_wan masquerade
    iif $tinc_net_hive          oifname $if_wan masquerade
    iif $wg_net_hive            oifname $if_wan masquerade
 
  }

Rendre les deux scripts exécutables Make both scripts executable

sudo chmod +x /etc/wireguard/PostUp.sh
sudo chmod +x /etc/wireguard/PostDown.sh

sur le client nomade

Configurer Wireguard sur le client nomade - Configure Wireguard on the nomade client :

sudo nano /etc/wireguard/wg-hive.conf
(j'ai pas encore testé la config DNS vu que je force la config dns dans le fichier PostUp.sh)
Remplir le fichier wg-hive.conf comme ceci Fill in the wg-hive.conf file like this

[Interface]
Address = 10.6.0.1/24
Address = fd42:42:42::1/64
#SaveConfig = true
PostUp = bash /etc/wireguard/PostUp.sh
PostDown = bash /etc/wireguard/PostDown.sh
ListenPort = 51820
PrivateKey = ZZZZZZZZZZZZZZZZZZZZZZZZ
# choose your DNS - for instance FDN DNS resolver
#DNS = 80.67.169.12, 2001:910:800::12
 
[Peer]
#miou2
PublicKey = WWWWWWWWWWWWWWWWWWWWWWWWW
AllowedIPs = 10.6.0.2/32, fd42:42:42::2/128
Endpoint = [2a02:8428:753:5001:cc58:d409:b945:ec40]:51820

# Save and quit (CTRL+O, CTRL+X)

Remplir le fichier PostUp.sh comme ceci Fill in the PostUp.sh file like this

sudo nano /etc/wireguard/PostUp.sh

# PostUp.sh
 
metric=100
 
VPN_GATEWAY_ip4=10.6.0.1
VPN_GATEWAY_ip6=fd42:42:42::1
 
# take the first server's tinc_ip as vpn gateway
REMOTEADDRESS_ip4="$(ip route show | grep ^default | cut -d ' ' -f 3)"
REMOTEADDRESS_ip6="$(ip -6 route show | grep ^default | cut -d ' ' -f 3)"
ORIGINAL_GATEWAY_ip4="$(ip route show | grep ^default | cut -d ' ' -f 2-5)"
ORIGINAL_GATEWAY_ip6="$(ip -6 route show | grep ^default | cut -d ' ' -f 2-5)"
INTERFACE="wg-hive"
 
ip route add $REMOTEADDRESS_ip4 $ORIGINAL_GATEWAY_ip4
ip route add $VPN_GATEWAY_ip4 dev $INTERFACE
ip route add 0.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric
ip route add 128.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric
 
#ip -6 route add $REMOTEADDRESS_ip6 $ORIGINAL_GATEWAY_ip6
#ip -6 route add $VPN_GATEWAY_ip6 dev $INTERFACE
#ip -6 route add ::/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric
#ip -6 route add ::1/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric
 
 
echo "nameserver 10.6.0.1" > /etc/resolv.conf 
echo "nameserver fd42:42:42::1" >> /etc/resolv.conf 
chattr +i /etc/resolv.conf
 
logger Wireguard "e17@wg-hive" UP metric $metric

# Save and quit (CTRL+O, CTRL+X)

Remplir le fichier PostDown.sh comme ceci Fill in the PostDown.sh file like this

sudo nano /etc/wireguard/PostDown.sh

# PostDown.sh
 
metric=100
 
VPN_GATEWAY_ip4=10.6.0.1
VPN_GATEWAY_ip6=fd42:42:42::1
 
 
# take the first server's tinc_ip as vpn gateway
REMOTEADDRESS_ip4="$(ip route show | grep ^default | cut -d ' ' -f 3)"
REMOTEADDRESS_ip6="$(ip -6 route show | grep ^default | cut -d ' ' -f 3)"
ORIGINAL_GATEWAY_ip4="$(ip route show | grep ^default | cut -d ' ' -f 2-5)"
ORIGINAL_GATEWAY_ip6="$(ip -6 route show | grep ^default | cut -d ' ' -f 2-5)"
INTERFACE="wg-hive"
 
ip route del $REMOTEADDRESS_ip4 $ORIGINAL_GATEWAY_ip4
ip route del $VPN_GATEWAY_ip4 dev $INTERFACE
ip route del 0.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric
ip route del 128.0.0.0/1 via $VPN_GATEWAY_ip4 dev $INTERFACE metric $metric
 
#ip -6 route del $REMOTEADDRESS_ip6 $ORIGINAL_GATEWAY_ip6
#ip -6 route del $VPN_GATEWAY_ip6 dev $INTERFACE
#ip -6 route del ::/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric
#ip -6 route del ::1/1 via $VPN_GATEWAY_ip6 dev $INTERFACE metric $metric
 
 
echo "nameserver 10.6.0.1" > /etc/resolv.conf
echo "nameserver fd42:42:42::1" >> /etc/resolv.conf
chattr -i /etc/resolv.conf
 
logger Wireguard "e17@wg-hive" down metric $metric

# Save and quit (CTRL+O, CTRL+X)

Rendre les deux scripts exécutables Make both scripts executable

sudo chmod +x /etc/wireguard/PostUp.sh
sudo chmod +x /etc/wireguard/PostDown.sh

Activer le VPN sur les deux serveurs, Enable VPN on both sides :

Sur le VPS puis sur le serveur YunoHost exécuter les commandes suivantes On the VPS and then on the YunoHost server run the following commands :

sudo systemctl start wg-quick@wg-hive.service
sudo systemctl enable wg-quick@wg-hive.service

Afin de permettre la génération automatique des certificats Let’s Encrypt des domaines/sous-domaines associés à votre serveur YunoHost, vous devez ajouter les lignes suivantes à votre fichier Hosts sur le serveur YunoHost (sudo nano /etc/hosts) In order to enable automatic generation of Let’s Encrypt certificates for domains/subdomains associated with your YunoHost server, you must add the following lines to your Hosts file on the YunoHost server (sudo nano /etc/hosts):

::1         domain.tld
127.0.0.1   domain.tld

Test et déploiement Testing and deployment:

  • Assurer vous que votre zone DNS est configurer de sorte que le champs A pointe vers l’IPV4 de votre VPS et le champs AAAA pointe vers l’IPV6 de votre VPS.
  • Une fois la propagation DNS effective, vous pouvez configurer les reverse DNS des IPV4 et IPV6 du VPS vers votre nom de domaine sur le site du fournisseur du VPS.
  • Faite un diagnostique sur l’API d’administration YunoHost, normalement tout est vert !
  • Make sure that your DNS zone is configured so that the A field points to the IPV4 of your VPS and the AAAA field points to the IPV6 of your VPS.
  • Once the DNS propagation is effective, you can configure the reverse DNS of the VPS IPV4 and IPV6 to your domain name on the VPS provider’s website.
  • Do a diagnostic on the YunoHost administration API, normally everything is green!
Misc/Wireguard_je64nr567asjkef34nsfrg/start.1761216554.txt.gz · Last modified: by err404

Page Tools