Outils pour utilisateurs

Outils du site


Divers:Wireguard_er2c5t4rt4yh1hawd4f6072:start

Différences

Ci-dessous, les différences entre deux révisions de la page.

Lien vers cette vue comparative

Les deux révisions précédentesRévision précédente
Divers:Wireguard_er2c5t4rt4yh1hawd4f6072:start [2025/11/02 09:05] – [Configurer Wireguard sur le client nomade - Configure Wireguard on the nomade client :] err404 Divers:Wireguard_er2c5t4rt4yh1hawd4f6072:start [2025/11/27 22:16] (Version actuelle) – supprimée err404
Ligne 1: Ligne 1:
-source: https://forum.yunohost.org/t/homemade-wireguard-vpn-on-a-vps-server 
-====== mettre en place un tunnel VPN Wireguard====== 
-par defaut, wireguard fait passer tous les paquets à travers un nœud de sortie (et c'est justement ce que je recherche) 
-ce qui permet d'avoir accès à de l'ipv6 (même si le FAI du client ne fourni pas d'ipv6) à partir du moment ou le serveur dispose de l'ipv6. 
- 
-====== Nœud de sortie ====== 
-===== Configuration ===== 
- 
-Définir les adresses ip publiques dans le fichier interfaces - Set public ip addresses in the interfaces file 
-(actuelement un proxmox avec un bridge en vmbr0) 
- 
-==== fichier '' /etc/network/interfaces'' ==== 
- 
-Le fichier doit ressembler à ça - The file should look like this : 
-<code bash> 
-auto lo 
-iface lo inet loopback 
- 
-auto eno1 
-iface eno1 inet manual 
-iface eno1 inet6 manual 
- 
-auto vmbr0 
-iface vmbr0 inet dhcp 
-        bridge-ports  eno1 
-        bridge-stp off 
-        bridge-fd 0 
-        post-up ip a a 192.168.1.5/24 dev vmbr0 
-        post-up ip a a 2a02:8428:753:5002:97dc:9048:620e:0242/64 dev vmbr0 
-        post-up ip r a default via fe80::ce2d:1bff:feb2:7b38 dev vmbr0 
-        post-up echo "2a02:8428:753:5002:97dc:9048:0:53" >> /etc/resolv.conf 
-        post-up nft -f /etc/nftables.conf 
- 
-</code>        
-# Save and quit (CTRL+O, CTRL+X) 
- 
-Redémarrer le réseau - restart the network 
- 
-''/etc/init.d/networking restart'' 
- 
-Autoriser la redirections des paquets IPV4 et IPV6 - Allow forwarding of IPV4 and IPV6 packets 
- 
-==== fichier ''/etc/sysctl.conf''==== 
-<code bash> 
-# Uncomment the following lines: 
-net.ipv4.ip_forward = 1 
-net.ipv6.conf.all.forwarding = 1 
-</code> 
-# Save and quit (CTRL+O, CTRL+X) 
-appliquer les modifications dans  ''/etc/sysctl.conf'' 
-''sudo sysctl -p'' 
- 
-sinon un ''sysctl -w net.ipv6.conf.all.forwarding=1 net.ipv4.ip_forward=1'' fait bien l'affaire 
- 
-==== Installation et configuration de Wireguard - installation and configuration of Wireguard : ===== 
- 
-Installer Wireguard sur le VPS et sur le serveur YunoHost (Les utilisateurs ayant des versions de Debian plus anciennes que Bullseye doivent d’abord activer les rétroportages) Install Wireguard on the VPS and on the YunoHost server (Users with Debian releases older than Bullseye should first enable backports) 
- 
-''apt install wireguard'' 
- 
-WireGuard nécessite des clés publiques et privées codées en base64. Celles-ci peuvent être générées en utilisant l’utilitaire wg. Des deux côtés, faites: 
-WireGuard requires base64-encoded public and private keys. These can be generated using the wg utility. On both side do : 
-''chown -c root:root /etc/wireguard'' 
-''chmod -c 0700 /etc/wireguard'' 
-''touch /etc/wireguard/wg-hive.conf'' 
-''cd /etc/wireguard'' 
-''wg genkey | tee privatekey-vg-hive | wg pubkey > publickey-vg-hive'' 
-''chmod -c 0600 /etc/wireguard/*'' 
-==== Configurer Wireguard sur le nœud de sortie - Configure Wireguard on the exit node : ==== 
- 
-==== fichier ''wg-hive.conf'' ==== 
-<code bash> 
-[Interface] 
-Address = 10.6.0.1/24 
-Address = fd42:42:42::1/64 
-#SaveConfig = true 
-#PostUp = bash /etc/wireguard/PostUp.sh 
-#PostDown = bash /etc/wireguard/PostDown.sh 
-PostUp = logger Wireguard "miou2@wg-hive" UP 
-PostUp = wg set %i private-key /etc/wireguard/privatekey-%i 
-PostDown = logger Wireguard "miou2@wg-hive" down 
-ListenPort = 1820 
-#PrivateKey = XXXXXXXXXXXXXXXXXXXXXX 
- 
-[Peer] 
-# e17 
-PublicKey = XZXZXZXZXZXZXZXZXZXZ 
-AllowedIPs = 10.6.0.2/32, fd42:42:42::2/128 
-#AllowedIPs = 10.6.0.2/24, fd42:42:42::2/64 
-#Endpoint = [2a02:8428:753:5001:cc58:d409:b945:ec40]:51820 
- 
-[Peer] 
-# ssd1 
-PublicKey = WXWXWXWXWXWXWXWXWXW 
-AllowedIPs = 10.6.0.3/32, fd42:42:42::3/128 
-#AllowedIPs = 10.6.0.3/24, fd42:42:42::3/64 
- 
- 
- 
-</code> 
- 
- 
-Rendre les deux scripts exécutables Make both scripts executable 
- 
-''chmod +x /etc/wireguard/PostUp.sh'' 
-''chmod +x /etc/wireguard/PostDown.sh'' 
- 
-====== sur le client nomade ====== 
-==== Installation et configuration de Wireguard - installation and configuration of Wireguard : ==== 
- 
-Installer Wireguard sur le VPS et sur client nomade 
- 
-''apt install wireguard'' 
- 
-WireGuard nécessite des clés publiques et privées codées en base64. Celles-ci peuvent être générées en utilisant l’utilitaire wg. Des deux côtés, faites: 
-WireGuard requires base64-encoded public and private keys. These can be generated using the wg utility. On both side do : 
-''chown -c root:root /etc/wireguard'' 
-''chmod -c 0700 /etc/wireguard'' 
-''touch /etc/wireguard/wg-hive.conf'' 
-''cd /etc/wireguard'' 
-''wg genkey | tee privatekey-vg-hive | wg pubkey > publickey-vg-hive'' 
-''chmod -c 0600 /etc/wireguard/*'' 
-==== fichier ''/etc/wireguard/wg-hive.conf'' ==== 
-Je n'utilise pas ''DNS ='' parce que ne veux pas installer resolvconf et que je veux forcer moi même les dns. 
-<code bash> 
-[Interface] 
-Address = 10.6.0.2/24 
-Address = fd42:42:42::2/64 
-#SaveConfig = true 
-#PostUp = bash /etc/wireguard/PostUp.sh 
-#PostDown = bash /etc/wireguard/PostDown.sh 
-PostUp = echo "nameserver 10.6.0.1" > /etc/resolv.conf 
-PostUp = echo "nameserver fd42:42:42::1" >> /etc/resolv.conf 
-PostUp = chattr +i /etc/resolv.conf 
-PostUp = logger Wireguard "e17@wg-hive" UP 
-PostDown = chattr -i /etc/resolv.conf 
-PostDown = logger Wireguard "e17@wg-hive" down 
-ListenPort = 1820 
-PostUp = wg set %i private-key /etc/wireguard/privatekey-%i 
-#PrivateKey = ZZZZZZZZZZZZZZZZZZZZZZZZ 
-# choose your DNS - for instance FDN DNS resolver 
-# you need to install resolvconf package to use this option 
-#DNS = fd42:42:42::1, 10.6.0.1 
- 
-[Peer] 
-#miou2 
-PublicKey = WWWWWWWWWWWWWWWWWWWWWWWWW 
-AllowedIPs = 0.0.0.0/0, ::0/0 
-PersistentKeepalive = 25 
-Endpoint = 77.129.238.159:1820 
-Endpoint = [2a02:8428:753:5002:97dc:9048:620e:242]:1820 
- 
-</code> 
- 
- 
-====== Activer le VPN des deux cotés, Enable VPN on both sides : ====== 
- 
-Sur le VPS puis sur le serveur YunoHost exécuter les commandes suivantes On the VPS and then on the YunoHost server run the following commands : 
- 
-''systemctl start wg-quick@wg-hive.service'' 
-''systemctl enable wg-quick@wg-hive.service'' 
- 
-Afin de permettre la génération automatique des certificats Let’s Encrypt des domaines/sous-domaines associés à votre serveur YunoHost, vous devez ajouter les lignes suivantes à votre fichier Hosts sur le serveur YunoHost (sudo nano /etc/hosts) In order to enable automatic generation of Let’s Encrypt certificates for domains/subdomains associated with your YunoHost server, you must add the following lines to your Hosts file on the YunoHost server (sudo nano /etc/hosts): 
-==== fichier ''/etc/hosts'' ==== 
-<code bash> 
-::1         domain.tld 
-127.0.0.1   domain.tld 
-</code> 
- 
-====== routes coté nœud de sortie ====== 
- 
-''ip r'' 
-<code> 
-ip r 
-default via 192.168.1.1 dev vmbr0  
-10.6.0.0/24 dev wg-hive proto kernel scope link src 10.6.0.1  
-172.18.42.0/24 dev hive proto kernel scope link src 172.18.42.3  
-192.168.1.0/24 dev vmbr0 proto kernel scope link src 192.168.1.250  
-</code> 
-''ip -6 r'' 
-<code> 
-2a02:8428:753:5002::/64 dev vmbr0 proto kernel metric 256 pref medium 
-fd42:42:42::/64 dev wg-hive proto kernel metric 256 pref medium 
-fe80::/64 dev fwpr104p0 proto kernel metric 256 pref medium 
-fe80::/64 dev vmbr0 proto kernel metric 256 pref medium 
-fe80::/64 dev hive proto kernel metric 256 pref medium 
-default via fe80::ce2d:1bff:feb2:7b38 dev vmbr0 metric 1024 pref medium 
-</code> 
-====== firewall coté nœud de sortie ====== 
-rien de particulier pour wireguard 
-(la chaine ''iif "hive" oifname "vmbr0" masquerade'' ne concerne pas wireguard mais tinc) 
- 
-''iptables -L'' 
-<code> 
-Chain INPUT (policy ACCEPT) 
-target     prot opt source               destination          
-ACCEPT     icmp --  anywhere             anywhere             
- 
-Chain FORWARD (policy ACCEPT) 
-target     prot opt source               destination          
-ACCEPT     all  --  anywhere             anywhere             
- 
-Chain OUTPUT (policy ACCEPT) 
-target     prot opt source               destination   
-</code> 
- 
-''nft list ruleset'' 
-<code> 
-table ip filter { 
-        chain incoming { 
-                type filter hook input priority filter; policy accept; 
-                tcp dport { 514, 3000 } iif "vmbr0" drop 
-                udp dport { 514, 3000 } iif "vmbr0" drop 
-        } 
- 
-        chain FORWARD { 
-                type filter hook forward priority filter; policy accept; 
-        } 
- 
-        chain outgoing { 
-                type filter hook output priority filter; policy accept; 
-        } 
-} 
-table ip6 filter { 
-        chain incoming { 
-                type filter hook input priority filter; policy accept; 
-                udp dport { 22, 53, 514, 3000, 8006 } iif "vmbr0" drop 
-                tcp dport { 22, 53, 514, 3000, 8006 } iif "vmbr0" drop 
-        } 
- 
-        chain FORWARD { 
-                type filter hook forward priority filter; policy accept; 
-        } 
- 
-        chain outgoing { 
-                type filter hook output priority filter; policy accept; 
-        } 
-} 
-table ip firewall { 
-        chain postrouting { 
-                type nat hook postrouting priority srcnat; policy accept; 
-                iif "hive" oifname "vmbr0" masquerade 
-        } 
-} 
-</code> 
-====== routes coté client nomade ====== 
- 
-''ip r'' 
-<code> 
-default via 192.168.1.1 dev eno1 proto dhcp src 192.168.1.228 metric 100 
-10.6.0.0/24 dev wg-hive proto kernel scope link src 10.6.0.2 
-192.168.1.0/24 dev eno1 proto kernel scope link src 192.168.1.228 metric 100  
-</code> 
-''ip -6 r'' 
-<code> 
-2a02:8428:753:5001::/64 dev eno1 proto ra metric 100 pref medium 
-fd42:42:42::/64 dev wg-hive proto kernel metric 256 pref medium 
-fe80::/64 dev eno1 proto kernel metric 1024 pref medium 
-default via fe80::ce2d:1bff:feb2:7b38 dev eno1 proto ra metric 100 pref high 
-</code> 
- 
-comme on peut de voir, il n'y a pas de remplacement de la route par défaut que ce soit en ipv4 ou en ipv6. 
-pourtant un traceroute montre bien un passage à travers le nœud de sortie: 
- 
-''traceroute -4 openbsd.org'' 
-<code> 
-traceroute to openbsd.org (199.185.178.80), 30 hops max, 60 byte packets 
- 1  10.6.0.1 (10.6.0.1)  3.197 ms  3.165 ms  3.529 ms 
- 2  192.168.1.1 (192.168.1.1)  4.664 ms  4.649 ms  4.634 ms 
- 3  * * * 
- 4  190.4.128.77.rev.sfr.net (77.128.4.190)  9.271 ms  9.254 ms  9.241 ms 
- 5  199.185.178.80 (199.185.178.80)  145.460 ms  145.446 ms  145.432 ms 
-</code> 
- 
-''traceroute -6 openbsd.org'' 
-<code> 
-traceroute to openbsd.org (2620:3d:c000:178::80), 30 hops max, 80 byte packets 
- 1  fd42:42:42::1 (fd42:42:42::1)  1.277 ms  1.245 ms  1.455 ms 
- 2  2a02-8428-0753-5002-0000-0000-0000-0001.rev.sfr.net (2a02:8428:753:5002::1)  4.725 ms  4.708 ms  4.694 ms 
- 3  * * * 
- 4  * * * 
- 5  * * * 
- 6  * * * 
- 7  * * * 
- 8  2a02-8400-0000-0003-0000-0000-0000-049a.rev.sfr.net (2a02:8400:0:3::49a)  6.336 ms  6.086 ms  6.273 ms 
- 9  2001:438:ffff::407d:18f6 (2001:438:ffff::407d:18f6)  123.879 ms  126.453 ms * 
-10  * * * 
-11  * * * 
-12  * * * 
-13  * * * 
-14  * * * 
-15  * * * 
-16  * * * 
-17  2001:438:ffff::407d:1f9e (2001:438:ffff::407d:1f9e)  128.358 ms  128.272 ms  128.261 ms 
-18  2-0.ATLNGAMASD3.zip.zayo.com (2001:438:ffff::407d:1d8f)  124.103 ms  124.046 ms  124.190 ms 
-19  2001:438:fffe::2752 (2001:438:fffe::2752)  129.673 ms  129.629 ms  132.729 ms 
-20  gw-openbsd.yycix.ca (2001:504:2f::2:2512:1)  131.535 ms  131.495 ms  131.449 ms 
-21  bb-pf.openbsd.org (2620:3d:c000:230::2)  131.409 ms  131.371 ms  131.329 ms 
-22  2620:3d:c000:178::80 (2620:3d:c000:178::80)  131.285 ms  129.035 ms  129.634 ms 
-</code> 
- 
-cela est du à wg-quick qui va modifier les règles de firewall plutôt que de compter uniquement sur le routage: 
-====== firewall coté client nomade ====== 
- 
-on voit bien les règles de firewall rajoutées par wg-quick 
- 
-''iptables -L'' 
-<code> 
-Chain INPUT (policy ACCEPT) 
-target     prot opt source               destination          
- 
-Chain FORWARD (policy ACCEPT) 
-target     prot opt source               destination          
- 
-Chain OUTPUT (policy ACCEPT) 
-target     prot opt source               destination   
-</code> 
-''nft list ruleset'' 
-<code> 
-table inet filter { 
-        chain input { 
-                type filter hook input priority filter; policy accept; 
-        } 
- 
-        chain forward { 
-                type filter hook forward priority filter; policy accept; 
-        } 
- 
-        chain output { 
-                type filter hook output priority filter; policy accept; 
-        } 
-} 
-table ip6 wg-quick-wg-hive { 
-        chain preraw { 
-                type filter hook prerouting priority raw; policy accept; 
-                iifname != "wg-hive" ip6 daddr fd42:42:42::2 fib saddr type != local drop 
-        } 
- 
-        chain premangle { 
-                type filter hook prerouting priority mangle; policy accept; 
-                meta l4proto udp meta mark set ct mark 
-        } 
- 
-        chain postmangle { 
-                type filter hook postrouting priority mangle; policy accept; 
-                meta l4proto udp meta mark 0x0123456 ct mark set meta mark 
-        } 
-} 
-table ip wg-quick-wg-hive { 
-        chain preraw { 
-                type filter hook prerouting priority raw; policy accept; 
-                iifname != "wg-hive" ip daddr 10.6.0.2 fib saddr type != local drop 
-        } 
- 
-        chain premangle { 
-                type filter hook prerouting priority mangle; policy accept; 
-                meta l4proto udp meta mark set ct mark 
-        } 
- 
-        chain postmangle { 
-                type filter hook postrouting priority mangle; policy accept; 
-                meta l4proto udp meta mark 0x0123456 ct mark set meta mark 
-        } 
-} 
-</code> 
-====== Test et déploiement Testing and deployment: ====== 
- 
- 
-  * Assurer vous que votre zone DNS est configurer de sorte que le champs A pointe vers l’IPV4 de votre VPS et le champs AAAA pointe vers l’IPV6 de votre VPS. 
-  * Une fois la propagation DNS effective, vous pouvez configurer les reverse DNS des IPV4 et IPV6 du VPS vers votre nom de domaine sur le site du fournisseur du VPS. 
-  * Faite un diagnostique sur l’API d’administration YunoHost, normalement tout est vert ! 
-  * Make sure that your DNS zone is configured so that the A field points to the IPV4 of your VPS and the AAAA field points to the IPV6 of your VPS. 
-  * Once the DNS propagation is effective, you can configure the reverse DNS of the VPS IPV4 and IPV6 to your domain name on the VPS provider’s website. 
-  * Do a diagnostic on the YunoHost administration API, normally everything is green! 
- 
- 
- 
  

Outils de la page