Ceci est une ancienne révision du document !
source: https://forum.yunohost.org/t/homemade-wireguard-vpn-on-a-vps-server
par defaut, wireguard fait passer tous les paquets à travers un nœud de sortie (et c'est justement ce que je recherche)
ce qui permet d'avoir accès à de l'ipv6 (même si le FAI du client ne fourni pas d'ipv6) à partir du moment ou le serveur dispose de l'ipv6.
Définir les adresses ip publiques dans le fichier interfaces - Set public ip addresses in the interfaces file
(actuelement un proxmox avec un bridge en vmbr0)
Le fichier doit ressembler à ça - The file should look like this :
auto lo
iface lo inet loopback
auto eno1
iface eno1 inet manual
iface eno1 inet6 manual
auto vmbr0
iface vmbr0 inet dhcp
bridge-ports eno1
bridge-stp off
bridge-fd 0
post-up ip a a 192.168.1.5/24 dev vmbr0
post-up ip a a 2a02:8428:753:5002:97dc:9048:620e:0242/64 dev vmbr0
post-up ip r a default via fe80::ce2d:1bff:feb2:7b38 dev vmbr0
post-up echo "2a02:8428:753:5002:97dc:9048:0:53" >> /etc/resolv.conf
post-up nft -f /etc/nftables.conf
# Save and quit (CTRL+O, CTRL+X)
Redémarrer le réseau - restart the network
/etc/init.d/networking restart
Autoriser la redirections des paquets IPV4 et IPV6 - Allow forwarding of IPV4 and IPV6 packets
# Uncomment the following lines: net.ipv4.ip_forward = 1 net.ipv6.conf.all.forwarding = 1
# Save and quit (CTRL+O, CTRL+X)
appliquer les modifications dans /etc/sysctl.conf
sudo sysctl -p
sinon un sysctl -w net.ipv6.conf.all.forwarding=1 net.ipv4.ip_forward=1 fait bien l'affaire
Installer Wireguard sur le VPS et sur le serveur YunoHost (Les utilisateurs ayant des versions de Debian plus anciennes que Bullseye doivent d’abord activer les rétroportages) Install Wireguard on the VPS and on the YunoHost server (Users with Debian releases older than Bullseye should first enable backports)
apt install wireguard
WireGuard nécessite des clés publiques et privées codées en base64. Celles-ci peuvent être générées en utilisant l’utilitaire wg. Des deux côtés, faites:
WireGuard requires base64-encoded public and private keys. These can be generated using the wg utility. On both side do :
chown -c root:root /etc/wireguard
chmod -c 0700 /etc/wireguard
touch /etc/wireguard/wg-hive.conf
cd /etc/wireguard
wg genkey | tee privatekey-vg-hive | wg pubkey > publickey-vg-hive
chmod -c 0600 /etc/wireguard/*
[Interface] Address = 10.6.0.1/24 Address = fd42:42:42::1/64 #SaveConfig = true #PostUp = bash /etc/wireguard/PostUp.sh #PostDown = bash /etc/wireguard/PostDown.sh PostUp = logger Wireguard "miou2@wg-hive" UP PostUp = wg set %i private-key /etc/wireguard/privatekey-%i PostDown = logger Wireguard "miou2@wg-hive" down ListenPort = 1820 #PrivateKey = XXXXXXXXXXXXXXXXXXXXXX [Peer] # e17 PublicKey = XZXZXZXZXZXZXZXZXZXZ AllowedIPs = 10.6.0.2/32, fd42:42:42::2/128 #AllowedIPs = 10.6.0.2/24, fd42:42:42::2/64 #Endpoint = [2a02:8428:753:5001:cc58:d409:b945:ec40]:51820 [Peer] # ssd1 PublicKey = WXWXWXWXWXWXWXWXWXW AllowedIPs = 10.6.0.3/32, fd42:42:42::3/128 #AllowedIPs = 10.6.0.3/24, fd42:42:42::3/64
Rendre les deux scripts exécutables Make both scripts executable
chmod +x /etc/wireguard/PostUp.sh
chmod +x /etc/wireguard/PostDown.sh
Installer Wireguard sur le VPS et sur client nomade
apt install wireguard
WireGuard nécessite des clés publiques et privées codées en base64. Celles-ci peuvent être générées en utilisant l’utilitaire wg. Des deux côtés, faites:
WireGuard requires base64-encoded public and private keys. These can be generated using the wg utility. On both side do :
chown -c root:root /etc/wireguard
chmod -c 0700 /etc/wireguard
touch /etc/wireguard/wg-hive.conf
cd /etc/wireguard
wg genkey | tee privatekey-vg-hive | wg pubkey > publickey-vg-hive
chmod -c 0600 /etc/wireguard/*
Je n'utilise pas DNS = parce que ne veux pas installer resolvconf et que je veux forcer moi même les dns.
[Interface] Address = 10.6.0.2/24 Address = fd42:42:42::2/64 #SaveConfig = true #PostUp = bash /etc/wireguard/PostUp.sh #PostDown = bash /etc/wireguard/PostDown.sh PostUp = echo "nameserver 10.6.0.1" > /etc/resolv.conf PostUp = echo "nameserver fd42:42:42::1" >> /etc/resolv.conf PostUp = chattr +i /etc/resolv.conf PostUp = logger Wireguard "e17@wg-hive" UP PostDown = chattr -i /etc/resolv.conf PostDown = logger Wireguard "e17@wg-hive" down ListenPort = 1820 PostUp = wg set %i private-key /etc/wireguard/privatekey-%i #PrivateKey = ZZZZZZZZZZZZZZZZZZZZZZZZ # choose your DNS - for instance FDN DNS resolver # you need to install resolvconf package to use this option #DNS = fd42:42:42::1, 10.6.0.1 [Peer] #miou2 PublicKey = WWWWWWWWWWWWWWWWWWWWWWWWW AllowedIPs = 0.0.0.0/0, ::0/0 PersistentKeepalive = 25 Endpoint = 77.129.238.159:1820 Endpoint = [2a02:8428:753:5002:97dc:9048:620e:242]:1820
Sur le VPS puis sur le serveur YunoHost exécuter les commandes suivantes On the VPS and then on the YunoHost server run the following commands :
systemctl start wg-quick@wg-hive.service
systemctl enable wg-quick@wg-hive.service
Afin de permettre la génération automatique des certificats Let’s Encrypt des domaines/sous-domaines associés à votre serveur YunoHost, vous devez ajouter les lignes suivantes à votre fichier Hosts sur le serveur YunoHost (sudo nano /etc/hosts) In order to enable automatic generation of Let’s Encrypt certificates for domains/subdomains associated with your YunoHost server, you must add the following lines to your Hosts file on the YunoHost server (sudo nano /etc/hosts):
::1 domain.tld
127.0.0.1 domain.tld
ip r
ip r default via 192.168.1.1 dev vmbr0 10.6.0.0/24 dev wg-hive proto kernel scope link src 10.6.0.1 172.18.42.0/24 dev hive proto kernel scope link src 172.18.42.3 192.168.1.0/24 dev vmbr0 proto kernel scope link src 192.168.1.250
ip -6 r
2a02:8428:753:5002::/64 dev vmbr0 proto kernel metric 256 pref medium fd42:42:42::/64 dev wg-hive proto kernel metric 256 pref medium fe80::/64 dev fwpr104p0 proto kernel metric 256 pref medium fe80::/64 dev vmbr0 proto kernel metric 256 pref medium fe80::/64 dev hive proto kernel metric 256 pref medium default via fe80::ce2d:1bff:feb2:7b38 dev vmbr0 metric 1024 pref medium
rien de particulier pour wireguard
(la chaine iif "hive" oifname "vmbr0" masquerade ne concerne pas wireguard mais tinc)
iptables -L
Chain INPUT (policy ACCEPT) target prot opt source destination ACCEPT icmp -- anywhere anywhere Chain FORWARD (policy ACCEPT) target prot opt source destination ACCEPT all -- anywhere anywhere Chain OUTPUT (policy ACCEPT) target prot opt source destination
nft list ruleset
table ip filter {
chain incoming {
type filter hook input priority filter; policy accept;
tcp dport { 514, 3000 } iif "vmbr0" drop
udp dport { 514, 3000 } iif "vmbr0" drop
}
chain FORWARD {
type filter hook forward priority filter; policy accept;
}
chain outgoing {
type filter hook output priority filter; policy accept;
}
}
table ip6 filter {
chain incoming {
type filter hook input priority filter; policy accept;
udp dport { 22, 53, 514, 3000, 8006 } iif "vmbr0" drop
tcp dport { 22, 53, 514, 3000, 8006 } iif "vmbr0" drop
}
chain FORWARD {
type filter hook forward priority filter; policy accept;
}
chain outgoing {
type filter hook output priority filter; policy accept;
}
}
table ip firewall {
chain postrouting {
type nat hook postrouting priority srcnat; policy accept;
iif "hive" oifname "vmbr0" masquerade
}
}
ip r
default via 192.168.1.1 dev eno1 proto dhcp src 192.168.1.228 metric 100 10.6.0.0/24 dev wg-hive proto kernel scope link src 10.6.0.2 192.168.1.0/24 dev eno1 proto kernel scope link src 192.168.1.228 metric 100
ip -6 r
2a02:8428:753:5001::/64 dev eno1 proto ra metric 100 pref medium fd42:42:42::/64 dev wg-hive proto kernel metric 256 pref medium fe80::/64 dev eno1 proto kernel metric 1024 pref medium default via fe80::ce2d:1bff:feb2:7b38 dev eno1 proto ra metric 100 pref high
comme on peut de voir, il n'y a pas de remplacement de la route par défaut que ce soit en ipv4 ou en ipv6.
pourtant un traceroute montre bien un passage à travers le nœud de sortie:
traceroute -4 openbsd.org
traceroute to openbsd.org (199.185.178.80), 30 hops max, 60 byte packets 1 10.6.0.1 (10.6.0.1) 3.197 ms 3.165 ms 3.529 ms 2 192.168.1.1 (192.168.1.1) 4.664 ms 4.649 ms 4.634 ms 3 * * * 4 190.4.128.77.rev.sfr.net (77.128.4.190) 9.271 ms 9.254 ms 9.241 ms 5 199.185.178.80 (199.185.178.80) 145.460 ms 145.446 ms 145.432 ms
traceroute -6 openbsd.org
traceroute to openbsd.org (2620:3d:c000:178::80), 30 hops max, 80 byte packets 1 fd42:42:42::1 (fd42:42:42::1) 1.277 ms 1.245 ms 1.455 ms 2 2a02-8428-0753-5002-0000-0000-0000-0001.rev.sfr.net (2a02:8428:753:5002::1) 4.725 ms 4.708 ms 4.694 ms 3 * * * 4 * * * 5 * * * 6 * * * 7 * * * 8 2a02-8400-0000-0003-0000-0000-0000-049a.rev.sfr.net (2a02:8400:0:3::49a) 6.336 ms 6.086 ms 6.273 ms 9 2001:438:ffff::407d:18f6 (2001:438:ffff::407d:18f6) 123.879 ms 126.453 ms * 10 * * * 11 * * * 12 * * * 13 * * * 14 * * * 15 * * * 16 * * * 17 2001:438:ffff::407d:1f9e (2001:438:ffff::407d:1f9e) 128.358 ms 128.272 ms 128.261 ms 18 2-0.ATLNGAMASD3.zip.zayo.com (2001:438:ffff::407d:1d8f) 124.103 ms 124.046 ms 124.190 ms 19 2001:438:fffe::2752 (2001:438:fffe::2752) 129.673 ms 129.629 ms 132.729 ms 20 gw-openbsd.yycix.ca (2001:504:2f::2:2512:1) 131.535 ms 131.495 ms 131.449 ms 21 bb-pf.openbsd.org (2620:3d:c000:230::2) 131.409 ms 131.371 ms 131.329 ms 22 2620:3d:c000:178::80 (2620:3d:c000:178::80) 131.285 ms 129.035 ms 129.634 ms
cela est du à wg-quick qui va modifier les règles de firewall plutôt que de compter uniquement sur le routage:
on voit bien les règles de firewall rajoutées par wg-quick
iptables -L
Chain INPUT (policy ACCEPT) target prot opt source destination Chain FORWARD (policy ACCEPT) target prot opt source destination Chain OUTPUT (policy ACCEPT) target prot opt source destination
nft list ruleset
table inet filter {
chain input {
type filter hook input priority filter; policy accept;
}
chain forward {
type filter hook forward priority filter; policy accept;
}
chain output {
type filter hook output priority filter; policy accept;
}
}
table ip6 wg-quick-wg-hive {
chain preraw {
type filter hook prerouting priority raw; policy accept;
iifname != "wg-hive" ip6 daddr fd42:42:42::2 fib saddr type != local drop
}
chain premangle {
type filter hook prerouting priority mangle; policy accept;
meta l4proto udp meta mark set ct mark
}
chain postmangle {
type filter hook postrouting priority mangle; policy accept;
meta l4proto udp meta mark 0x0123456 ct mark set meta mark
}
}
table ip wg-quick-wg-hive {
chain preraw {
type filter hook prerouting priority raw; policy accept;
iifname != "wg-hive" ip daddr 10.6.0.2 fib saddr type != local drop
}
chain premangle {
type filter hook prerouting priority mangle; policy accept;
meta l4proto udp meta mark set ct mark
}
chain postmangle {
type filter hook postrouting priority mangle; policy accept;
meta l4proto udp meta mark 0x0123456 ct mark set meta mark
}
}