Outils pour utilisateurs

Outils du site


Divers:Wireguard_er2c5t4rt4yh1hawd4f6072:start

Ceci est une ancienne révision du document !


source: https://forum.yunohost.org/t/homemade-wireguard-vpn-on-a-vps-server

mettre en place un tunnel VPN Wireguard

par defaut, wireguard fait passer tous les paquets à travers un nœud de sortie (et c'est justement ce que je recherche)
ce qui permet d'avoir accès à de l'ipv6 (même si le FAI du client ne fourni pas d'ipv6) à partir du moment ou le serveur dispose de l'ipv6.

Nœud de sortie

Configuration

Définir les adresses ip publiques dans le fichier interfaces - Set public ip addresses in the interfaces file
(actuelement un proxmox avec un bridge en vmbr0)

fichier '' /etc/network/interfaces''

Le fichier doit ressembler à ça - The file should look like this :

auto lo
iface lo inet loopback
 
auto eno1
iface eno1 inet manual
iface eno1 inet6 manual
 
auto vmbr0
iface vmbr0 inet dhcp
        bridge-ports  eno1
        bridge-stp off
        bridge-fd 0
        post-up ip a a 192.168.1.5/24 dev vmbr0
        post-up ip a a 2a02:8428:753:5002:97dc:9048:620e:0242/64 dev vmbr0
        post-up ip r a default via fe80::ce2d:1bff:feb2:7b38 dev vmbr0
        post-up echo "2a02:8428:753:5002:97dc:9048:0:53" >> /etc/resolv.conf
        post-up nft -f /etc/nftables.conf


# Save and quit (CTRL+O, CTRL+X)

Redémarrer le réseau - restart the network

/etc/init.d/networking restart

Autoriser la redirections des paquets IPV4 et IPV6 - Allow forwarding of IPV4 and IPV6 packets

fichier ''/etc/sysctl.conf''

# Uncomment the following lines:
net.ipv4.ip_forward = 1
net.ipv6.conf.all.forwarding = 1

# Save and quit (CTRL+O, CTRL+X)
appliquer les modifications dans /etc/sysctl.conf
sudo sysctl -p

sinon un sysctl -w net.ipv6.conf.all.forwarding=1 net.ipv4.ip_forward=1 fait bien l'affaire

Installation et configuration de Wireguard - installation and configuration of Wireguard :

Installer Wireguard sur le VPS et sur le serveur YunoHost (Les utilisateurs ayant des versions de Debian plus anciennes que Bullseye doivent d’abord activer les rétroportages) Install Wireguard on the VPS and on the YunoHost server (Users with Debian releases older than Bullseye should first enable backports)

apt install wireguard

WireGuard nécessite des clés publiques et privées codées en base64. Celles-ci peuvent être générées en utilisant l’utilitaire wg. Des deux côtés, faites:
WireGuard requires base64-encoded public and private keys. These can be generated using the wg utility. On both side do :
chown -c root:root /etc/wireguard
chmod -c 0700 /etc/wireguard
touch /etc/wireguard/wg-hive.conf
cd /etc/wireguard
wg genkey | tee privatekey-vg-hive | wg pubkey > publickey-vg-hive
chmod -c 0600 /etc/wireguard/*

Configurer Wireguard sur le nœud de sortie - Configure Wireguard on the exit node :

fichier ''wg-hive.conf''

[Interface]
Address = 10.6.0.1/24
Address = fd42:42:42::1/64
#SaveConfig = true
#PostUp = bash /etc/wireguard/PostUp.sh
#PostDown = bash /etc/wireguard/PostDown.sh
PostUp = logger Wireguard "miou2@wg-hive" UP
PostUp = wg set %i private-key /etc/wireguard/privatekey-%i
PostDown = logger Wireguard "miou2@wg-hive" down
ListenPort = 1820
#PrivateKey = XXXXXXXXXXXXXXXXXXXXXX
 
[Peer]
# e17
PublicKey = XZXZXZXZXZXZXZXZXZXZ
AllowedIPs = 10.6.0.2/32, fd42:42:42::2/128
#AllowedIPs = 10.6.0.2/24, fd42:42:42::2/64
#Endpoint = [2a02:8428:753:5001:cc58:d409:b945:ec40]:51820
 
[Peer]
# ssd1
PublicKey = WXWXWXWXWXWXWXWXWXW
AllowedIPs = 10.6.0.3/32, fd42:42:42::3/128
#AllowedIPs = 10.6.0.3/24, fd42:42:42::3/64

Rendre les deux scripts exécutables Make both scripts executable

chmod +x /etc/wireguard/PostUp.sh
chmod +x /etc/wireguard/PostDown.sh

sur le client nomade

Installation et configuration de Wireguard - installation and configuration of Wireguard :

Installer Wireguard sur le VPS et sur client nomade

apt install wireguard

WireGuard nécessite des clés publiques et privées codées en base64. Celles-ci peuvent être générées en utilisant l’utilitaire wg. Des deux côtés, faites:
WireGuard requires base64-encoded public and private keys. These can be generated using the wg utility. On both side do :
chown -c root:root /etc/wireguard
chmod -c 0700 /etc/wireguard
touch /etc/wireguard/wg-hive.conf
cd /etc/wireguard
wg genkey | tee privatekey-vg-hive | wg pubkey > publickey-vg-hive
chmod -c 0600 /etc/wireguard/*

fichier ''/etc/wireguard/wg-hive.conf''

Je n'utilise pas DNS = parce que ne veux pas installer resolvconf et que je veux forcer moi même les dns.

[Interface]
Address = 10.6.0.2/24
Address = fd42:42:42::2/64
#SaveConfig = true
#PostUp = bash /etc/wireguard/PostUp.sh
#PostDown = bash /etc/wireguard/PostDown.sh
PostUp = echo "nameserver 10.6.0.1" > /etc/resolv.conf
PostUp = echo "nameserver fd42:42:42::1" >> /etc/resolv.conf
PostUp = chattr +i /etc/resolv.conf
PostUp = logger Wireguard "e17@wg-hive" UP
PostDown = chattr -i /etc/resolv.conf
PostDown = logger Wireguard "e17@wg-hive" down
ListenPort = 1820
PostUp = wg set %i private-key /etc/wireguard/privatekey-%i
#PrivateKey = ZZZZZZZZZZZZZZZZZZZZZZZZ
# choose your DNS - for instance FDN DNS resolver
# you need to install resolvconf package to use this option
#DNS = fd42:42:42::1, 10.6.0.1
 
[Peer]
#miou2
PublicKey = WWWWWWWWWWWWWWWWWWWWWWWWW
AllowedIPs = 0.0.0.0/0, ::0/0
PersistentKeepalive = 25
Endpoint = 77.129.238.159:1820
Endpoint = [2a02:8428:753:5002:97dc:9048:620e:242]:1820

Activer le VPN des deux cotés, Enable VPN on both sides :

Sur le VPS puis sur le serveur YunoHost exécuter les commandes suivantes On the VPS and then on the YunoHost server run the following commands :

systemctl start wg-quick@wg-hive.service
systemctl enable wg-quick@wg-hive.service

Afin de permettre la génération automatique des certificats Let’s Encrypt des domaines/sous-domaines associés à votre serveur YunoHost, vous devez ajouter les lignes suivantes à votre fichier Hosts sur le serveur YunoHost (sudo nano /etc/hosts) In order to enable automatic generation of Let’s Encrypt certificates for domains/subdomains associated with your YunoHost server, you must add the following lines to your Hosts file on the YunoHost server (sudo nano /etc/hosts):

fichier ''/etc/hosts''

::1         domain.tld
127.0.0.1   domain.tld

routes coté nœud de sortie

ip r

ip r
default via 192.168.1.1 dev vmbr0 
10.6.0.0/24 dev wg-hive proto kernel scope link src 10.6.0.1 
172.18.42.0/24 dev hive proto kernel scope link src 172.18.42.3 
192.168.1.0/24 dev vmbr0 proto kernel scope link src 192.168.1.250 

ip -6 r

2a02:8428:753:5002::/64 dev vmbr0 proto kernel metric 256 pref medium
fd42:42:42::/64 dev wg-hive proto kernel metric 256 pref medium
fe80::/64 dev fwpr104p0 proto kernel metric 256 pref medium
fe80::/64 dev vmbr0 proto kernel metric 256 pref medium
fe80::/64 dev hive proto kernel metric 256 pref medium
default via fe80::ce2d:1bff:feb2:7b38 dev vmbr0 metric 1024 pref medium

firewall coté nœud de sortie

rien de particulier pour wireguard
(la chaine iif "hive" oifname "vmbr0" masquerade ne concerne pas wireguard mais tinc)

iptables -L

Chain INPUT (policy ACCEPT)
target     prot opt source               destination         
ACCEPT     icmp --  anywhere             anywhere            

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination         
ACCEPT     all  --  anywhere             anywhere            

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination  

nft list ruleset

table ip filter {
        chain incoming {
                type filter hook input priority filter; policy accept;
                tcp dport { 514, 3000 } iif "vmbr0" drop
                udp dport { 514, 3000 } iif "vmbr0" drop
        }

        chain FORWARD {
                type filter hook forward priority filter; policy accept;
        }

        chain outgoing {
                type filter hook output priority filter; policy accept;
        }
}
table ip6 filter {
        chain incoming {
                type filter hook input priority filter; policy accept;
                udp dport { 22, 53, 514, 3000, 8006 } iif "vmbr0" drop
                tcp dport { 22, 53, 514, 3000, 8006 } iif "vmbr0" drop
        }

        chain FORWARD {
                type filter hook forward priority filter; policy accept;
        }

        chain outgoing {
                type filter hook output priority filter; policy accept;
        }
}
table ip firewall {
        chain postrouting {
                type nat hook postrouting priority srcnat; policy accept;
                iif "hive" oifname "vmbr0" masquerade
        }
}

routes coté client nomade

ip r

default via 192.168.1.1 dev eno1 proto dhcp src 192.168.1.228 metric 100
10.6.0.0/24 dev wg-hive proto kernel scope link src 10.6.0.2
192.168.1.0/24 dev eno1 proto kernel scope link src 192.168.1.228 metric 100 

ip -6 r

2a02:8428:753:5001::/64 dev eno1 proto ra metric 100 pref medium
fd42:42:42::/64 dev wg-hive proto kernel metric 256 pref medium
fe80::/64 dev eno1 proto kernel metric 1024 pref medium
default via fe80::ce2d:1bff:feb2:7b38 dev eno1 proto ra metric 100 pref high

comme on peut de voir, il n'y a pas de remplacement de la route par défaut que ce soit en ipv4 ou en ipv6.
pourtant un traceroute montre bien un passage à travers le nœud de sortie:

traceroute -4 openbsd.org

traceroute to openbsd.org (199.185.178.80), 30 hops max, 60 byte packets
 1  10.6.0.1 (10.6.0.1)  3.197 ms  3.165 ms  3.529 ms
 2  192.168.1.1 (192.168.1.1)  4.664 ms  4.649 ms  4.634 ms
 3  * * *
 4  190.4.128.77.rev.sfr.net (77.128.4.190)  9.271 ms  9.254 ms  9.241 ms
 5  199.185.178.80 (199.185.178.80)  145.460 ms  145.446 ms  145.432 ms

traceroute -6 openbsd.org

traceroute to openbsd.org (2620:3d:c000:178::80), 30 hops max, 80 byte packets
 1  fd42:42:42::1 (fd42:42:42::1)  1.277 ms  1.245 ms  1.455 ms
 2  2a02-8428-0753-5002-0000-0000-0000-0001.rev.sfr.net (2a02:8428:753:5002::1)  4.725 ms  4.708 ms  4.694 ms
 3  * * *
 4  * * *
 5  * * *
 6  * * *
 7  * * *
 8  2a02-8400-0000-0003-0000-0000-0000-049a.rev.sfr.net (2a02:8400:0:3::49a)  6.336 ms  6.086 ms  6.273 ms
 9  2001:438:ffff::407d:18f6 (2001:438:ffff::407d:18f6)  123.879 ms  126.453 ms *
10  * * *
11  * * *
12  * * *
13  * * *
14  * * *
15  * * *
16  * * *
17  2001:438:ffff::407d:1f9e (2001:438:ffff::407d:1f9e)  128.358 ms  128.272 ms  128.261 ms
18  2-0.ATLNGAMASD3.zip.zayo.com (2001:438:ffff::407d:1d8f)  124.103 ms  124.046 ms  124.190 ms
19  2001:438:fffe::2752 (2001:438:fffe::2752)  129.673 ms  129.629 ms  132.729 ms
20  gw-openbsd.yycix.ca (2001:504:2f::2:2512:1)  131.535 ms  131.495 ms  131.449 ms
21  bb-pf.openbsd.org (2620:3d:c000:230::2)  131.409 ms  131.371 ms  131.329 ms
22  2620:3d:c000:178::80 (2620:3d:c000:178::80)  131.285 ms  129.035 ms  129.634 ms

cela est du à wg-quick qui va modifier les règles de firewall plutôt que de compter uniquement sur le routage:

firewall coté client nomade

on voit bien les règles de firewall rajoutées par wg-quick

iptables -L

Chain INPUT (policy ACCEPT)
target     prot opt source               destination         

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination         

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination  

nft list ruleset

table inet filter {
        chain input {
                type filter hook input priority filter; policy accept;
        }

        chain forward {
                type filter hook forward priority filter; policy accept;
        }

        chain output {
                type filter hook output priority filter; policy accept;
        }
}
table ip6 wg-quick-wg-hive {
        chain preraw {
                type filter hook prerouting priority raw; policy accept;
                iifname != "wg-hive" ip6 daddr fd42:42:42::2 fib saddr type != local drop
        }

        chain premangle {
                type filter hook prerouting priority mangle; policy accept;
                meta l4proto udp meta mark set ct mark
        }

        chain postmangle {
                type filter hook postrouting priority mangle; policy accept;
                meta l4proto udp meta mark 0x0123456 ct mark set meta mark
        }
}
table ip wg-quick-wg-hive {
        chain preraw {
                type filter hook prerouting priority raw; policy accept;
                iifname != "wg-hive" ip daddr 10.6.0.2 fib saddr type != local drop
        }

        chain premangle {
                type filter hook prerouting priority mangle; policy accept;
                meta l4proto udp meta mark set ct mark
        }

        chain postmangle {
                type filter hook postrouting priority mangle; policy accept;
                meta l4proto udp meta mark 0x0123456 ct mark set meta mark
        }
}

Test et déploiement Testing and deployment:

  • Assurer vous que votre zone DNS est configurer de sorte que le champs A pointe vers l’IPV4 de votre VPS et le champs AAAA pointe vers l’IPV6 de votre VPS.
  • Une fois la propagation DNS effective, vous pouvez configurer les reverse DNS des IPV4 et IPV6 du VPS vers votre nom de domaine sur le site du fournisseur du VPS.
  • Faite un diagnostique sur l’API d’administration YunoHost, normalement tout est vert !
  • Make sure that your DNS zone is configured so that the A field points to the IPV4 of your VPS and the AAAA field points to the IPV6 of your VPS.
  • Once the DNS propagation is effective, you can configure the reverse DNS of the VPS IPV4 and IPV6 to your domain name on the VPS provider’s website.
  • Do a diagnostic on the YunoHost administration API, normally everything is green!
Divers/Wireguard_er2c5t4rt4yh1hawd4f6072/start.1762074325.txt.gz · Dernière modification : de err404

Outils de la page