User Tools

Site Tools


wireguard

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
wireguard [2021/02/23 07:33] – created baumiwireguard [2026/08/02 10:15] (current) baumi
Line 1: Line 1:
 ====== Wireguard ====== ====== Wireguard ======
  
-===== Install Wireguard on Debian 9.x and Raspbian 10.x =====+===== Create Key Pairs ===== 
 +**Host A** 
 +<code> 
 +root@hosta # wg genkey > privateA 
 +root@hosta # wg pubkey < privateA > publicA 
 +</code>
  
 +**Host B**
 <code> <code>
-echo "deb http://deb.debian.org/debian/ unstable main" /etc/apt/sources.list.d/unstable.list +root@hostb wg genkey privateB 
-echo -e "Package: *\nPin: release a=unstable\nPin-Priority: 150\n" /etc/apt/preferences.d/limit-unstable +root@hostb wg pubkey < privateB publicB
-# apt-get update && apt-get install wireguard-dkms wireguard-tools +
-# modprobe wireguard && lsmod | grep wireguard+
 </code> </code>
  
-===== Create Key Pairs ===== +===== Assign Link Network to Wireguard-Tunnel ===== 
-Host A+  Link-Network: 172.24.0.0/30 
 +  HostA: 172.24.0.1/30 
 +  HostB: 172.24.0.2/30 
 + 
 +===== Create Config ===== 
 +**Assumption** 
 +Host A is visible to Host B 
 + 
 +**Host A**
 <code> <code>
-wg genkey > privateA +root@hosta cat /etc/wireguard/wg0.conf 
-wg pubkey < privateA > publicA+HostA - HostB 
 +[Interface] 
 +Address = 172.24.0.1/30 
 +PrivateKey = <contents of privateA> 
 +ListenPort = 51820 
 + 
 +[Peer] 
 +PublicKey = <contents of publicB> 
 +AllowedIPs = 172.24.0.2/32
 </code> </code>
  
-Host B+**Host B**
 <code> <code>
-# wg genkey privateB +root@hostb # cat /etc/wireguard/wg0.conf 
-# wg pubkey privateB publicB+# HostB - HostA 
 +[Interface] 
 +Address = 172.24.0.2/30 
 +PrivateKey = <contents of privateB> 
 +ListenPort = 51820 
 +#If something needs to happen after tunnel is up or before tunnel goes down 
 +#PostUp = /usr/local/sbin/wg0-PostUp.sh 
 +#PreDown = /usr/local/sbin/wg0-PreDown.sh 
 + 
 +[Peer] 
 +PublicKey = <contents of publicA> 
 +Endpoint = <visible ip of HostA> 
 +AllowedIPs = 172.24.0.1/32 
 +# Uncomment if HostB is behind NAT Router 
 +# PersistentKeepAlive = 25 
 +</code> 
 + 
 +===== Start Wireguard Tunnel ===== 
 +Issue on both hosts 
 +<code> 
 +root@hosta # wg-quick up wg0 
 +root@hostb # wg-quick up wg0 
 +</code
 +===== Check Status ===== 
 +**Host A** 
 +<code> 
 +root@hosta # wg 
 +interface: wg0 
 +  public key: PUBLIC-KEY-A 
 +  private key: (hidden) 
 +  listening port: 51820 
 + 
 +peer: PUBLIC-KEY-B 
 +  endpoint: 185.69.244.140:25920 
 +  allowed ips: 172.24.0.2/32 
 +  latest handshake: 1 minute, 44 seconds ago 
 +  transfer: 2.80 MiB received, 1.09 MiB sent 
 +</code> 
 + 
 +**Host B** 
 +<code> 
 +root@hostb # wg 
 +interface: wg0 
 +  public key: PUBLIC-KEY-B 
 +  private key: (hidden) 
 +  listening port: 51820 
 + 
 +peer: PUBLIC-KEY-A 
 +  endpoint: 144.76.72.57:51820 
 +  allowed ips: 172.24.0.1/32 
 +  latest handshake: 21 seconds ago 
 +  transfer: 1006.68 KiB received, 2.57 MiB sent 
 +  persistent keepalive: every 25 seconds 
 +</code> 
 + 
 +===== Fallback systemd service to call PreDown script ===== 
 +<code> 
 +root@hostb # cat << EOF > /etc/systemd/system/wg0-shutdown-fallback.service 
 +[Unit] 
 +Description=WireGuard wg0 shutdown fallback 
 +DefaultDependencies=no 
 + 
 +Before=shutdown.target reboot.target halt.target 
 +Before=wg-quick@wg0.service 
 + 
 +Conflicts=shutdown.target reboot.target halt.target 
 + 
 +After=local-fs.target 
 + 
 +[Service] 
 +Type=oneshot 
 +RemainAfterExit=yes 
 + 
 +ExecStart=/bin/true 
 +ExecStop=/usr/local/sbin/wg0-PreDown.sh 
 + 
 +TimeoutStopSec=30 
 + 
 +[Install] 
 +WantedBy=multi-user.target 
 +EOF 
 +root@hostb # systemctl daemon-reload 
 +root@hostb # systemctl enable wg0-shutdown-fallback.service 
 +root@hostb # systemctl start wg0-shutdown-fallback.service
 </code> </code>
  
  
 +{{tag>kb linux}}
wireguard.1614062029.txt.gz · Last modified: by baumi

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki