From 3a138f1cfe271defb96e9c78e75747aee44d84f5 Mon Sep 17 00:00:00 2001 From: keteflips Date: Fri, 10 Oct 2025 19:25:02 +0200 Subject: [PATCH] Update wireward config --- wireguard.md | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/wireguard.md b/wireguard.md index 3cc645b..63e09bd 100644 --- a/wireguard.md +++ b/wireguard.md @@ -8,33 +8,44 @@ wg genkey | tee privatekey | wg pubkey > publickey ## CONFIGURE - +```sh configure +``` ### Configure server +```sh set interfaces wireguard wg0 private-key /config/auth/privatekey set interfaces wireguard wg0 address 10.200.254.1/24 set interfaces wireguard wg0 route-allowed-ips true set interfaces wireguard wg0 listen-port 51820 +``` ### Configure peer (clientes) +```sh set interfaces wireguard wg0 peer HMAlHHPMLvcDWhPoGbOkpDiKpZbdfkPZfIb7z6Q3XV0= allowed-ips 10.200.254.101/32 set interfaces wireguard wg0 peer HMAlHHPMLvcDWhPoGbOkpDiKpZbdfkPZfIb7z6Q3XV0= endpoint capsulecorp.duckdns.org:29922 set interfaces wireguard wg0 peer HMAlHHPMLvcDWhPoGbOkpDiKpZbdfkPZfIb7z6Q3XV0= persistent-keepalive 25 +``` ### Configure Firewall +```sh set firewall name WAN_LOCAL rule 20 action accept set firewall name WAN_LOCAL rule 20 protocol udp set firewall name WAN_LOCAL rule 20 description 'WireGuard' set firewall name WAN_LOCAL rule 20 destination port 51820 +``` ### Configure NAT +```sh set service nat rule 5010 description 'WireGuard NAT' set service nat rule 5010 outbound-interface eth0 set service nat rule 5010 type masquerade set service nat rule 5010 source address 10.200.254.0/24 +``` +### Save changes +```sh commit save exit - +```