wireguard
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| wireguard [2025/12/04 19:35] – djgalloway | wireguard [2026/08/24 15:23] (current) – djgalloway | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== Wireguard Access ====== | ====== Wireguard Access ====== | ||
| ===== Summary ===== | ===== Summary ===== | ||
| - | For now, this is a manual process to access the " | + | We use Wireguard for VPN access |
| ===== How To ===== | ===== How To ===== | ||
| + | |||
| + | ==== Summary ==== | ||
| + | |||
| + | * Install Wireguard | ||
| + | * Generate a public/ | ||
| + | * Provide the public key in the [[https:// | ||
| + | * Once your access is approved, you'll be e-mailed your Wireguard IP | ||
| + | * Connect | ||
| + | |||
| + | ==== Mac/Linux == | ||
| 1. For Mac, Install Wireguard from the App Store\\ | 1. For Mac, Install Wireguard from the App Store\\ | ||
| Line 15: | Line 25: | ||
| </ | </ | ||
| - | 2. Install | + | For Mac, install |
| < | < | ||
| brew install wireguard-tools | brew install wireguard-tools | ||
| Line 26: | Line 36: | ||
| 4. Generate a keypair | 4. Generate a keypair | ||
| + | |||
| < | < | ||
| wg genkey | tee ~/ | wg genkey | tee ~/ | ||
| Line 32: | Line 43: | ||
| **Keep the Private Key secret!!** | **Keep the Private Key secret!!** | ||
| - | 5. Send the public.key contents | + | 5. Provide |
| - | 6. Create '' | + | === DO NOT ping any Lab Admins directly === |
| + | |||
| + | 6. Create '' | ||
| + | the actual text of your private key)\\ | ||
| < | < | ||
| PRIVATE_KEY=$(cat ~/ | PRIVATE_KEY=$(cat ~/ | ||
| Line 42: | Line 56: | ||
| PrivateKey = $PRIVATE_KEY | PrivateKey = $PRIVATE_KEY | ||
| Address = X.X.X.X/32 | Address = X.X.X.X/32 | ||
| - | DNS = 10.20.192.11, front.sepia.ceph.com, | + | DNS = 10.20.192.13, front.sepia.ceph.com, |
| + | MTU = 1200 | ||
| [Peer] | [Peer] | ||
| PublicKey = kyEHy3ZBewI5RiK4/ | PublicKey = kyEHy3ZBewI5RiK4/ | ||
| - | AllowedIPs = 172.16.48.0/ | + | AllowedIPs = 172.21.0.0/ |
| Endpoint = 192.86.31.5: | Endpoint = 192.86.31.5: | ||
| PersistentKeepalive = 25 | PersistentKeepalive = 25 | ||
| Line 52: | Line 67: | ||
| </ | </ | ||
| - | 6. Once Dan or David give you your private IP, replace '' | + | 6. Once you receive |
| - | + | ||
| - | === TODO: Linux CLI instructions === | + | |
| 7. Bring up the interface | 7. Bring up the interface | ||
| - | **On Mac OS**, open the Wireguard GUI. Press Command+O and open '' | + | **On Mac OS**, open the Wireguard GUI. Press Command+O and open '' |
| + | |||
| + | Success looks like\\ | ||
| + | {{:: | ||
| **On Ubuntu**,\\ | **On Ubuntu**,\\ | ||
| Line 68: | Line 85: | ||
| </ | </ | ||
| - | 8. Click **Activate** | + | Use '' |
| - | Success looks like\\ | + | ==== Windows ==== |
| - | {{::screenshot_2025-12-03_at_9.08.01_am.png?400|}} | + | 1. Install Windows client from https:// |
| + | |||
| + | 2. In the Wireguard app, select "Add tunnel/Add empty tunnel" | ||
| + | |||
| + | 3. Submit your public key in the [[https:// | ||
| + | |||
| + | 4. Wait to receive your Wireguard IP | ||
| + | |||
| + | 5. Add the configuration to the wireguard app. The first two lines | ||
| + | ([Interface] and PrivateKey = <your private key>) will already be present. | ||
| + | Be very careful to not change anything besides your Address. | ||
| + | particular, do not edit [Peer] PublicKey; that is the server' | ||
| + | and does not change. | ||
| + | |||
| + | < | ||
| + | [Interface] | ||
| + | PrivateKey = <your private key> | ||
| + | Address = <address from communication with David/ | ||
| + | DNS = 10.20.192.13, | ||
| + | MTU = 1200 | ||
| + | |||
| + | [Peer] | ||
| + | PublicKey = kyEHy3ZBewI5RiK4/ | ||
| + | AllowedIPs = 172.21.0.0/ | ||
| + | Endpoint = 192.86.31.5: | ||
| + | PersistentKeepalive = 25 | ||
| + | </ | ||
| + | |||
| + | 6. Save the configuration, | ||
| + | |||
| + | 7. despite DNS = , the current wireguard client does not properly handle split-horizon DNS. You must add Powershell scripts to the configuration, | ||
| + | |||
| + | Add the following after MTU = in the [Interface] section: | ||
| + | |||
| + | < | ||
| + | PostUp = powershell -ExecutionPolicy Bypass -File "C:\Wireguard\wg-up.ps1" | ||
| + | PostDown = powershell -ExecutionPolicy Bypass -File " | ||
| + | </ | ||
| + | |||
| + | and add the scripts to C: | ||
| + | < | ||
| + | # wg-up.ps1 | ||
| + | param( | ||
| + | [string]$InterfaceAlias = " | ||
| + | [string[]]$Domains = @(" | ||
| + | [string]$DNSServer = " | ||
| + | ) | ||
| + | |||
| + | # Ensure admin | ||
| + | if (-not ([Security.Principal.WindowsPrincipal] [Security.Principal.WindowsIdentity]:: | ||
| + | Write-Error "This script must be run as Administrator." | ||
| + | exit 1 | ||
| + | } | ||
| + | |||
| + | # Verify the requested interface exists and is up | ||
| + | $Interface = Get-NetAdapter -Name $InterfaceAlias -ErrorAction Stop | ||
| + | |||
| + | if ($Interface.Status -ne " | ||
| + | Write-Error " | ||
| + | exit 1 | ||
| + | } | ||
| + | |||
| + | Write-Output "Using WireGuard interface: $InterfaceAlias" | ||
| + | |||
| + | # Add NRPT rules (idempotent) | ||
| + | foreach ($domain in $Domains) { | ||
| + | if (-not (Get-DnsClientNrptRule | Where-Object { $_.Namespace -eq $domain })) { | ||
| + | Write-Output " | ||
| + | Add-DnsClientNrptRule -Namespace $domain -NameServers $DNSServer | ||
| + | } | ||
| + | } | ||
| + | |||
| + | # Set connection-specific DNS suffix (short names) | ||
| + | Set-DnsClient -InterfaceAlias $InterfaceAlias -ConnectionSpecificSuffix $Domains[0] | ||
| + | Write-Output "Set connection-specific suffix: $($Domains[0])" | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | # wg-down.ps1 | ||
| + | param( | ||
| + | [string]$InterfaceAlias = " | ||
| + | [string[]]$Domains = @(" | ||
| + | ) | ||
| + | |||
| + | # Ensure admin | ||
| + | if (-not ([Security.Principal.WindowsPrincipal] [Security.Principal.WindowsIdentity]:: | ||
| + | Write-Error "This script must be run as Administrator." | ||
| + | exit 1 | ||
| + | } | ||
| + | |||
| + | Write-Output "Using WireGuard interface: $InterfaceAlias" | ||
| + | |||
| + | # Remove NRPT rules safely | ||
| + | foreach ($domain in $Domains) { | ||
| + | Get-DnsClientNrptRule | ||
| + | Where-Object { $_.Namespace -eq $domain | ||
| + | Remove-DnsClientNrptRule -Force -ErrorAction SilentlyContinue | ||
| + | Write-Output " | ||
| + | } | ||
| + | |||
| + | # Clear connection-specific suffix | ||
| + | Set-DnsClient -InterfaceAlias $InterfaceAlias -ConnectionSpecificSuffix '' | ||
| + | Write-Output " | ||
| + | |||
| + | </ | ||
| + | |||
| + | Add to the registry: | ||
| + | |||
| + | < | ||
| + | HKEY_LOCAL_MACHINE\Software\WireGuard\DangerousScriptExecution | ||
| + | </ | ||
| + | |||
| + | set it to 1. You can do this with a Command prompt running as administrator: | ||
| + | |||
| + | < | ||
| + | reg add HKLM\Software\WireGuard /v DangerousScriptExecution /t REG_DWORD /d 1 /f | ||
| + | </ | ||
| + | |||
| + | |||
| + | ===== DNS Configuration using dnsmasq on Linux ===== | ||
| + | |||
| + | If you're using systemd-resolved, | ||
| + | |||
| + | The way I (dmick) chose on Fedora 41 was to disable systemd-resolved and set up a dnsmasq instance behind / | ||
| + | |||
| + | 1) sudo systemctl stop systemd-resolved; | ||
| + | 2) add this to / | ||
| + | |||
| + | < | ||
| + | [Network] | ||
| + | DynamicUser=no | ||
| + | ManageResolver=false | ||
| + | </ | ||
| + | |||
| + | 3) install dnsmasq if necessary, and configure it. I chose to put my configuration in / | ||
| + | |||
| + | < | ||
| + | # add domain to shortnames in /etc/hosts; may be helpful | ||
| + | expand-hosts | ||
| + | # don't use / | ||
| + | no-resolv | ||
| + | |||
| + | # for debugging, enable log-queries | ||
| + | # log-queries | ||
| + | |||
| + | # set the server that should handle these three domains | ||
| + | server=/ | ||
| + | server=/ | ||
| + | server=/ | ||
| + | |||
| + | # set the upstream servers for anything else | ||
| + | server=1.1.1.1 | ||
| + | server=9.9.9.9 | ||
| + | </ | ||
| + | |||
| + | 4) remove the existing / | ||
| + | |||
| + | < | ||
| + | nameserver 127.0.0.1 | ||
| + | search front.sepia.ceph.com ipmi.sepia.ceph.com sepia.ceph.com | ||
| + | options ndots:2 | ||
| + | </ | ||
| + | |||
| + | 5) systemctl restart dnsmasq | ||
| + | |||
| + | Now lookups of shortname or shortname.front or shortname.ipmi should work. Note that dig does not respect the search domains in / | ||
| + | |||
| + | ===== Split DNS on systemd-resolved distros (Fedora, recent Ubuntu, etc.) ===== | ||
| + | |||
| + | If all web browsing / external DNS stops working while connected to the Sepia VPN, but works again after '' | ||
| + | |||
| + | Do **not** use '' | ||
| + | |||
| + | - Edit ''/ | ||
| + | - **Remove** (or comment out) the '' | ||
| + | - Add the following lines under '' | ||
| + | |||
| + | < | ||
| + | PostUp = resolvectl dns %i 10.20.192.13 | ||
| + | PostUp = resolvectl domain %i ~sepia.ceph.com ~front.sepia.ceph.com ~ipmi.sepia.ceph.com | ||
| + | PostUp = resolvectl default-route %i false | ||
| + | </ | ||
| + | |||
| + | Then restart the tunnel: | ||
| + | |||
| + | < | ||
| + | sudo wg-quick down sepia && sudo wg-quick up sepia | ||
| + | </ | ||
| + | |||
| + | Verify: | ||
| + | |||
| + | < | ||
| + | resolvectl status sepia | ||
| + | </ | ||
| + | |||
| + | You should see '' | ||
| + | |||
| + | ==== Alternative: | ||
| + | |||
| + | On Fedora you can instead import the tunnel into NetworkManager, | ||
| + | |||
| + | < | ||
| + | sudo nmcli connection import type wireguard file / | ||
| + | sudo nmcli connection modify sepia ipv4.dns-search " | ||
| + | sudo nmcli connection up sepia | ||
| + | </ | ||
| + | |||
| + | Only use one method — don't run wg-quick and the NetworkManager connection at the same time. | ||
wireguard.1764876901.txt.gz · Last modified: by djgalloway
