User Tools

Site Tools


wireguard

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
wireguard [2026/08/11 12:56] – djgallowaywireguard [2026/08/24 15:23] (current) – djgalloway
Line 1: Line 1:
 ====== Wireguard Access ====== ====== Wireguard Access ======
 ===== Summary ===== ===== Summary =====
-For now, this is a manual process to access the "new" Sepia lab in Poughkeepsie, NY.+We use Wireguard for VPN access to the Sepia lab.  Lab access requests are now automated.
  
 ===== How To ===== ===== How To =====
Line 9: Line 9:
   * Install Wireguard   * Install Wireguard
   * Generate a public/private keypair   * Generate a public/private keypair
-  * Provide the public key in a ticket +  * Provide the public key in the [[https://onboarding.sepia.ceph.com/wireguard|Onboarding Portal]] 
-  * The Labs team will DM or e-mail your Wireguard IP to you+  * Once your access is approved, you'll be e-mailed your Wireguard IP
   * Connect   * Connect
 +
 ==== Mac/Linux == ==== Mac/Linux ==
  
Line 42: Line 43:
 **Keep the Private Key secret!!** **Keep the Private Key secret!!**
  
-5. Provide the Wireguard public key (''~/.wireguard/public.key'' contents) [[http://tracker.ceph.com/projects/lab/issues/new?issue[tracker_id]=3|in a tracker ticket]].  We will DM your Wireguard IP to you. +5. Provide the Wireguard public key (''~/.wireguard/public.key'' contents) in the [[https://onboarding.sepia.ceph.com/wireguard|Onboarding Portal]].
- +
-=== DO NOT ping any Lab Admins directly.  We have a rotation we follow for processing tickets. ===+
  
 +=== DO NOT ping any Lab Admins directly ===
  
 6. Create ''~/.wireguard/client.conf''  (note that the $PRIVATE_KEY must expand to 6. Create ''~/.wireguard/client.conf''  (note that the $PRIVATE_KEY must expand to
Line 56: Line 56:
 PrivateKey = $PRIVATE_KEY PrivateKey = $PRIVATE_KEY
 Address = X.X.X.X/32 Address = X.X.X.X/32
-DNS = 10.20.192.11, front.sepia.ceph.com, ipmi.sepia.ceph.com+DNS = 10.20.192.13, front.sepia.ceph.com, ipmi.sepia.ceph.com
 MTU = 1200 MTU = 1200
  
Line 67: Line 67:
 </code> </code>
  
-6. Once Dan or David give you your private IP, replace ''X.X.X.X'' in ''client.conf'' with it.+6. Once you receive your private IP, replace ''X.X.X.X'' in ''client.conf'' with it.
  
 7. Bring up the interface 7. Bring up the interface
Line 85: Line 85:
 </code> </code>
  
-use wg show to show status.+Use ''wg show'' to show status. 
 ==== Windows ==== ==== Windows ====
-1.  Install Windows client from https://www.wireguard.com/install/+1. Install Windows client from https://www.wireguard.com/install/
  
-2. In the wireguard app, select "Add tunnel/Add empty tunnel".  A public and private key will be automatically generated for you.  Note them.  KEEP THE PRIVATE KEY SECRET.+2. In the Wireguard app, select "Add tunnel/Add empty tunnel".  A public and private key will be automatically generated for you.  Note them.  KEEP THE PRIVATE KEY SECRET.
  
-3. send in your public key to David/Dan+3. Submit your public key in the [[https://onboarding.sepia.ceph.com/wireguard|Onboarding Portal]]
  
-4. get an IP address in return+4. Wait to receive your Wireguard IP
  
-5. add the configuration to the wireguard app.  The first two lines+5. Add the configuration to the wireguard app.  The first two lines
 ([Interface] and PrivateKey = <your private key>) will already be present. ([Interface] and PrivateKey = <your private key>) will already be present.
 Be very careful to not change anything besides your Address.  In  Be very careful to not change anything besides your Address.  In 
Line 105: Line 106:
 PrivateKey = <your private key> PrivateKey = <your private key>
 Address = <address from communication with David/Dan>/32 Address = <address from communication with David/Dan>/32
-DNS = 10.20.192.11, front.sepia.ceph.com, ipmi.sepia.ceph.com+DNS = 10.20.192.13, front.sepia.ceph.com, ipmi.sepia.ceph.com
 MTU = 1200 MTU = 1200
  
Line 122: Line 123:
  
 <code> <code>
-PostUp = powershell -ExecutionPolicy Bypass -File "C:\Wireguard\wg-up.ps1" +PostUp = powershell -ExecutionPolicy Bypass -File "C:\Wireguard\wg-up.ps1" -InterfaceAlias wg0 
-PostDown = powershell -ExecutionPolicy Bypass -File "C:\Wireguard\wg-down.ps1"+PostDown = powershell -ExecutionPolicy Bypass -File "C:\Wireguard\wg-down.ps1" -InterfaceAlias wg0
 </code> </code>
  
Line 130: Line 131:
 # wg-up.ps1 # wg-up.ps1
 param( param(
-    [string[]]$Domains = @("sepia.ceph.com", "front.sepia.ceph.com"),+    [string]$InterfaceAlias = "wg0", 
 +    [string[]]$Domains = @("front.sepia.ceph.com"),
     [string]$DNSServer = "10.20.192.11"     [string]$DNSServer = "10.20.192.11"
 ) )
Line 140: Line 142:
 } }
  
-# Auto-detect WireGuard interface (by type) +# Verify the requested interface exists and is up 
-$Interface = Get-NetAdapter | Where-Object { $_.InterfaceDescription -match "WireGuard" -and $_.Status -eq "Up" } | Select-Object -First 1+$Interface = Get-NetAdapter -Name $InterfaceAlias -ErrorAction Stop
  
-if (-not $Interface) { +if ($Interface.Status -ne "Up") { 
-    Write-Error "No active WireGuard interface found."+    Write-Error "WireGuard interface /$InterfaceAlias' is not up."
     exit 1     exit 1
 } }
  
-$InterfaceAlias = $Interface.Name 
 Write-Output "Using WireGuard interface: $InterfaceAlias" Write-Output "Using WireGuard interface: $InterfaceAlias"
  
Line 161: Line 162:
 # Set connection-specific DNS suffix (short names) # Set connection-specific DNS suffix (short names)
 Set-DnsClient -InterfaceAlias $InterfaceAlias -ConnectionSpecificSuffix $Domains[0] Set-DnsClient -InterfaceAlias $InterfaceAlias -ConnectionSpecificSuffix $Domains[0]
-Write-Output "Set connection-specific suffix: $($Domains[0])+Write-Output "Set connection-specific suffix: $($Domains[0])"
 </code> </code>
  
Line 167: Line 168:
 # wg-down.ps1 # wg-down.ps1
 param( param(
 +    [string]$InterfaceAlias = "wg0",
     [string[]]$Domains = @("sepia.ceph.com")     [string[]]$Domains = @("sepia.ceph.com")
 ) )
Line 176: Line 178:
 } }
  
-# Auto-detect WireGuard interface (by type) 
-$Interface = Get-NetAdapter | Where-Object { $_.InterfaceDescription -match "WireGuard" -and $_.Status -eq "Up" } | Select-Object -First 1 
- 
-if (-not $Interface) { 
-    Write-Output "No active WireGuard interface found; skipping cleanup." 
-    exit 0 
-} 
- 
-$InterfaceAlias = $Interface.Name 
 Write-Output "Using WireGuard interface: $InterfaceAlias" Write-Output "Using WireGuard interface: $InterfaceAlias"
  
Line 191: Line 184:
     Get-DnsClientNrptRule |     Get-DnsClientNrptRule |
         Where-Object { $_.Namespace -eq $domain } |         Where-Object { $_.Namespace -eq $domain } |
-        Remove-DnsClientNrptRule -ErrorAction SilentlyContinue+        Remove-DnsClientNrptRule -Force -ErrorAction SilentlyContinue
     Write-Output "Removed NRPT rule for $domain"     Write-Output "Removed NRPT rule for $domain"
 } }
Line 198: Line 191:
 Set-DnsClient -InterfaceAlias $InterfaceAlias -ConnectionSpecificSuffix '' Set-DnsClient -InterfaceAlias $InterfaceAlias -ConnectionSpecificSuffix ''
 Write-Output "Cleared connection-specific suffix" Write-Output "Cleared connection-specific suffix"
 +
 </code> </code>
  
Line 213: Line 207:
  
  
-===== More about DNS Configuration on Linux =====+===== DNS Configuration using dnsmasq on Linux =====
  
 If you're using systemd-resolved, stop.  It is incapable of handling split DNS.  I would not use resolvconf. If you're using systemd-resolved, stop.  It is incapable of handling split DNS.  I would not use resolvconf.
Line 261: Line 255:
 Now lookups of shortname or shortname.front or shortname.ipmi should work.  Note that dig does not respect the search domains in /etc/resolv.conf by default; you must use dig +search <domain> Now lookups of shortname or shortname.front or shortname.ipmi should work.  Note that dig does not respect the search domains in /etc/resolv.conf by default; you must use dig +search <domain>
  
 +===== Split DNS on systemd-resolved distros (Fedora, recent Ubuntu, etc.) =====
 +
 +If all web browsing / external DNS stops working while connected to the Sepia VPN, but works again after ''sudo resolvectl revert sepia'', your distro is using systemd-resolved and wg-quick has set the lab DNS server as the **default** resolver for all queries — not just Sepia ones.
 +
 +Do **not** use ''resolvectl revert'' as a workaround; it also breaks resolution of lab hostnames. Configure split DNS instead so only Sepia domains are sent to the lab resolver:
 +
 +  - Edit ''/etc/wireguard/sepia.conf''
 +  - **Remove** (or comment out) the ''DNS ='' line
 +  - Add the following lines under ''[Interface]'':
 +
 +<code>
 +PostUp = resolvectl dns %i 10.20.192.13
 +PostUp = resolvectl domain %i ~sepia.ceph.com ~front.sepia.ceph.com ~ipmi.sepia.ceph.com
 +PostUp = resolvectl default-route %i false
 +</code>
 +
 +Then restart the tunnel:
 +
 +<code>
 +sudo wg-quick down sepia && sudo wg-quick up sepia
 +</code>
 +
 +Verify:
 +
 +<code>
 +resolvectl status sepia
 +</code>
 +
 +You should see ''Default Route: no'' and the three sepia domains listed. Lab hostnames (e.g. ''smithi001.front.sepia.ceph.com'') will resolve via the VPN; everything else uses your normal DNS.
 +
 +==== Alternative: NetworkManager ====
 +
 +On Fedora you can instead import the tunnel into NetworkManager, which handles split DNS natively:
 +
 +<code>
 +sudo nmcli connection import type wireguard file /etc/wireguard/sepia.conf
 +sudo nmcli connection modify sepia ipv4.dns-search "~sepia.ceph.com;front.sepia.ceph.com;ipmi.sepia.ceph.com" ipv4.dns-priority 50
 +sudo nmcli connection up sepia
 +</code>
  
 +Only use one method — don't run wg-quick and the NetworkManager connection at the same time.
wireguard.1786452985.txt.gz · Last modified: by djgalloway