wireguard
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| wireguard [2026/08/13 22:13] – [Windows] fix up/down scripts to take interface name as argument dmick | wireguard [2026/08/24 15:23] (current) – djgalloway | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== Wireguard Access ====== | ====== Wireguard Access ====== | ||
| ===== Summary ===== | ===== Summary ===== | ||
| - | For now, this is a manual process to access the " | + | We use Wireguard for VPN access |
| ===== How To ===== | ===== How To ===== | ||
| Line 9: | Line 9: | ||
| * Install Wireguard | * Install Wireguard | ||
| * Generate a public/ | * Generate a public/ | ||
| - | * Provide the public key in a ticket | + | * Provide the public key in the [[https:// |
| - | * The Labs team will DM or e-mail your Wireguard IP to you | + | * Once your access is approved, you'll be e-mailed |
| * Connect | * Connect | ||
| + | |||
| ==== Mac/Linux == | ==== Mac/Linux == | ||
| Line 42: | Line 43: | ||
| **Keep the Private Key secret!!** | **Keep the Private Key secret!!** | ||
| - | 5. Provide the Wireguard public key ('' | + | 5. Provide the Wireguard public key ('' |
| - | + | ||
| - | === DO NOT ping any Lab Admins directly. | + | |
| + | === DO NOT ping any Lab Admins directly === | ||
| 6. Create '' | 6. Create '' | ||
| Line 56: | Line 56: | ||
| PrivateKey = $PRIVATE_KEY | PrivateKey = $PRIVATE_KEY | ||
| Address = X.X.X.X/32 | Address = X.X.X.X/32 | ||
| - | DNS = 10.20.192.11, front.sepia.ceph.com, | + | DNS = 10.20.192.13, front.sepia.ceph.com, |
| MTU = 1200 | MTU = 1200 | ||
| Line 67: | Line 67: | ||
| </ | </ | ||
| - | 6. Once Dan or David give you your private IP, replace '' | + | 6. Once you receive |
| 7. Bring up the interface | 7. Bring up the interface | ||
| Line 85: | Line 85: | ||
| </ | </ | ||
| - | use wg show to show status. | + | Use '' |
| ==== Windows ==== | ==== Windows ==== | ||
| - | 1. Install Windows client from https:// | + | 1. Install Windows client from https:// |
| - | 2. In the wireguard | + | 2. In the Wireguard |
| - | 3. send in your public key to David/Dan | + | 3. Submit |
| - | 4. get an IP address in return | + | 4. Wait to receive your Wireguard |
| - | 5. add the configuration to the wireguard app. The first two lines | + | 5. Add the configuration to the wireguard app. The first two lines |
| ([Interface] and PrivateKey = <your private key>) will already be present. | ([Interface] and PrivateKey = <your private key>) will already be present. | ||
| Be very careful to not change anything besides your Address. | Be very careful to not change anything besides your Address. | ||
| Line 105: | Line 106: | ||
| PrivateKey = <your private key> | PrivateKey = <your private key> | ||
| Address = <address from communication with David/ | Address = <address from communication with David/ | ||
| - | DNS = 10.20.192.11, front.sepia.ceph.com, | + | DNS = 10.20.192.13, front.sepia.ceph.com, |
| MTU = 1200 | MTU = 1200 | ||
| Line 206: | Line 207: | ||
| - | ===== More about DNS Configuration on Linux ===== | + | ===== DNS Configuration |
| If you're using systemd-resolved, | If you're using systemd-resolved, | ||
| Line 254: | Line 255: | ||
| Now lookups of shortname or shortname.front or shortname.ipmi should work. Note that dig does not respect the search domains in / | Now lookups of shortname or shortname.front or shortname.ipmi should work. Note that dig does not respect the search domains in / | ||
| + | ===== Split DNS on systemd-resolved distros (Fedora, recent Ubuntu, etc.) ===== | ||
| + | |||
| + | If all web browsing / external DNS stops working while connected to the Sepia VPN, but works again after '' | ||
| + | |||
| + | Do **not** use '' | ||
| + | |||
| + | - Edit ''/ | ||
| + | - **Remove** (or comment out) the '' | ||
| + | - Add the following lines under '' | ||
| + | |||
| + | < | ||
| + | PostUp = resolvectl dns %i 10.20.192.13 | ||
| + | PostUp = resolvectl domain %i ~sepia.ceph.com ~front.sepia.ceph.com ~ipmi.sepia.ceph.com | ||
| + | PostUp = resolvectl default-route %i false | ||
| + | </ | ||
| + | |||
| + | Then restart the tunnel: | ||
| + | |||
| + | < | ||
| + | sudo wg-quick down sepia && sudo wg-quick up sepia | ||
| + | </ | ||
| + | |||
| + | Verify: | ||
| + | |||
| + | < | ||
| + | resolvectl status sepia | ||
| + | </ | ||
| + | |||
| + | You should see '' | ||
| + | |||
| + | ==== Alternative: | ||
| + | |||
| + | On Fedora you can instead import the tunnel into NetworkManager, | ||
| + | |||
| + | < | ||
| + | sudo nmcli connection import type wireguard file / | ||
| + | sudo nmcli connection modify sepia ipv4.dns-search " | ||
| + | sudo nmcli connection up sepia | ||
| + | </ | ||
| + | Only use one method — don't run wg-quick and the NetworkManager connection at the same time. | ||
wireguard.1786659202.txt.gz · Last modified: by dmick
