Hirdetés

Új hozzászólás Aktív témák

  • rekop

    Topikgazda

    válasz VeryByte #4227 üzenetére

    Megpróbáltam összeírni egy s2s-ot. Közel sem biztos hogy működöképes, de kiindulási alapnak talán jó lesz.

    Legyenek az interfészek:
    Site A
    eth0 : 203.0.113.1
    eth1: 192.168.1.1/24
    wg0: 192.168.100.1/24

    Site B
    eth0: 83.45.2.47.1
    eth1: 192.168.2.1/24
    wg0: 192.168.100.2/24

    Site A router:
    wg genkey | tee wg_private.key | wg pubkey > wg_public.key
    configure
    set interfaces wireguard wg0 address 192.168.100.1/24
    set interfaces wireguard wg0 listen-port 51820
    set interfaces wireguard wg0 route-allowed-ips true
    set interfaces wireguard wg0 <wg_private.key

    set interfaces wireguard wg0 peer <site B wg_public.key> allowed-ips 192.168.0.0/16
    set interfaces wireguard wg0 peer <site B wg_public.key> endpoint 83.45.2.47.1:51820
    set interfaces wireguard wg0 peer <site B wg_public.key> persistent-keepalive 15

    set firewall name WAN_LOCAL rule 80 action accept
    set firewall name WAN_LOCAL rule 80 protocol udp
    set firewall name WAN_LOCAL rule 80 source port 51820
    set firewall name WAN_LOCAL rule 80 destination port 51820

    commit; save
    ip route add 192.168.2.0/24 dev wg0

    Site B router:
    wg genkey | tee wg_private.key | wg pubkey > wg_public.key
    configure
    set interfaces wireguard wg0 address 192.168.100.2/24
    set interfaces wireguard wg0 listen-port 51820
    set interfaces wireguard wg0 route-allowed-ips true
    set interfaces wireguard wg0 <wg_private.key>

    set interfaces wireguard wg0 peer <site A wg_public.key> allowed-ips 192.168.0.0/16
    set interfaces wireguard wg0 peer <site A wg_public.key> endpoint 203.0.113.1:51820
    set interfaces wireguard wg0 peer <site A wg_public.key> persistent-keepalive 15

    set firewall name WAN_LOCAL rule 80 action accept
    set firewall name WAN_LOCAL rule 80 protocol udp
    set firewall name WAN_LOCAL rule 80 source port 51820
    set firewall name WAN_LOCAL rule 80 destination port 51820

    commit; save
    ip route add 192.168.1.0/24 dev wg0

    [ Szerkesztve ]

    Eladó dolgaim: https://tinyurl.com/5n7jmuvj

Új hozzászólás Aktív témák