ansible-infra/docs/guides/wiregueard-admin-vpn.md
Stefan Bethke 6c4f2dc9b6
All checks were successful
/ build (push) Successful in 30s
/ Ansible Lint (push) Successful in 2m45s
Update with correct prefixes
2026-08-04 18:44:51 +02:00

2.1 KiB

title summary
Wiregard Admin VPN How to configure your Wireguard client to access the Z9 network

Onboarding

tbd. where to add your key

Local Client Configuration

Example Config

Replace YOUR_IP_IN_DEC with your IP in decimal, and YOUR_IP_IN_HEX with your IP in hexadecimal.

See resources/z9/z9-router/systemd_networkd/10-wg56.netdev for the Wireguard endpoints configured on the router.

[Interface]
PrivateKey = YOUR_PRIVATE_KEY
Address = 10.89.214.YOUR_IP_IN_DEC/32, 2a07:c481:1:37::YOUR_IP_IN_HEX/128

[Peer]
PublicKey = fmlxjh3iOfpgrHQQpK3dyOD0BvDppGCUkFuMSroqQR4=
AllowedIPs = 10.89.208.0/20, 2a07:c481:1::/48, 212.12.48.120/29, 2a00:14b0:4200:3000::/64, 212.12.50.208/29, 2a00:14b0:42:100::/56, 212.12.51.128/28, 2a00:14b0:f000:23::/64
Endpoint = rt-wan.ccchh.net:51820

AllowedIDs

The following prefixes should be tunneled to gain access to both CCCHH Z9 resources as well as Chaosknoten. It is also possible to run a default route through wireguard, but please do not abuse this as a general VPN for purposes other than admin tasks.

Prefix Description
10.89.208.0/20 prefix for CCCHH Z9 local networks
2a07:c481:1::/48 prefix for CCCHH Z9 local networks
212.12.48.120/29 Fakep refix for hosts that come from 212.12.48.0/24
2a00:14b0:4200:3000::/64 Public IPv6 in Wieske's shared network
212.12.50.208/29 Public IPv4 for VMs on chaosknoten, routed by router
2a00:14b0:42💯:/56 Public IPv6 for VMs on chaosknoten, routed by router
212.12.51.128/28 IPv4 for VMs on chaosknoten, routed by Wieske
2a00:14b0:f000:23::/64 IPv6 for VMs on chaosknoten, routed by Wieske