forked from CCCHH/ansible-infra
2.1 KiB
2.1 KiB
| title | summary |
|---|---|
| Wiregard Admin VPN | How to configure your Wireguard client to access the Z9 network |
Onboarding
tbd. where to add your key
Local Client Configuration
Example Config
Replace YOUR_IP_IN_DEC with your IP in decimal, and YOUR_IP_IN_HEX with your IP in hexadecimal.
See resources/z9/z9-router/systemd_networkd/10-wg56.netdev for the Wireguard endpoints configured on the router.
[Interface]
PrivateKey = YOUR_PRIVATE_KEY
Address = 10.89.214.YOUR_IP_IN_DEC/32, 2a07:c481:1:37::YOUR_IP_IN_HEX/128
[Peer]
PublicKey = fmlxjh3iOfpgrHQQpK3dyOD0BvDppGCUkFuMSroqQR4=
AllowedIPs = 10.89.208.0/20, 2a07:c481:1::/48, 212.12.48.120/29, 2a00:14b0:4200:3000::/64, 212.12.50.208/29, 2a00:14b0:42:100::/56, 212.12.51.128/28, 2a00:14b0:f000:23::/64
Endpoint = rt-wan.ccchh.net:51820
AllowedIDs
The following prefixes should be tunneled to gain access to both CCCHH Z9 resources as well as Chaosknoten. It is also possible to run a default route through wireguard, but please do not abuse this as a general VPN for purposes other than admin tasks.
| Prefix | Description |
|---|---|
| 10.89.208.0/20 | prefix for CCCHH Z9 local networks |
| 2a07:c481:1::/48 | prefix for CCCHH Z9 local networks |
| 212.12.48.120/29 | Fakep refix for hosts that come from 212.12.48.0/24 |
| 2a00:14b0:4200:3000::/64 | Public IPv6 in Wieske's shared network |
| 212.12.50.208/29 | Public IPv4 for VMs on chaosknoten, routed by router |
| 2a00:14b0:42💯:/56 | Public IPv6 for VMs on chaosknoten, routed by router |
| 212.12.51.128/28 | IPv4 for VMs on chaosknoten, routed by Wieske |
| 2a00:14b0:f000:23::/64 | IPv6 for VMs on chaosknoten, routed by Wieske |