Re: wireguard in leaf-bering-uclibc 6.2 ?

Boris <[email protected]>
Newsgroups gmane.linux.leaf.user
Message-ID <[email protected]>
Wow Steve,

good step! Thank you! I will try to follow your notes...

Boris

Am 17.09.20 um 05:19 schrieb Steve Tell:
> 
> I've been fiddling around for a couple of evenings, and I believe I have
> wireguard working correctly on 6.2.6.
> 
> Here are some notes, in a form resembling a very rough tutorial document:
> The biggest hurdles were finding the right things to put into
> /etc/network/interfaces, and discovering that the android app will
> import the same syntax of /etc/wireguard/wg*.conf as used on the server.
> 
> 
> wireguard on leaf-bering-uclibc:
> 
> add wireguard.lrp to leaf.cfg
> 
> add wireguard to /etc/modules
> save config and reboot
> 
> create the four keys following the tutorials
>     but there's no "tee" (why not, busybox?), so use:
> 
> wg genkey > fwall.private
> wg pubkey  < fwall.private > fwall.pub
> 
> the other pair for the remote peer, in my case a cellphone:
> 
> wg genkey > phone.private
> wg pubkey  < phone.private > phone.pub
> 
> now make the firewall /etc/wireguard/wg0.conf using that info
> 
> edit /etc/wireguard/wg0.conf
> [Interface]
> # note no Address keyword, contrary to some tutorials
> ListenPort = 51820
> PrivateKey =   (firewall private key from fwall.private
> 
> [Peer]
> PublicKey = (this peer's public key, from phone.pub)
> AllowedIPs = 10.x.y.z        # /32 address permanently assigned to this
> peer
> 
> 
> the wg-quick script doesn't work on bering, I think because it needs
> some features missing in busybox.  o
> 
> so, proceed almost as if we had a real ethernet interface named wg0:
> 
> edit /etc/network/interfaces, to add:
> 
> # wireguard vpn
> # replace 10.x.x.* with same subnet as used in peer AllowedIPs  in wg0.conf
> iface wg0 inet static
>         address 10.x.y.1
>         netmask 255.255.255.0
>         pre-up ip link add dev wg0 type wireguard
>         pre-up wg setconf wg0 /etc/wireguard/wg0.conf
>         post-up ip route add 10.x.y.0/24 dev wg0
>         post-down ip link delete dev wg0
> 
> check dnsmasq.conf, make sure that dnsmasq will accept DNS queries from wg0
> (interface=, except-interface= options)
> 
> add wg0 interface and vpn zone to shorewall:
> 
> interfaces:
>     vpn          wg0                     logmartians
> snat:
>     MASQUERADE     10.x.y.0/24       eth0
> policy:
>     vpn              all             ACCEPT
> # or, I think rules:
> rules:
>     HTTP(ACCEPT)    vpn          loc
>     etc
> 
> ---
> 
> next, build a config file to transport to the peer machine.
> in my case, the peer is an android phone with the wireguard app from
> fdroid.
> 
> I called this file phone.wg.conf:
> 
> # phone/road-warrior wireguard config
> [Interface]
> Address = 10.x.y.z/32  # same as peer AllowedIP on the firewall side.
> ListenPort = 51820
> PrivateKey = (from phone.private file generate above)
> 
> # Peer1: home firewall
> [Peer]
> PublicKey = (from phone.pub generated above)
> #AllowedIPs = 0.0.0/0 ::/0   # I think this is right, but I entered it
> manually instead.
> 
> 
> Then, copy this config file to the phone. I used MTP over USB, and put
> it in the downloads directory.
> open the wireguard app.
> click "+" to add a tunnel, and "import from file".
> select downloads/phone.wg.conf
> 
> the keys get imported.
> then manually configure these two things:
> 
> Interface:
>     DNS Servers: 10.x.y.1
>             the IP addr of the firewall's wg0 interface
>             on which dnsmasq should be listening
> Peer:
>     Allowed IPs: 0.0.0.0/0 ::/0
>         this is right for tunneling all traffic
>         somthing more interesting might allow split tunneling.
> 
> It must be possible to put this stuff into phone.wg.conf, because some
> commercial vpn services provide a tool to generate and download a
> wireguard config file.
> 
> Flip the switch in the wireguard app to turn on the tunnel.
> use "wg show" on the firewall to see the connection.
> 
> some debug aids I used:
>  "ping" and "nslookup" in termmux on android
>  "wg show" on firewall
>  logfiles on firewall
> 
> note that nslookup (and dig) in termmux don't use whatever mechanism
> android normally uses to find the dns server, they always use a
> resolv.conf file with google servers only.
> but "nslookup lan-machine 10.x.y.1" should query dnsmasq on the firewall
> for its view of the world.
> 
> 
> 
> 
> 
> 
> 
> On Mon, 14 Sep 2020, Boris wrote:
> 
>> Am 09.09.20 um 17:19 schrieb Steve Tell:
>>>
>>> 6.2.6 has a wireguard.lrp package that installs /usr/bin/wg and related
>>> template config files.
>>>
>>> But no mention of wg in the mailing list or docs.  Anyone using
>>> wireguard as server on leaf for a basic "road warrior" setup?  Does it
>>> "just work" so easily there's no docs needed?
>>
>> Hej Steve,
>>
>> wireguard is on my tasklist. I tried once with 6.2.3 and stepped onto a
>> missing component. In 6.2.5 this missing thing is fixed and I managed to
>> generate keys. Next step would be to do the connection and routing but I
>> have to wait for days with bad weather or longer nights ;-)
>>
>> Boris
>>
>>
>> ------------------------------------------------------------------------
>> leaf-user mailing list: [email protected]
>> https://lists.sourceforge.net/lists/listinfo/leaf-user
>> Support Request -- http://leaf-project.org/



------------------------------------------------------------------------
leaf-user mailing list: [email protected]
https://lists.sourceforge.net/lists/listinfo/leaf-user
Support Request -- http://leaf-project.org/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.