summaryrefslogtreecommitdiffstats
path: root/roles/wireguard_gateway/tasks
diff options
context:
space:
mode:
authorAhmed Abdelhalim <[email protected]>2025-09-03 02:26:21 +0200
committerAhmed Abdelhalim <[email protected]>2025-09-03 03:26:09 +0200
commit7221496f0555bbdd1601ea70da2a9ca99cd34488 (patch)
tree412c8a78aaccb9000cad92e2a515ae87922ec353 /roles/wireguard_gateway/tasks
parent0985f7534da7ffabec9e707f0a355a8307b1ea97 (diff)
Refactor: rename wireguard_gateway to gateway
As the role now functions as a gateway and not just a wireguard gateway it's better name for clarity
Diffstat (limited to 'roles/wireguard_gateway/tasks')
-rw-r--r--roles/wireguard_gateway/tasks/main.yml112
1 files changed, 0 insertions, 112 deletions
diff --git a/roles/wireguard_gateway/tasks/main.yml b/roles/wireguard_gateway/tasks/main.yml
deleted file mode 100644
index c33a49bf..00000000
--- a/roles/wireguard_gateway/tasks/main.yml
+++ /dev/null
@@ -1,112 +0,0 @@
----
-- name: "Ensure iptables are installed"
- become: true
- ansible.builtin.package:
- name: "iptables"
- state: "present"
-
-- name: "Configure IP forwarding"
- become: true
- ansible.builtin.blockinfile:
- path: "/etc/sysctl.conf"
- state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}"
- prepend_newline: true
- append_newline: true
- marker: "# ==== {mark} ANSIBLE WIREGUARD GATEWAY CONFIG"
- create: true
- mode: "0644"
- block: |
- net.ipv4.ip_forward=1
- net.ipv6.conf.all.forwarding=1
- notify: "Reload sysctl"
-
-# IPv4 iptables rules
-- name: "Add IPv4 NAT masquerading for traffic through internet"
- become: true
- ansible.builtin.iptables:
- table: "nat"
- chain: "POSTROUTING"
- source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24"
- out_interface: "{{ ansible_default_ipv4.interface }}"
- jump: "MASQUERADE"
- comment: "NAT local subnet traffic through internet"
- state: "present"
-
-- name: "Add IPv4 NAT masquerading for traffic through VPN"
- become: true
- ansible.builtin.iptables:
- table: "nat"
- chain: "POSTROUTING"
- source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24"
- out_interface: "{{ item }}"
- jump: "MASQUERADE"
- comment: "NAT local subnet traffic through VPN"
- state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}"
- with_items: "{{ wireguard_connections }}"
-
-- name: "Add IPv4 FORWARD rule to accept traffic from local subnet"
- become: true
- ansible.builtin.iptables:
- chain: "FORWARD"
- source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24"
- jump: "ACCEPT"
- comment: "Allow forwarding from local subnet"
- state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}"
-
-- name: "Add IPv4 FORWARD rule to accept established connections"
- become: true
- ansible.builtin.iptables:
- chain: "FORWARD"
- match: "conntrack"
- ctstate: "RELATED,ESTABLISHED"
- jump: "ACCEPT"
- comment: "Allow established connections"
- state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}"
-
-# IPv6 iptables rules
-- name: "Add IPv6 NAT masquerading for traffic through internet"
- become: true
- ansible.builtin.iptables:
- table: "nat"
- chain: "POSTROUTING"
- source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}"
- out_interface: "{{ ansible_default_ipv6.interface }}"
- jump: "MASQUERADE"
- comment: "NAT IPv6 local subnet traffic through internet"
- ip_version: "ipv6"
- state: "present"
- when: ansible_default_ipv6.address is defined
-
-- name: "Add IPv6 NAT masquerading for traffic through VPN"
- become: true
- ansible.builtin.iptables:
- table: "nat"
- chain: "POSTROUTING"
- source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}"
- out_interface: "{{ item }}"
- jump: "MASQUERADE"
- comment: "NAT IPv6 local subnet traffic through VPN"
- ip_version: "ipv6"
- state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}"
- with_items: "{{ wireguard_connections }}"
-
-- name: "Add IPv6 FORWARD rule to accept traffic from local subnet"
- become: true
- ansible.builtin.iptables:
- chain: "FORWARD"
- source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}"
- jump: "ACCEPT"
- comment: "Allow IPv6 forwarding from local subnet"
- ip_version: "ipv6"
- state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}"
-
-- name: "Add IPv6 FORWARD rule to accept established connections"
- become: true
- ansible.builtin.iptables:
- chain: "FORWARD"
- match: "conntrack"
- ctstate: "RELATED,ESTABLISHED"
- jump: "ACCEPT"
- comment: "Allow IPv6 established connections"
- ip_version: "ipv6"
- state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}"