diff options
| author | Ahmed Abdelhalim <[email protected]> | 2025-09-10 18:09:52 +0200 |
|---|---|---|
| committer | Ahmed Abdelhalim <[email protected]> | 2025-09-10 18:09:52 +0200 |
| commit | 6ddc1505a11c74ffb0c8c65498f5eef5086e62d1 (patch) | |
| tree | d71d82698bd7025e7745e718ffdb527a8045d56e /roles | |
| parent | e9e609e89ad879e10e58f2c4fcfa572f60d6dfad (diff) | |
Remove wireguard_gateway
This implementation doesn't work properly after testing.
The iptable configuration didn't allow for changing the VPN state
without running into networking issues.
Either have to change the VPN by running the role, which is inconvenient
or reimplement the role differently to allow for control over
network/interfaces
Diffstat (limited to 'roles')
| -rw-r--r-- | roles/wireguard_gateway/README.md | 98 | ||||
| -rw-r--r-- | roles/wireguard_gateway/defaults/main.yml | 2 | ||||
| -rw-r--r-- | roles/wireguard_gateway/handlers/main.yml | 6 | ||||
| -rw-r--r-- | roles/wireguard_gateway/meta/argument_specs.yml | 10 | ||||
| -rw-r--r-- | roles/wireguard_gateway/meta/main.yml | 20 | ||||
| -rw-r--r-- | roles/wireguard_gateway/tasks/main.yml | 97 |
6 files changed, 0 insertions, 233 deletions
diff --git a/roles/wireguard_gateway/README.md b/roles/wireguard_gateway/README.md deleted file mode 100644 index 06c3ceb7..00000000 --- a/roles/wireguard_gateway/README.md +++ /dev/null @@ -1,98 +0,0 @@ -# Ansible Role: wireguard_gateway - -This role configures a Linux host as a WireGuard VPN gateway, -routing all traffic from local network clients through the VPN connection. - -## Role Variables - -- `wireguard_gateway_enabled`: Boolean flag to enable/disable gateway functionality (default: `false`) - -## What This Role Does - -When `wireguard_gateway_enabled` is `true`, the role: - -- Sets `net.ipv4.ip_forward=1` and `net.ipv6.conf.all.forwarding=1` in `/etc/sysctl.conf` -- Creates custom routing table (100) to route traffic through VPN -- Routes IPv4 and IPv6 traffic from local subnet through VPN interface -- Allows traffic forwarding and established connections - -When `wireguard_gateway_enabled` is `false`, the role: - -- Removes all routing rules and iptables configurations -- Disables IP forwarding in sysctl configuration -- Cleans up custom routing tables - -## Example Configuration - -```yaml -# In host_vars/gateway.yml -wireguard_gateway_enabled: true -wireguard_autostart_connection: "protonvpn-us-1" - -# WireGuard connection configuration -wireguard_connections: - protonvpn-us-1: | - [Interface] - PrivateKey = your_private_key_here - Address = 10.2.0.2/32 - DNS = 10.2.0.1 - - [Peer] - PublicKey = server_public_key - AllowedIPs = 0.0.0.0/0, ::/0 - Endpoint = vpn.example.com:51820 -``` - -## Client Configuration - -For client machines to route through the VPN gateway: - -1. **IPv4**: Set gateway to VPN gateway host's IP -2. **IPv6**: Set IPv6 gateway to VPN gateway host's IPv6 address -3. **Manual network config**: Disable auto-configuration to use custom gateway - -Example client network configuration: - -```yaml -network_ipv4_address: "192.168.1.100" -network_ipv4_gateway: "192.168.1.254" # VPN gateway host -network_ipv6_address: "2001:db8::100/64" -network_ipv6_gateway: "2001:db8::254" # VPN gateway host -``` - -## Technical Details - -### Routing Rules Created - -```bash -# Policy routing rules (priority 200) -ip rule add iif eth0 table 100 priority 200 -ip -6 rule add iif eth0 table 100 priority 200 - -# Custom routing table (table 100) -ip route add default dev wg-connection table 100 -ip -6 route add default dev wg-connection table 100 -``` - -### iptables Rules Created - -```bash -# IPv4 NAT masquerading -iptables -t nat -A POSTROUTING -s 192.168.1.0/24 -o wg-connection -j MASQUERADE - -# IPv4 FORWARD rules -iptables -A FORWARD -s 192.168.1.0/24 -j ACCEPT -iptables -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT - -# IPv6 equivalent rules -ip6tables -t nat -A POSTROUTING -s 2001:db8::/64 -o wg-connection -j MASQUERADE -ip6tables -A FORWARD -s 2001:db8::/64 -j ACCEPT -ip6tables -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -``` - -## Troubleshooting - -- **Check VPN connection**: `sudo wg show` should show active connection -- **Verify routing**: `ip rule show` and `ip route show table 100` -- **Test connectivity**: `curl ip.me` should show VPN IP from client machines -- **Check iptables**: `sudo iptables -t nat -L -n -v` should show masquerading rules diff --git a/roles/wireguard_gateway/defaults/main.yml b/roles/wireguard_gateway/defaults/main.yml deleted file mode 100644 index 0086e118..00000000 --- a/roles/wireguard_gateway/defaults/main.yml +++ /dev/null @@ -1,2 +0,0 @@ ---- -wireguard_gateway_enabled: false diff --git a/roles/wireguard_gateway/handlers/main.yml b/roles/wireguard_gateway/handlers/main.yml deleted file mode 100644 index 4b7cb2f2..00000000 --- a/roles/wireguard_gateway/handlers/main.yml +++ /dev/null @@ -1,6 +0,0 @@ ---- -- name: "Reload sysctl" - become: true - ansible.builtin.command: - cmd: "sysctl -p" - changed_when: false diff --git a/roles/wireguard_gateway/meta/argument_specs.yml b/roles/wireguard_gateway/meta/argument_specs.yml deleted file mode 100644 index 23f755b9..00000000 --- a/roles/wireguard_gateway/meta/argument_specs.yml +++ /dev/null @@ -1,10 +0,0 @@ ---- -argument_specs: - main: - description: "Configure WireGuard VPN as a network gateway" - author: "a14m" - options: - wireguard_gateway_enabled: - description: "Toggle flag for enabling/disabling network gateway configurations" - type: "bool" - default: false diff --git a/roles/wireguard_gateway/meta/main.yml b/roles/wireguard_gateway/meta/main.yml deleted file mode 100644 index 36df4aad..00000000 --- a/roles/wireguard_gateway/meta/main.yml +++ /dev/null @@ -1,20 +0,0 @@ ---- -dependencies: - - "wireguard" - -galaxy_info: - author: "a14m" - description: "Install and configure WireGuard VPN as a network gateway" - company: "kartoffeln.work GmbH." - license: "MIT" - min_ansible_version: "2.18" - platforms: - - name: "ArchLinux" - versions: - - "all" - - name: "Ubuntu" - versions: - - "noble" - - name: "Debian" - versions: - - "bookworm" diff --git a/roles/wireguard_gateway/tasks/main.yml b/roles/wireguard_gateway/tasks/main.yml deleted file mode 100644 index 1c2887dc..00000000 --- a/roles/wireguard_gateway/tasks/main.yml +++ /dev/null @@ -1,97 +0,0 @@ ---- -- name: "Ensure iptables are installed" - become: true - ansible.builtin.package: - name: "iptables" - state: "present" - -- name: "Configure IP forwarding" - become: true - ansible.builtin.blockinfile: - path: "/etc/sysctl.conf" - state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" - prepend_newline: true - append_newline: true - marker: "# ==== {mark} ANSIBLE WIREGUARD GATEWAY CONFIG" - create: true - mode: "0644" - block: | - net.ipv4.ip_forward=1 - net.ipv6.conf.all.forwarding=1 - notify: "Reload sysctl" - -# IPv4 iptables rules -- name: "Add IPv4 NAT masquerading for traffic through VPN" - become: true - ansible.builtin.iptables: - table: "nat" - chain: "POSTROUTING" - source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24" - out_interface: "{{ item }}" - jump: "MASQUERADE" - comment: "NAT local subnet traffic through VPN" - state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" - with_items: "{{ wireguard_connections }}" - -- name: "Add IPv4 FORWARD rule to accept traffic from local subnet" - become: true - ansible.builtin.iptables: - chain: "FORWARD" - source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24" - jump: "ACCEPT" - comment: "Allow forwarding from local subnet" - state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" - -- name: "Add IPv4 FORWARD rule to accept established connections" - become: true - ansible.builtin.iptables: - chain: "FORWARD" - match: "conntrack" - ctstate: "RELATED,ESTABLISHED" - jump: "ACCEPT" - comment: "Allow established connections" - state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" - -# IPv6 iptables rules -- name: "Add IPv6 NAT masquerading for traffic through VPN" - become: true - ansible.builtin.iptables: - table: "nat" - chain: "POSTROUTING" - source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}" - out_interface: "{{ item }}" - jump: "MASQUERADE" - comment: "NAT IPv6 local subnet traffic through VPN" - ip_version: "ipv6" - state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" - with_items: "{{ wireguard_connections }}" - failed_when: false - # NOTE: on github the 'IPv6 default: {}' and that makes the task fails - tags: - - molecule-idempotence-notest - -- name: "Add IPv6 FORWARD rule to accept traffic from local subnet" - become: true - ansible.builtin.iptables: - chain: "FORWARD" - source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}" - jump: "ACCEPT" - comment: "Allow IPv6 forwarding from local subnet" - ip_version: "ipv6" - state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" - failed_when: false - # NOTE: on github the 'IPv6 default: {}' and that makes the task fails - tags: - - molecule-idempotence-notest - -- name: "Add IPv6 FORWARD rule to accept established connections" - become: true - ansible.builtin.iptables: - chain: "FORWARD" - match: "conntrack" - ctstate: "RELATED,ESTABLISHED" - jump: "ACCEPT" - comment: "Allow IPv6 established connections" - ip_version: "ipv6" - state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" - failed_when: false |
