diff options
| -rw-r--r-- | roles/wireguard_gateway/tasks/main.yml | 24 |
1 files changed, 24 insertions, 0 deletions
diff --git a/roles/wireguard_gateway/tasks/main.yml b/roles/wireguard_gateway/tasks/main.yml index f8cb1ed0..c33a49bf 100644 --- a/roles/wireguard_gateway/tasks/main.yml +++ b/roles/wireguard_gateway/tasks/main.yml @@ -21,6 +21,17 @@ notify: "Reload sysctl" # IPv4 iptables rules +- name: "Add IPv4 NAT masquerading for traffic through internet" + become: true + ansible.builtin.iptables: + table: "nat" + chain: "POSTROUTING" + source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24" + out_interface: "{{ ansible_default_ipv4.interface }}" + jump: "MASQUERADE" + comment: "NAT local subnet traffic through internet" + state: "present" + - name: "Add IPv4 NAT masquerading for traffic through VPN" become: true ansible.builtin.iptables: @@ -53,6 +64,19 @@ state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" # IPv6 iptables rules +- name: "Add IPv6 NAT masquerading for traffic through internet" + become: true + ansible.builtin.iptables: + table: "nat" + chain: "POSTROUTING" + source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}" + out_interface: "{{ ansible_default_ipv6.interface }}" + jump: "MASQUERADE" + comment: "NAT IPv6 local subnet traffic through internet" + ip_version: "ipv6" + state: "present" + when: ansible_default_ipv6.address is defined + - name: "Add IPv6 NAT masquerading for traffic through VPN" become: true ansible.builtin.iptables: |
