diff options
Diffstat (limited to 'roles/wireguard_gateway/tasks/main.yml')
| -rw-r--r-- | roles/wireguard_gateway/tasks/main.yml | 112 |
1 files changed, 112 insertions, 0 deletions
diff --git a/roles/wireguard_gateway/tasks/main.yml b/roles/wireguard_gateway/tasks/main.yml new file mode 100644 index 00000000..c33a49bf --- /dev/null +++ b/roles/wireguard_gateway/tasks/main.yml @@ -0,0 +1,112 @@ +--- +- name: "Ensure iptables are installed" + become: true + ansible.builtin.package: + name: "iptables" + state: "present" + +- name: "Configure IP forwarding" + become: true + ansible.builtin.blockinfile: + path: "/etc/sysctl.conf" + state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" + prepend_newline: true + append_newline: true + marker: "# ==== {mark} ANSIBLE WIREGUARD GATEWAY CONFIG" + create: true + mode: "0644" + block: | + net.ipv4.ip_forward=1 + net.ipv6.conf.all.forwarding=1 + notify: "Reload sysctl" + +# IPv4 iptables rules +- name: "Add IPv4 NAT masquerading for traffic through internet" + become: true + ansible.builtin.iptables: + table: "nat" + chain: "POSTROUTING" + source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24" + out_interface: "{{ ansible_default_ipv4.interface }}" + jump: "MASQUERADE" + comment: "NAT local subnet traffic through internet" + state: "present" + +- name: "Add IPv4 NAT masquerading for traffic through VPN" + become: true + ansible.builtin.iptables: + table: "nat" + chain: "POSTROUTING" + source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24" + out_interface: "{{ item }}" + jump: "MASQUERADE" + comment: "NAT local subnet traffic through VPN" + state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" + with_items: "{{ wireguard_connections }}" + +- name: "Add IPv4 FORWARD rule to accept traffic from local subnet" + become: true + ansible.builtin.iptables: + chain: "FORWARD" + source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24" + jump: "ACCEPT" + comment: "Allow forwarding from local subnet" + state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" + +- name: "Add IPv4 FORWARD rule to accept established connections" + become: true + ansible.builtin.iptables: + chain: "FORWARD" + match: "conntrack" + ctstate: "RELATED,ESTABLISHED" + jump: "ACCEPT" + comment: "Allow established connections" + state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" + +# IPv6 iptables rules +- name: "Add IPv6 NAT masquerading for traffic through internet" + become: true + ansible.builtin.iptables: + table: "nat" + chain: "POSTROUTING" + source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}" + out_interface: "{{ ansible_default_ipv6.interface }}" + jump: "MASQUERADE" + comment: "NAT IPv6 local subnet traffic through internet" + ip_version: "ipv6" + state: "present" + when: ansible_default_ipv6.address is defined + +- name: "Add IPv6 NAT masquerading for traffic through VPN" + become: true + ansible.builtin.iptables: + table: "nat" + chain: "POSTROUTING" + source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}" + out_interface: "{{ item }}" + jump: "MASQUERADE" + comment: "NAT IPv6 local subnet traffic through VPN" + ip_version: "ipv6" + state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" + with_items: "{{ wireguard_connections }}" + +- name: "Add IPv6 FORWARD rule to accept traffic from local subnet" + become: true + ansible.builtin.iptables: + chain: "FORWARD" + source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}" + jump: "ACCEPT" + comment: "Allow IPv6 forwarding from local subnet" + ip_version: "ipv6" + state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" + +- name: "Add IPv6 FORWARD rule to accept established connections" + become: true + ansible.builtin.iptables: + chain: "FORWARD" + match: "conntrack" + ctstate: "RELATED,ESTABLISHED" + jump: "ACCEPT" + comment: "Allow IPv6 established connections" + ip_version: "ipv6" + state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" |
