From 0985f7534da7ffabec9e707f0a355a8307b1ea97 Mon Sep 17 00:00:00 2001 From: Ahmed Abdelhalim Date: Wed, 3 Sep 2025 02:14:06 +0200 Subject: Fix networking issue This allows forwarding the traffic through the pi (similar to how the VPN is routing all the traffic using it's iptables) This means that the role is more of a general gateway When the vpn is activated it handles routing all the traffic through it This commits provide the same functionality when the VPN isn't active --- roles/wireguard_gateway/tasks/main.yml | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/roles/wireguard_gateway/tasks/main.yml b/roles/wireguard_gateway/tasks/main.yml index f8cb1ed0..c33a49bf 100644 --- a/roles/wireguard_gateway/tasks/main.yml +++ b/roles/wireguard_gateway/tasks/main.yml @@ -21,6 +21,17 @@ notify: "Reload sysctl" # IPv4 iptables rules +- name: "Add IPv4 NAT masquerading for traffic through internet" + become: true + ansible.builtin.iptables: + table: "nat" + chain: "POSTROUTING" + source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24" + out_interface: "{{ ansible_default_ipv4.interface }}" + jump: "MASQUERADE" + comment: "NAT local subnet traffic through internet" + state: "present" + - name: "Add IPv4 NAT masquerading for traffic through VPN" become: true ansible.builtin.iptables: @@ -53,6 +64,19 @@ state: "{{ 'present' if wireguard_gateway_enabled else 'absent' }}" # IPv6 iptables rules +- name: "Add IPv6 NAT masquerading for traffic through internet" + become: true + ansible.builtin.iptables: + table: "nat" + chain: "POSTROUTING" + source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}" + out_interface: "{{ ansible_default_ipv6.interface }}" + jump: "MASQUERADE" + comment: "NAT IPv6 local subnet traffic through internet" + ip_version: "ipv6" + state: "present" + when: ansible_default_ipv6.address is defined + - name: "Add IPv6 NAT masquerading for traffic through VPN" become: true ansible.builtin.iptables: -- cgit v1.2.3