105 lines
2.7 KiB
Plaintext
105 lines
2.7 KiB
Plaintext
# This is an example of WireGuard Dashboard Setup to allow LAN Access:
|
|
|
|
Name wg0 (allowing LAN access)
|
|
Public Key your_public_key
|
|
Private Key your_private_key
|
|
IP Adress/CIDR
|
|
10.0.0.1/24
|
|
Listen Port
|
|
51888 (of your choosing, your router MUST forward this port from WAN to the wgdashboard IP - docker machine)
|
|
|
|
Optional Settings:
|
|
Table
|
|
blank
|
|
PreUp
|
|
blank
|
|
PreDown
|
|
blank
|
|
PostUp (eth0 is typical but change if yours is not...)
|
|
iptables -A FORWARD -i wg0 -j ACCEPT; iptables -A FORWARD -o wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE;
|
|
PostDown
|
|
iptables -D FORWARD -i wg0 -iptables -D FORWARD -i wg0 -j ACCEPT; iptables -D FORWARD -o wg0 -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE;
|
|
|
|
Override Peer Settings
|
|
Only apply to peers in this configuration
|
|
DNS
|
|
192.168.X.X (your internet Router DHCP given Gateway IP)
|
|
Endpoint Allowed IPs
|
|
0.0.0.0/0
|
|
Listen Port
|
|
51888 (same as wg0's)
|
|
MTU
|
|
1420
|
|
Peer Remote Endpoint
|
|
your_subdomain.duckdns.org
|
|
Persistent Keepalive
|
|
21
|
|
|
|
example Peer Settings:
|
|
Public Key your_peer_pubkey
|
|
Name
|
|
cool_name_ISP_IP_and_LAN_access
|
|
Notes
|
|
blank
|
|
Private Key(Required for QR Code and Download)
|
|
your_peer_privkey
|
|
Allowed IPs(Required)
|
|
10.0.0.2/32
|
|
Endpoint Allowed IPs(Required)
|
|
0.0.0.0/0
|
|
DNS
|
|
1.1.1.1
|
|
|
|
# This is an example of WireGuard Dashboard Setup to NOT allow LAN Access, e.g. to share your ISP IP for family and friends:
|
|
|
|
Name wg1 (disallowing LAN access)
|
|
Public Key your_public_key
|
|
Private Key your_private_key
|
|
IP Adress/CIDR
|
|
10.20.0.1/24
|
|
Listen Port
|
|
51820 (of your choosing, your router MUST forward this port from WAN to the wgdashboard IP - docker machine)
|
|
|
|
Optional Settings:
|
|
Table
|
|
blank
|
|
PreUp
|
|
blank
|
|
PreDown
|
|
blank
|
|
PostUp (eth0 is typical but change if yours is not...)
|
|
to DISALLOW LAN access enter your router DHCP subnet where it says 192.168.X.0/24, e.g 192.168.0.0/24 or 192.168.1.0/24
|
|
iptables -A FORWARD -i wg1 -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE; iptables -I FORWARD -i wg1 -d 192.168.X.0/24 -j REJECT
|
|
PostDown
|
|
iptables -D FORWARD -i wg1 -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE; iptables -D FORWARD -i wg1 -d 192.168.X.0/24 -j REJECT
|
|
|
|
Override Peer Settings
|
|
Only apply to peers in this configuration
|
|
DNS
|
|
1.1.1.1 (your internet Router DHCP given Gateway IP will not work as we are blocking it so here use public one like 9.9.9.9 or 8.8.8.8)
|
|
Endpoint Allowed IPs
|
|
0.0.0.0/0
|
|
Listen Port
|
|
51820 (same as wg1's)
|
|
MTU
|
|
1420
|
|
Peer Remote Endpoint
|
|
your_subdomain.duckdns.org
|
|
Persistent Keepalive
|
|
21
|
|
|
|
example Peer Settings:
|
|
Public Key your_peer_pubkey
|
|
Name
|
|
cool_name_ISP_IP_only_no_LAN_access
|
|
Notes
|
|
blank
|
|
Private Key(Required for QR Code and Download)
|
|
your_peer_privkey
|
|
Allowed IPs(Required)
|
|
10.20.0.2/32
|
|
Endpoint Allowed IPs(Required)
|
|
0.0.0.0/0
|
|
DNS
|
|
1.1.1.1
|