sudo apt-cache policy wireguard to see if it is in the repository
sudo apt install wireguard -y to get it
To created the keys
sudo su to become root and able to do:
cd /etc/wireguard
$(umask 077; wg genkey | tee privatekey_<name> | wg pubkey > publickey_<name>) produce new private and public keys. After that exit to become a regular user again.
In case multiple key pairs are required, the optional _ appendix identifies them. Especially the <name>privatekey should be kept in a secret location, it is also recommended to recreate new keys for new things and changing them would not hurt either. However when having lots of devices connected to a central server over long distances, it is a disaster loosing the privatekey of the server. It is therefore recommended to do a backup of it.
When changing or updating the server hardware then use the keys from the old server. Prepare everything and then change the routers port forwarding from the old server to the new server.
Now it needs to be decided if the raspberry will act as a server or a client.
Server Examples:
A Raspberry at home that runs 24h a day and can be accessed from everywhere used router to a other location is a typical wireguard server.
It will be used as a webserver
Client Examples:
A IoT device located somewhere that needs access to the home network is a typical wireguard client
sudo touch /etc/wireguard/wg0.conf and edit the wireguard configuration file.
When having multiple tunnels do not call them wg0.conf and wg1.conf give more meaningful names as wg_<tunnel destination>.conf
Put an entry in the wireguard server to know the raspberry public key and its VPN wireguard address.
[Interface] Address =<Raspberry VPN wireguard address>PrivateKey =</etc/wireguard/privatekey of the raspberry>[Peer] PublicKey =</etc/wireguard/publickey of the wireguard server>AllowedIPs =<wireguard address of the server><optional Addresses that will be accessed using the tunnel>Endpoint =<url or IP address of the server>:51820
A tunnel can not be created from the server to a client. The tunnel must be created by the client. Methods to create the tunnel from the client:
use rpi-connect to a remote client
use a computer on the same local network as the client and log in with ssh
attach monitor and keyboard to the client and work locally
add a cron job that checks for the tunnel and if not creates it
and edit it
[Interface] Address =<Raspberry VPN wireguard address>ListenPort = 51820 PrivateKey =</etc/wireguard/privatekey of the raspberry>[Peer] PublicKey =</etc/wireguard/publickey of the client device>AllowedIPs =<wireguard address of the client device>
For every device added to the server add a [Peer] entry
sudo wg-quick up wg0 to bring it up
sudo ifconfig to see if it is there
sudo wg show to see
sudo wg-quick down wg0 to bring it down
To have the tunnel working obviously the server needs to know about the raspberry. Do the necessary work there and restart the wireguard server.
sudo systemctl enable wg-quick@wg0 to have it started automatically
sudo systemctl restart wg-quick@wg0
Stopping the tunnel breaks it. Don’t saw off the branch you’re sitting on, use restart.
PersistentKeepalive = 25
Can be put optional into wg0.conf. It sends out every 25 seconds something so the tunnel will not collapse when not used. Without this the routers on the way of the tunnel will collapse it when not in use.
If PersistentKeepalive is used the wg-quick service needs to be restarted when the wireguard configuration has been modified. Otherwise it tries to continioue with the old configuration.
A wireguard client might want to access an other wireguard client using a ping or accessing the other clients webserver.
To make this happen the sender client must pass all wireguard addresses to the wireguard server. This is done with the AllowedIPs setting. Use either wildcard or adding the receivers IP.
AllowedIPs = 192.168.10.0/24
The wireguard setver must be configured to forward the messages cat /proc/sys/net/ipv4/ip_forward has to show 1.
The wiregurd server must also know to what interfaces to use. This is done with nftables
Create /etc/nftables.config (backup an existing /etc/nftables.config) as:
#!/usr/sbin/nft -f
flush ruleset
table inet filter {
chain forward {
type filter hook forward priority filter; policy drop;
iifname "wg0" oifname "eth0" accept
iifname "eth0" oifname "wg0" accept
iifname "wg0" oifname "wg0" accept
}
}
sudo systemctl stop nftables
sudo systemctl start nftables
sudo systemctl status nftables
sudo systemctl enable nftables