Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- głupi AP - serwer WG + serwer DHCP-Guest:
- /etc/config/network
- ....
- config interface 'wg0'
- option proto 'wireguard'
- option private_key 'xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx'
- option listen_port '55055'
- list addresses '10.9.0.1/24'
- option mtu 2800
- config wireguard_wg0
- option public_key 'xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx'
- option route_allowed_ips '1'
- option allowed_ips '10.9.0.2/24 192.168.2.0/24'
- option persistent_keepalive '25'
- option description 'peer2'
- config interface 'gretap'
- option proto 'gretap'
- option peeraddr '10.9.0.2'
- option ipaddr '10.9.0.1'
- option tunlink 'wg0'
- option mtu '1560'
- config device
- option name 'br-guest'
- option type 'bridge'
- list ports '@gretap'
- config interface 'guest'
- option proto 'static'
- option device 'br-guest'
- list ipaddr '172.16.0.1'
- option netmask '255.255.255.0'
- /etc/config/dhcp
- ...
- config dhcp 'guest'
- option interface 'guest'
- option start '100'
- option limit '10'
- option leasetime '12h'
- option dhcpv4 'server'
- option dhcpv6 'server'
- option ra 'server'
- option ra_slaac '1'
- list ra_flags 'managed-config'
- list ra_flags 'other-config'
- list dhcp_option '3'
- list dhcp_option '6'
- /etc/config/firewall
- ....
- config zone
- option name wg
- list network 'wg0'
- option input ACCEPT
- option output ACCEPT
- option forward ACCEPT
- config forwarding
- option src wg
- option dest lan
- config forwarding
- option src lan
- option dest wg
- config zone
- option name guest
- list network 'guest'
- option input ACCEPT
- option output ACCEPT
- option forward ACCEPT
- /etc/firewall.user
- #blokada z sieci Guest do lokalnej sieci LAN1
- iptables -I input_rule -s 172.16.0.0/24 -d 192.168.1.0/24 -j DROP
- #blokada z lokalnej sieci LAN1 do sieci Guest.
- iptables -I input_rule -d 172.16.0.0/24 -s 192.168.1.0/24 -j DROP
- /etc/config/wireless
- ....
- config wifi-iface 'default_radio0'
- option device 'radio0'
- option network 'lan'
- option mode 'ap'
- option ssid 'LAN1'
- option encryption 'psk2'
- option key 'passwordlan1'
- config wifi-iface 'guest'
- option device 'radio0'
- option network 'guest'
- option mode 'ap'
- option ssid 'guest1'
- option encryption 'psk2'
- option key 'passwordguest1'
- ############################################################################
- Peer WG + client DHCP Guest
- /etc /config/network
- ....
- config interface 'wg0'
- option proto 'wireguard'
- option private_key 'yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy'
- list addresses '10.9.0.2/24'
- option mtu 2800
- config wireguard_wg0
- option public_key 'yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy'
- option route_allowed_ips '1'
- option allowed_ips '10.9.0.0/24 192.168.1.0/24'
- option endpoint_host 'Public_IP_routera_brzegowego'
- option endpoint_port '55055'
- option persistent_keepalive '25'
- option description 'serwer_WG'
- config interface 'gretap'
- option proto 'gretap
- option peeraddr '10.9.0.1'
- option ipaddr '10.9.0.2'
- option tunlink 'wg0'
- option mtu '1560'
- config device
- option name 'br-guest'
- option type 'bridge'
- list ports '@gretap'
- config interface 'guest'
- option proto 'dhcp'
- option device 'br-guest'
- /etc/config/dhcp
- ...
- config dhcp 'guest'
- option interface 'guest'
- option ignore '1'
- /etc/config/firewall
- ....
- config zone
- option name wg
- list network 'wg0'
- option input ACCEPT
- option output ACCEPT
- option forward ACCEPT
- config forwarding
- option src lan
- option dest wg
- config forwarding
- option src wg
- option dest lan
- config zone
- option name guest
- list network 'guest'
- option input ACCEPT
- option output ACCEPT
- option forward ACCEPT
- /etc/firewall.user
- #blokada z sieci Guest do lokalnej sieci LAN2
- iptables -I input_rule -s 172.16.0.0/24 -d 192.168.2.0/24 -j DROP
- #blokada z lokalnej sieci LAN2 do sieci Guest.
- iptables -I input_rule -d 172.16.0.0/24 -s 192.168.2.0/24 -j DROP
- /etc/config/wireless
- ....
- config wifi-iface 'default_radio0'
- option device 'radio0'
- option network 'lan'
- option mode 'ap'
- option ssid 'LAN2'
- option encryption 'psk2'
- option key 'passwordlan2'
- config wifi-iface 'guest'
- option device 'radio0'
- option network 'guest'
- option mode 'ap'
- option ssid 'guest2'
- option encryption 'psk2'
- option key 'passwordguest2'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement