Rather than manually configuring WireGuard client software on every smartphone, laptop, and smart TV in your home, you can configure a dedicated Linux machine (such as a Raspberry Pi, Orange Pi, or spare PC) as a standalone VPN Wi-Fi Gateway. Any device connecting to the designated Wi-Fi access point or Ethernet LAN automatically has all its traffic encrypted and tunneled through your remote WireGuard VPS.
Topology: Wi-Fi Clients → Access Point Router → Linux Gateway (dnsmasq + NAT) → Encrypted WireGuard Tunnel (wg0) → Cloud VPS Gateway
1. Cloud Server Configuration (/etc/wireguard/wg0.conf)
[Interface]
Address = 10.200.200.1/24
ListenPort = 51820
PrivateKey = SERVER_PRIVATE_KEY
PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
[Peer]
PublicKey = GATEWAY_PUBLIC_KEY
AllowedIPs = 10.200.200.2/32
2. Linux Gateway Router Setup (wg0.conf)
[Interface]
Address = 10.200.200.2/24
PrivateKey = GATEWAY_PRIVATE_KEY
DNS = 1.1.1.1
[Peer]
PublicKey = SERVER_PUBLIC_KEY
Endpoint = VPS_PUBLIC_IP:51820
AllowedIPs = 0.0.0.0/0
PersistentKeepalive = 25
3. Routing and NAT Masquerading
Enable IPv4 packet forwarding and route traffic arriving on your local LAN NIC (e.g. eth1) through the WireGuard interface (wg0):
echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf
sysctl -p
iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE
iptables -A FORWARD -i eth1 -o wg0 -j ACCEPT
iptables -A FORWARD -i wg0 -o eth1 -m state --state RELATED,ESTABLISHED -j ACCEPT
No comments:
Post a Comment