Saturday, July 6, 2019

How to Build a Dedicated WireGuard VPN Wi-Fi Gateway and LAN Router

Rather than manually configuring WireGuard client software on every smartphone, laptop, and smart TV in your home, you can configure a dedicated Linux machine (such as a Raspberry Pi, Orange Pi, or spare PC) as a standalone VPN Wi-Fi Gateway. Any device connecting to the designated Wi-Fi access point or Ethernet LAN automatically has all its traffic encrypted and tunneled through your remote WireGuard VPS.

Topology: Wi-Fi Clients → Access Point Router → Linux Gateway (dnsmasq + NAT) → Encrypted WireGuard Tunnel (wg0) → Cloud VPS Gateway

1. Cloud Server Configuration (/etc/wireguard/wg0.conf)

[Interface]
Address = 10.200.200.1/24
ListenPort = 51820
PrivateKey = SERVER_PRIVATE_KEY
PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE

[Peer]
PublicKey = GATEWAY_PUBLIC_KEY
AllowedIPs = 10.200.200.2/32

2. Linux Gateway Router Setup (wg0.conf)

[Interface]
Address = 10.200.200.2/24
PrivateKey = GATEWAY_PRIVATE_KEY
DNS = 1.1.1.1

[Peer]
PublicKey = SERVER_PUBLIC_KEY
Endpoint = VPS_PUBLIC_IP:51820
AllowedIPs = 0.0.0.0/0
PersistentKeepalive = 25

3. Routing and NAT Masquerading

Enable IPv4 packet forwarding and route traffic arriving on your local LAN NIC (e.g. eth1) through the WireGuard interface (wg0):

echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf
sysctl -p

iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE
iptables -A FORWARD -i eth1 -o wg0 -j ACCEPT
iptables -A FORWARD -i wg0 -o eth1 -m state --state RELATED,ESTABLISHED -j ACCEPT

No comments:

Post a Comment

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...