EXPERIMENT: wireguard config
This commit is contained in:
@@ -0,0 +1,29 @@
|
||||
# reference: https://www.procustodibus.com/blog/2022/06/multi-hop-wireguard/#site-gateway-as-a-spoke
|
||||
# this configuration is for a device on the home network
|
||||
# it exposes the entire home network to outside peers
|
||||
|
||||
{ip, config, pkgs, ...}@inputs: {
|
||||
networking = {
|
||||
firewall.allowedUDPPorts = [56878];
|
||||
wireguard = {
|
||||
enable = true;
|
||||
interfaces.wg0 = {
|
||||
ips = [ ("192.168.87." ++ ip ++ "/32")];
|
||||
listenPort = 56878;
|
||||
privateKeyFile = "/root/wg.keys";
|
||||
|
||||
peers = [
|
||||
{
|
||||
name = "hub";
|
||||
publicKey = "XEaJXQW+7llbreoK161NkMhFxlctL1UK8nFiY/GtuC0=";
|
||||
allowedIPs = [ "192.168.178.0/24" "192.168.87.127/32" "192.168.87.128/25"];
|
||||
endpoint = "173.249.36.74:56878";
|
||||
persistentKeepalive = 20;
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user