2022-06-18 14:12:12 +02:00
|
|
|
[Interface]
|
2023-03-05 04:26:29 +01:00
|
|
|
{% for addr in wireguard.cidr %}
|
|
|
|
Address = {{ addr }}
|
|
|
|
{% endfor %}
|
2022-06-18 14:12:12 +02:00
|
|
|
MTU = 1420
|
|
|
|
SaveConfig = true
|
|
|
|
PostUp = iptables -A FORWARD -i wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE; ip6tables -A FORWARD -i wg0 -j ACCEPT; ip6tables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
|
|
|
|
PostDown = iptables -D FORWARD -i wg0 -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE; ip6tables -D FORWARD -i wg0 -j ACCEPT; ip6tables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
|
2023-03-05 04:26:29 +01:00
|
|
|
ListenPort = {{ wireguard.port }}
|
2022-06-18 14:12:12 +02:00
|
|
|
PrivateKey = {{ wireguard.private_key }}
|
|
|
|
|
|
|
|
{% for peer in wireguard_peers %}
|
|
|
|
# Peer: {{ peer.name }}
|
|
|
|
[Peer]
|
|
|
|
PublicKey = {{ peer.pubkey }}
|
|
|
|
AllowedIPs = {{ peer.allowedips | join(", ") }}
|
2023-03-05 04:26:29 +01:00
|
|
|
{% if peer.endpoint is defined %}
|
|
|
|
Endpoint = {{ peer.endpoint }}
|
|
|
|
{% endif %}
|
|
|
|
{% if peer.keepalive is defined %}
|
|
|
|
PersistentKeepalive = {{ peer.keepalive }}
|
|
|
|
{% endif %}
|
2022-06-18 14:12:12 +02:00
|
|
|
|
|
|
|
{% endfor %}
|