1
0

Pin tunnel ips

This commit is contained in:
clerie 2021-02-03 18:50:17 +01:00
parent 6fa28acff8
commit e64e66ecd2

View File

@ -33,7 +33,7 @@
networking.wireguard.enable = true; networking.wireguard.enable = true;
networking.wireguard.interfaces = { networking.wireguard.interfaces = {
wg-carbon = { wg-carbon4 = {
ips = [ "fe80::138:1/64" "169.254.138.1/24" ]; ips = [ "fe80::138:1/64" "169.254.138.1/24" ];
peers = [ { peers = [ {
allowedIPs = [ "0.0.0.0/0" "::/0" ]; allowedIPs = [ "0.0.0.0/0" "::/0" ];
@ -41,18 +41,18 @@
} ]; } ];
listenPort = 50138; listenPort = 50138;
allowedIPsAsRoutes = false; allowedIPsAsRoutes = false;
privateKeyFile = "/var/src/secrets/wireguard/wg-carbon"; privateKeyFile = "/var/src/secrets/wireguard/wg-carbon4";
}; };
wg-nonat = { wg-nonat6 = {
ips = [ "fe80::1337:1/64" "169.254.137.1/24" ]; ips = [ "fe80::1337:1/64" "169.254.137.1/24" ];
peers = [ { peers = [ {
allowedIPs = [ "0.0.0.0/0" "::/0" ]; allowedIPs = [ "0.0.0.0/0" "::/0" ];
endpoint = "nonat.net.clerie.de:51337"; endpoint = "[2001:638:904:ffca::6]:51337";
publicKey = "Z5HltUKBSOzePqZCJjSsJPZ3UxGjFR4a5Vxmm+ePNRk="; publicKey = "Z5HltUKBSOzePqZCJjSsJPZ3UxGjFR4a5Vxmm+ePNRk=";
} ]; } ];
listenPort = 51337; listenPort = 51337;
allowedIPsAsRoutes = false; allowedIPsAsRoutes = false;
privateKeyFile = "/var/src/secrets/wireguard/wg-nonat"; privateKeyFile = "/var/src/secrets/wireguard/wg-nonat6";
}; };
}; };
@ -112,11 +112,11 @@
export all; export all;
}; };
area 0 { area 0 {
interface "wg-carbon" { interface "wg-carbon4" {
cost 80; cost 80;
type pointopoint; type pointopoint;
}; };
interface "wg-nonat" { interface "wg-nonat6" {
cost 80; cost 80;
type pointopoint; type pointopoint;
}; };
@ -130,11 +130,11 @@
export all; export all;
}; };
area 0 { area 0 {
interface "wg-carbon" { interface "wg-carbon4" {
cost 80; cost 80;
type pointopoint; type pointopoint;
}; };
interface "wg-nonat" { interface "wg-nonat6" {
cost 80; cost 80;
type pointopoint; type pointopoint;
}; };