summaryrefslogtreecommitdiff
path: root/roles/install_wireguard_backbone/templates
diff options
context:
space:
mode:
authorNiklas Yann Wettengel <niyawe@niyawe.de>2018-01-26 15:37:08 +0100
committerNiklas Yann Wettengel <niyawe@niyawe.de>2018-01-26 15:37:08 +0100
commit663c6c74c629fc3785a9f9846e5be104e10c78ca (patch)
tree37b244e2aa45ee06c3d60273bd90fc7d1c10aeb6 /roles/install_wireguard_backbone/templates
parent41b22ed59b80bc49275ebc5b2f2fed5a7c1863a0 (diff)
uplink: add additional peers
Diffstat (limited to 'roles/install_wireguard_backbone/templates')
-rw-r--r--roles/install_wireguard_backbone/templates/down2.sh.j25
-rw-r--r--roles/install_wireguard_backbone/templates/up2.sh.j28
-rw-r--r--roles/install_wireguard_backbone/templates/wg2.conf.j29
3 files changed, 22 insertions, 0 deletions
diff --git a/roles/install_wireguard_backbone/templates/down2.sh.j2 b/roles/install_wireguard_backbone/templates/down2.sh.j2
new file mode 100644
index 0000000..fbdd387
--- /dev/null
+++ b/roles/install_wireguard_backbone/templates/down2.sh.j2
@@ -0,0 +1,5 @@
+#!/bin/bash
+ip -4 rule del iif bb{{ item.name }} table ffmyk
+ip -6 rule del iif bb{{ item.name }} table ffmyk
+ip link set down dev bb{{ item.name }}
+ip link del bb{{ item.name }}
diff --git a/roles/install_wireguard_backbone/templates/up2.sh.j2 b/roles/install_wireguard_backbone/templates/up2.sh.j2
new file mode 100644
index 0000000..dae70a4
--- /dev/null
+++ b/roles/install_wireguard_backbone/templates/up2.sh.j2
@@ -0,0 +1,8 @@
+#!/bin/bash
+ip link add bb{{ item.name }} type wireguard
+wg setconf bb{{ item.name }} /etc/wireguard/wgbb{{ item.name }}.conf
+ip addr add {{ wireguard_bb_ipv6 }} dev bb{{ item.name }}
+ip addr add {{ wireguard_bb_ipv4 }}/32 peer {{ item.ipv4 }}/32 dev bb{{ item.name }}
+ip link set up dev bb{{ item.name }}
+ip -4 rule add iif bb{{ item.name }} table ffmyk priority 10
+ip -6 rule add iif bb{{ item.name }} table ffmyk priority 10
diff --git a/roles/install_wireguard_backbone/templates/wg2.conf.j2 b/roles/install_wireguard_backbone/templates/wg2.conf.j2
new file mode 100644
index 0000000..cbccda8
--- /dev/null
+++ b/roles/install_wireguard_backbone/templates/wg2.conf.j2
@@ -0,0 +1,9 @@
+[Interface]
+ListenPort = {{ item.port }}
+PrivateKey = {{ wireguard_bb_priv_key }}
+
+[Peer]
+PublicKey = {{ item.pub_key }}
+AllowedIPs = 0.0.0.0/0,::/0
+Endpoint = [{{ item.endpoint }}]:{{ wireguard_bb_port }}
+PersistentKeepalive = 30