Optimise wireguard
This commit is contained in:
parent
6bcf35137f
commit
615929ac4f
@ -87,7 +87,7 @@ fail2ban_activate_modules:
|
|||||||
## WIREGUARD
|
## WIREGUARD
|
||||||
wireguard_enabled: True
|
wireguard_enabled: True
|
||||||
wireguard_is_gateway: False
|
wireguard_is_gateway: False
|
||||||
wireguard_allow_adjacent_client_traffic: False
|
wireguard_allow_adjacent_client_traffic: True
|
||||||
wireguard_keepalive: 25
|
wireguard_keepalive: 25
|
||||||
|
|
||||||
wireguard_gateway_interface: eth0
|
wireguard_gateway_interface: eth0
|
||||||
|
|||||||
@ -1,11 +1,11 @@
|
|||||||
[Interface]
|
[Interface]
|
||||||
Address = {{ wireguard_gateway_net_prefix }}.{{ wireguard_clients[wireguard_client_host].index }}/32
|
Address = {{ wireguard_gateway_net_prefix }}.{{ wireguard_clients[wireguard_client_host].index }}/{{ wireguard_gateway_net_cidr }}
|
||||||
PrivateKey = {{ wireguard_clients[wireguard_client_host].private_key }}
|
PrivateKey = {{ wireguard_clients[wireguard_client_host].private_key }}
|
||||||
DNS = {{ cloud_internal_dns }}
|
DNS = {{ cloud_internal_dns }}
|
||||||
|
|
||||||
[Peer]
|
[Peer]
|
||||||
PublicKey = {{ wireguard_gateway_public_key }}
|
PublicKey = {{ wireguard_gateway_public_key }}
|
||||||
Endpoint = {{ wireguard_gateway_host }}:{{ wireguard_gateway_port }}
|
Endpoint = {{ wireguard_gateway_host }}:{{ wireguard_gateway_port }}
|
||||||
AllowedIPs = {{ wireguard_gateway_net_prefix }}.1/{% if wireguard_allow_adjacent_client_traffic %}{{ wireguard_gateway_net_cidr }}{% else %}32{% endif %}
|
AllowedIPs = {{ wireguard_gateway_net_prefix }}{% if wireguard_allow_adjacent_client_traffic %}.0/{{ wireguard_gateway_net_cidr }}{% else %}.1/32{% endif %}
|
||||||
|
|
||||||
PersistentKeepalive = {{ wireguard_keepalive }}
|
PersistentKeepalive = {{ wireguard_keepalive }}
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user