# VPN Setup for Monitoring Stack ## Architecture ``` Internet (public) ├─ [Prod/Pre-prod] (accessible) │ └─→(1514/tcp)→ monitoring-uber (port ouvert) │ ├─ [VPN Server] (nouveau VPS, 1 CPU 2GB RAM) │ └─ WireGuard 0.0.0.0:51820/udp │ └─ [monitoring-uber] (185.103.167.138) ├─ Client VPN (10.0.0.2) └─ Services: Wazuh, Dozzle, Beszel, S3 (VPN only) VPN Network: 10.0.0.0/24 ├─ VPN Server: 10.0.0.1 ├─ monitoring-uber: 10.0.0.2 └─ Admins: 10.0.0.3+ ``` ## Configuration **Mode:** VPN + Internet normal (pas de kill switch) - Admins connectés au VPN → accès à services VPN (10.0.0.0/24) - Admins gardent aussi accès à Internet normal (pas de restriction) - Si VPN tombe → retrouvent Internet automatiquement --- ## Implementation Steps ### Phase 1: VPN Server Setup (nouveau VPS) ```bash # 1. Login to VPS ssh root@ # 2. Run firewall setup chmod +x /path/to/firewall-vpn-server.sh ./firewall-vpn-server.sh # 3. Setup WireGuard server chmod +x /path/to/wireguard-server-setup.sh ./wireguard-server-setup.sh # Output will show: # - Server Public Key (note this) # - Example: aBcDeFgHiJkLmNoPqRsTuVwXyZ1234567890AbCdE= ``` Save the **Server Public Key** — you'll need it for clients. ### Phase 2: monitoring-uber VPN Client ```bash # 1. Login to monitoring-uber ssh root@185.103.167.138 # 2. Run firewall setup chmod +x /path/to/firewall-monitoring-uber.sh ./firewall-monitoring-uber.sh # 3. Setup WireGuard client # Syntax: wireguard-client-setup.sh chmod +x /path/to/wireguard-client-setup.sh ./wireguard-client-setup.sh "" # Example: # ./wireguard-client-setup.sh 123.45.67.89 "aBcDeFgHiJkLmNoPqRsTuVwXyZ1234567890AbCdE=" # Output will show: # - Client Public Key (note this) # - Example: XyZ9876543210AbCdEfGhIjKlMnOpQrStUvWxYz= ``` ### Phase 3: Add monitoring-uber to VPN Server ```bash # Back on VPS, add monitoring-uber as a peer ssh root@ # Use the Client Public Key from Phase 2 wg set wg0 peer allowed-ips 10.0.0.2/32 # Verify wg show # Example output: # interface: wg0 # public key: aBcDeFgHiJkLmNoPqRsTuVwXyZ1234567890AbCdE= # private key: (hidden) # listening port: 51820 # # peer: XyZ9876543210AbCdEfGhIjKlMnOpQrStUvWxYz= # endpoint: :xxxxx # allowed ips: 10.0.0.2/32 # latest handshake: X seconds ago # transfer: X B received, X B sent ``` ### Phase 4: Verify VPN Connection ```bash # On monitoring-uber ping 10.0.0.1 # Should respond # PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. # 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=XX.X ms # Check interface ip addr show wg0 ``` ### Phase 5: Rebind Services to VPN IP ```bash # On monitoring-uber chmod +x /path/to/rebind-services-to-vpn.sh ./rebind-services-to-vpn.sh # This will update docker-compose-security.yml: # - Wazuh Dashboard: 0.0.0.0:443 → 10.0.0.2:443 # - Dozzle: 0.0.0.0:8080 → 10.0.0.2:8080 # - Beszel: 0.0.0.0:9090 → 10.0.0.2:9090 # - S3/RustFS: 0.0.0.0:9000/9001 → 10.0.0.2:9000/9001 # - Wazuh Manager: stays on 0.0.0.0:1514 (for agents) # Restart services cd /home/ubuntu/docker docker compose -f docker-compose-security.yml down docker compose -f docker-compose-security.yml up -d # Verify docker ps ``` ### Phase 6: Ajouter un admin VPN La clé privée ne doit **jamais quitter la machine de l'admin**. La procédure se fait en deux temps. #### Étape A — Sur la machine de l'admin (à faire par l'admin) Installer WireGuard si besoin : - Windows/Mac : https://www.wireguard.com/install/ - Linux : `sudo apt install wireguard` Générer les clés **localement** : ```bash # Linux / Mac wg genkey | tee privatekey | wg pubkey > publickey cat privatekey # à garder secret cat publickey # à envoyer à l'administrateur VPN ``` ```powershell # Windows (PowerShell, WireGuard installé) cd "C:\Program Files\WireGuard" .\wireguard.exe /genkey | Out-File -Encoding ascii privatekey.txt Get-Content privatekey.txt | .\wireguard.exe /pubkey | Out-File -Encoding ascii publickey.txt type publickey.txt # à envoyer à l'administrateur VPN ``` Créer le fichier de config `admin_nom.conf` **sur sa machine** : ```ini [Interface] Address = 10.0.0.X/32 # IP assignée par l'administrateur VPN PrivateKey = DNS = 8.8.8.8 [Peer] PublicKey = VQa6g1foaXhJgYWbwyJ9R/EAmmXg0nOnhPhbIIPLlmg= AllowedIPs = 10.0.0.0/24 Endpoint = 45.150.111.158:51820 PersistentKeepalive = 25 ``` Importer ce fichier dans l'app WireGuard → **Tunnel prêt, pas encore actif**. #### Étape B — Sur le serveur VPN (à faire par l'administrateur) L'admin envoie sa **clé publique** et l'administrateur l'ajoute : ```bash ssh root@45.150.111.158 # Assigner une IP libre (voir tableau ci-dessous) et ajouter le peer wg set wg0 peer allowed-ips 10.0.0.X/32 # Persister la config (survie au reboot) wg-quick save wg0 # Vérifier wg show ``` L'admin peut maintenant activer le tunnel dans l'app WireGuard. #### IPs assignées | Admin | IP VPN | Clé publique | |--------|------------|--------------| | admin1 | 10.0.0.3 | (voir admin1.conf) | | admin2 | 10.0.0.10 | `SL6qEf2K0/3a26wBkvQpOmgILHxxLS1N8M5hJAqfRCc=` | Prochaine IP libre : **10.0.0.11** ### Phase 7: Admin Connection Each admin: 1. Download WireGuard app: https://www.wireguard.com/install/ 2. Import config file (admin1.conf, admin2.conf, etc.) 3. Connect to VPN 4. Access services: - **Wazuh Dashboard**: https://10.0.0.2 - **Dozzle**: http://10.0.0.2:8080 - **Beszel**: http://10.0.0.2:9090 - **S3/RustFS Console**: http://10.0.0.2:9001 ## Firewall Rules Summary ### VPS VPN Server | Protocol | Port | Source | Action | |----------|------|--------|--------| | UDP | 51820 | Any | ACCEPT (WireGuard) | | TCP | 22 | Any | ACCEPT (SSH) | | ICMP | echo-request | Any | ACCEPT | | Any | Any | Any | REJECT | NAT masquerade enabled for VPN → Internet routing. ### monitoring-uber (185.103.167.138) | Protocol | Port | Source | Action | |----------|------|--------|--------| | TCP | 1514 | 185.103.166.119 | ACCEPT (Prod Wazuh Agent) | | TCP | 1514 | 185.103.166.112 | ACCEPT (Pre-prod Wazuh Agent) | | UDP | 51820 | Any | ACCEPT (VPN) | | TCP | 443 | 10.0.0.0/24 | ACCEPT (Wazuh Dashboard — VPN) | | TCP | 8080 | 10.0.0.0/24 | ACCEPT (Dozzle — VPN) | | TCP | 9090 | 10.0.0.0/24 | ACCEPT (Beszel — VPN) | | TCP | 9000-9001 | 10.0.0.0/24 | ACCEPT (S3 — VPN) | | TCP | 22 | Any | ACCEPT (SSH) | | Any | Any | Any | DROP (Deny all) | ## Troubleshooting ### VPN connection not establishing ```bash # On monitoring-uber systemctl status wg-quick@wg0 journalctl -u wg-quick@wg0 -n 20 # Restart systemctl restart wg-quick@wg0 ``` ### Can't access services over VPN ```bash # On monitoring-uber, check bindings netstat -tlnp | grep -E "(443|8080|9090|9000)" # Should show 10.0.0.2 (not 0.0.0.0) ``` ### Wazuh agents can't connect Make sure firewall allows 1514/tcp from prod/pre-prod: ```bash # On monitoring-uber iptables -L INPUT -v | grep 1514 ``` Should show rules for prod (185.103.166.119) and pre-prod (185.103.166.112). ## Persistence & Boot All rules are saved with: - `iptables-save` → `/etc/iptables/rules.v4` - WireGuard: `systemctl enable wg-quick@wg0` Both survive reboots. ## Next Steps - [ ] Deploy VPS VPN Server - [ ] Run firewall + WireGuard setup on VPS - [ ] Get Server Public Key - [ ] Deploy firewall + WireGuard client on monitoring-uber - [ ] Add monitoring-uber peer on VPS - [ ] Verify VPN connection (ping 10.0.0.1) - [ ] Rebind services to VPN IP - [ ] Restart docker containers - [ ] Generate admin client configs - [ ] Add admin peers on VPS - [ ] Test admin VPN connection - [ ] Test service access (Wazuh, Dozzle, Beszel, S3)