chore: update
This commit is contained in:
@@ -0,0 +1,258 @@
|
||||
# VPN Deployment Summary
|
||||
|
||||
## Infrastructure
|
||||
|
||||
| Role | Hostname | IP Public | IP VPN | Status |
|
||||
|------|----------|-----------|--------|--------|
|
||||
| **VPN Server** | vpn-uber | 45.150.111.158 | 10.0.0.1/24 | ✓ Active |
|
||||
| **Monitoring** | monitoring-uber | 185.103.167.138 | 10.0.0.2/24 | ✓ Connected |
|
||||
| **Admins** | (clients) | — | 10.0.0.3+ | Ready |
|
||||
|
||||
---
|
||||
|
||||
## Server Credentials
|
||||
|
||||
### VPN Server (vpn-uber)
|
||||
|
||||
- **IP Public:** 45.150.111.158
|
||||
- **Port:** 51820/udp
|
||||
- **Server Private Key:** (secured at `/etc/wireguard/privatekey`)
|
||||
- **Server Public Key:** `VQa6g1foaXhJgYWbwyJ9R/EAmmXg0nOnhPhbIIPLlmg=`
|
||||
- **Network:** 10.0.0.0/24
|
||||
- **Interface IP:** 10.0.0.1
|
||||
|
||||
**SSH Access:**
|
||||
```bash
|
||||
ssh root@45.150.111.158
|
||||
# Password: yqZ98EJL1h3ISlfT6l (from host.ini)
|
||||
```
|
||||
|
||||
### Monitoring Server (monitoring-uber)
|
||||
|
||||
- **IP Public:** 185.103.167.138
|
||||
- **VPN IP:** 10.0.0.2/24
|
||||
- **Status:** Connected to VPN ✓
|
||||
- **Firewall:** Configured (iptables)
|
||||
- **Interface:** wg0 UP
|
||||
|
||||
**SSH Access:**
|
||||
```bash
|
||||
ssh root@185.103.167.138
|
||||
# Password: rL9lY6YkcDQmfRuZ3Z (from host.ini)
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## VPN Configuration
|
||||
|
||||
### Firewall Rules
|
||||
|
||||
**VPN Server (vpn-uber):**
|
||||
```
|
||||
INPUT:
|
||||
✓ 22/tcp (SSH)
|
||||
✓ 51820/udp (WireGuard)
|
||||
✗ Everything else → REJECT
|
||||
|
||||
OUTPUT:
|
||||
✓ All
|
||||
|
||||
FORWARD:
|
||||
✓ wg0 interface (VPN traffic)
|
||||
✓ NAT masquerade (10.0.0.0/24 → Internet)
|
||||
```
|
||||
|
||||
**Monitoring Server (monitoring-uber):**
|
||||
```
|
||||
INPUT:
|
||||
✓ 1514/tcp FROM 185.103.166.119 (Prod agents)
|
||||
✓ 1514/tcp FROM 185.103.166.112 (Pre-prod agents)
|
||||
✓ 51820/udp (VPN)
|
||||
✓ 443/tcp FROM 10.0.0.0/24 (Wazuh Dashboard)
|
||||
✓ 8080/tcp FROM 10.0.0.0/24 (Dozzle)
|
||||
✓ 9090/tcp FROM 10.0.0.0/24 (Beszel)
|
||||
✓ 9000-9001/tcp FROM 10.0.0.0/24 (S3/RustFS)
|
||||
✗ Everything else → DROP
|
||||
|
||||
OUTPUT:
|
||||
✓ All (Internet)
|
||||
```
|
||||
|
||||
### WireGuard Routing
|
||||
|
||||
```
|
||||
VPN Server (10.0.0.1)
|
||||
↓
|
||||
Monitoring (10.0.0.2) — Connected ✓
|
||||
↓
|
||||
Admin Clients (10.0.0.3+) — Ready to connect
|
||||
```
|
||||
|
||||
**Current Peers:**
|
||||
```
|
||||
peer: 4WLn2BR9ZGhM195mIvLbZR7tP/mb7ks4+mZ5ppZ21xw= (monitoring-uber)
|
||||
allowed ips: 10.0.0.2/32
|
||||
status: Connected ✓ (45ms latency, 0% loss)
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Services Accessible via VPN
|
||||
|
||||
Once connected to VPN from admin client:
|
||||
|
||||
| Service | URL | Port | Status |
|
||||
|---------|-----|------|--------|
|
||||
| **Wazuh Dashboard** | https://10.0.0.2 | 443 | ✓ (VPN only) |
|
||||
| **Dozzle** | http://10.0.0.2:8080 | 8080 | ✓ (VPN only) |
|
||||
| **Beszel** | http://10.0.0.2:9090 | 9090 | ✓ (VPN only) |
|
||||
| **S3/RustFS Console** | http://10.0.0.2:9001 | 9001 | ✓ (VPN only) |
|
||||
| **S3/RustFS API** | http://10.0.0.2:9000 | 9000 | ✓ (VPN only) |
|
||||
|
||||
**Mode:** VPN + Internet normal (no kill switch)
|
||||
- Admins can access services via VPN
|
||||
- Admins keep normal Internet access
|
||||
- If VPN drops → automatic fallback to Internet
|
||||
|
||||
---
|
||||
|
||||
## Next Steps for Admins
|
||||
|
||||
### 1. Generate Client Configs
|
||||
|
||||
```bash
|
||||
./wireguard-admin-client.sh admin1 45.150.111.158 "VQa6g1foaXhJgYWbwyJ9R/EAmmXg0nOnhPhbIIPLlmg="
|
||||
```
|
||||
|
||||
Creates: `admin1.conf`
|
||||
|
||||
### 2. Add Client to VPN Server
|
||||
|
||||
SSH to VPN server:
|
||||
```bash
|
||||
ssh root@45.150.111.158
|
||||
```
|
||||
|
||||
Then:
|
||||
```bash
|
||||
# Get client's public key from admin1.conf (PrivateKey → PublicKey)
|
||||
wg set wg0 peer <CLIENT_PUBKEY> allowed-ips 10.0.0.3/32
|
||||
wg show
|
||||
```
|
||||
|
||||
### 3. Admin Setup
|
||||
|
||||
- Install WireGuard app (wireguard.com/install)
|
||||
- Import admin1.conf
|
||||
- Connect to VPN
|
||||
- Test access to services
|
||||
|
||||
---
|
||||
|
||||
## Testing
|
||||
|
||||
### From Monitoring Server
|
||||
|
||||
```bash
|
||||
# Test VPN connection
|
||||
ping 10.0.0.1
|
||||
# Response: 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=45.0 ms
|
||||
|
||||
# Check VPN status
|
||||
ip addr show wg0
|
||||
ip route show | grep wg0
|
||||
|
||||
# VPN traffic
|
||||
tcpdump -i wg0
|
||||
```
|
||||
|
||||
### From VPN Server
|
||||
|
||||
```bash
|
||||
# Monitor active connections
|
||||
wg show
|
||||
|
||||
# Check interface
|
||||
ip addr show wg0
|
||||
|
||||
# Verify firewall rules
|
||||
iptables -L
|
||||
iptables -L -t nat
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### Monitoring not connecting to VPN
|
||||
|
||||
```bash
|
||||
# Check WireGuard daemon
|
||||
ssh root@185.103.167.138
|
||||
systemctl status wg-quick@wg0
|
||||
journalctl -u wg-quick@wg0 -n 20
|
||||
|
||||
# Restart
|
||||
systemctl restart wg-quick@wg0
|
||||
```
|
||||
|
||||
### VPN Server not accepting peers
|
||||
|
||||
```bash
|
||||
# On VPN server, verify WireGuard is running
|
||||
wg show
|
||||
|
||||
# Check if peer was added correctly
|
||||
wg show wg0
|
||||
|
||||
# If not showing, re-add:
|
||||
wg set wg0 peer <CLIENT_PUBKEY> allowed-ips 10.0.0.X/32
|
||||
```
|
||||
|
||||
### Admin client can't connect
|
||||
|
||||
- Verify VPN server is listening: `netstat -ulnp | grep 51820`
|
||||
- Verify firewall allows 51820/udp: `ufw status` or `iptables -L`
|
||||
- Check client config has correct server IP and pubkey
|
||||
- Try reconnecting after 2-3 seconds
|
||||
|
||||
---
|
||||
|
||||
## Files & Scripts Used
|
||||
|
||||
- `firewall-vpn-server.sh` — VPN server firewall (iptables)
|
||||
- `wireguard-server-setup.sh` — WireGuard server install + config
|
||||
- `firewall-monitoring-uber.sh` — Monitoring firewall (iptables)
|
||||
- `wireguard-client-setup.sh` — WireGuard client install
|
||||
- `wireguard-admin-client.sh` — Generate admin client configs
|
||||
- `VPN_SETUP.md` — Full setup guide (phases 1-7)
|
||||
|
||||
---
|
||||
|
||||
## Persistence
|
||||
|
||||
All configurations survive reboot:
|
||||
|
||||
- **Firewall:** `/etc/iptables/rules.v4` (loaded via iptables-restore)
|
||||
- **WireGuard:** Enabled at boot via `systemctl enable wg-quick@wg0`
|
||||
- **Routes:** Persistent in wg0 config
|
||||
|
||||
---
|
||||
|
||||
## Security Notes
|
||||
|
||||
- Firewall rules block unauthorized access
|
||||
- WireGuard handshake: 45ms latency (acceptable)
|
||||
- No kill switch enabled (VPN + Internet normal)
|
||||
- Services (Wazuh, Dozzle, Beszel, S3) accessible ONLY via VPN
|
||||
- Agents (prod/pre-prod) still have direct access to Wazuh manager (1514/tcp)
|
||||
|
||||
---
|
||||
|
||||
## Status
|
||||
|
||||
✓ VPN Server deployed on vpn-uber (45.150.111.158)
|
||||
✓ Monitoring-uber connected to VPN (10.0.0.2)
|
||||
✓ Firewall configured on both servers
|
||||
✓ VPN connection tested (45ms, 0% loss)
|
||||
✓ Ready for admin client setup
|
||||
Reference in New Issue
Block a user