# VPN Deployment Summary ## Infrastructure | Role | Hostname | IP Public | IP VPN | Status | |------|----------|-----------|--------|--------| | **VPN Server** | vpn-uber | 45.150.111.158 | 10.0.0.1/24 | ✓ Active | | **Monitoring** | monitoring-uber | 185.103.167.138 | 10.0.0.2/24 | ✓ Connected | | **Admins** | (clients) | — | 10.0.0.3+ | Ready | --- ## Server Credentials ### VPN Server (vpn-uber) - **IP Public:** 45.150.111.158 - **Port:** 51820/udp - **Server Private Key:** (secured at `/etc/wireguard/privatekey`) - **Server Public Key:** `VQa6g1foaXhJgYWbwyJ9R/EAmmXg0nOnhPhbIIPLlmg=` - **Network:** 10.0.0.0/24 - **Interface IP:** 10.0.0.1 **SSH Access:** ```bash ssh root@45.150.111.158 # Password: yqZ98EJL1h3ISlfT6l (from host.ini) ``` ### Monitoring Server (monitoring-uber) - **IP Public:** 185.103.167.138 - **VPN IP:** 10.0.0.2/24 - **Status:** Connected to VPN ✓ - **Firewall:** Configured (iptables) - **Interface:** wg0 UP **SSH Access:** ```bash ssh root@185.103.167.138 # Password: rL9lY6YkcDQmfRuZ3Z (from host.ini) ``` --- ## VPN Configuration ### Firewall Rules **VPN Server (vpn-uber):** ``` INPUT: ✓ 22/tcp (SSH) ✓ 51820/udp (WireGuard) ✗ Everything else → REJECT OUTPUT: ✓ All FORWARD: ✓ wg0 interface (VPN traffic) ✓ NAT masquerade (10.0.0.0/24 → Internet) ``` **Monitoring Server (monitoring-uber):** ``` INPUT: ✓ 1514/tcp FROM 185.103.166.119 (Prod agents) ✓ 1514/tcp FROM 185.103.166.112 (Pre-prod agents) ✓ 51820/udp (VPN) ✓ 443/tcp FROM 10.0.0.0/24 (Wazuh Dashboard) ✓ 8080/tcp FROM 10.0.0.0/24 (Dozzle) ✓ 9090/tcp FROM 10.0.0.0/24 (Beszel) ✓ 9000-9001/tcp FROM 10.0.0.0/24 (S3/RustFS) ✗ Everything else → DROP OUTPUT: ✓ All (Internet) ``` ### WireGuard Routing ``` VPN Server (10.0.0.1) ↓ Monitoring (10.0.0.2) — Connected ✓ ↓ Admin Clients (10.0.0.3+) — Ready to connect ``` **Current Peers:** ``` peer: 4WLn2BR9ZGhM195mIvLbZR7tP/mb7ks4+mZ5ppZ21xw= (monitoring-uber) allowed ips: 10.0.0.2/32 status: Connected ✓ (45ms latency, 0% loss) ``` --- ## Services Accessible via VPN Once connected to VPN from admin client: | Service | URL | Port | Status | |---------|-----|------|--------| | **Wazuh Dashboard** | https://10.0.0.2 | 443 | ✓ (VPN only) | | **Dozzle** | http://10.0.0.2:8080 | 8080 | ✓ (VPN only) | | **Beszel** | http://10.0.0.2:9090 | 9090 | ✓ (VPN only) | | **S3/RustFS Console** | http://10.0.0.2:9001 | 9001 | ✓ (VPN only) | | **S3/RustFS API** | http://10.0.0.2:9000 | 9000 | ✓ (VPN only) | **Mode:** VPN + Internet normal (no kill switch) - Admins can access services via VPN - Admins keep normal Internet access - If VPN drops → automatic fallback to Internet --- ## Next Steps for Admins ### 1. Generate Client Configs ```bash ./wireguard-admin-client.sh admin1 45.150.111.158 "VQa6g1foaXhJgYWbwyJ9R/EAmmXg0nOnhPhbIIPLlmg=" ``` Creates: `admin1.conf` ### 2. Add Client to VPN Server SSH to VPN server: ```bash ssh root@45.150.111.158 ``` Then: ```bash # Get client's public key from admin1.conf (PrivateKey → PublicKey) wg set wg0 peer allowed-ips 10.0.0.3/32 wg show ``` ### 3. Admin Setup - Install WireGuard app (wireguard.com/install) - Import admin1.conf - Connect to VPN - Test access to services --- ## Testing ### From Monitoring Server ```bash # Test VPN connection ping 10.0.0.1 # Response: 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=45.0 ms # Check VPN status ip addr show wg0 ip route show | grep wg0 # VPN traffic tcpdump -i wg0 ``` ### From VPN Server ```bash # Monitor active connections wg show # Check interface ip addr show wg0 # Verify firewall rules iptables -L iptables -L -t nat ``` --- ## Troubleshooting ### Monitoring not connecting to VPN ```bash # Check WireGuard daemon ssh root@185.103.167.138 systemctl status wg-quick@wg0 journalctl -u wg-quick@wg0 -n 20 # Restart systemctl restart wg-quick@wg0 ``` ### VPN Server not accepting peers ```bash # On VPN server, verify WireGuard is running wg show # Check if peer was added correctly wg show wg0 # If not showing, re-add: wg set wg0 peer allowed-ips 10.0.0.X/32 ``` ### Admin client can't connect - Verify VPN server is listening: `netstat -ulnp | grep 51820` - Verify firewall allows 51820/udp: `ufw status` or `iptables -L` - Check client config has correct server IP and pubkey - Try reconnecting after 2-3 seconds --- ## Files & Scripts Used - `firewall-vpn-server.sh` — VPN server firewall (iptables) - `wireguard-server-setup.sh` — WireGuard server install + config - `firewall-monitoring-uber.sh` — Monitoring firewall (iptables) - `wireguard-client-setup.sh` — WireGuard client install - `wireguard-admin-client.sh` — Generate admin client configs - `VPN_SETUP.md` — Full setup guide (phases 1-7) --- ## Persistence All configurations survive reboot: - **Firewall:** `/etc/iptables/rules.v4` (loaded via iptables-restore) - **WireGuard:** Enabled at boot via `systemctl enable wg-quick@wg0` - **Routes:** Persistent in wg0 config --- ## Security Notes - Firewall rules block unauthorized access - WireGuard handshake: 45ms latency (acceptable) - No kill switch enabled (VPN + Internet normal) - Services (Wazuh, Dozzle, Beszel, S3) accessible ONLY via VPN - Agents (prod/pre-prod) still have direct access to Wazuh manager (1514/tcp) --- ## Status ✓ VPN Server deployed on vpn-uber (45.150.111.158) ✓ Monitoring-uber connected to VPN (10.0.0.2) ✓ Firewall configured on both servers ✓ VPN connection tested (45ms, 0% loss) ✓ Ready for admin client setup