Files
projet_gestion_commande/monitoring/security/VPN_SETUP.md
T
2026-07-01 21:35:10 +02:00

7.7 KiB

VPN Setup for Monitoring Stack

Architecture

Internet (public)
    ├─ [Prod/Pre-prod] (accessible)
    │   └─→(1514/tcp)→ monitoring-uber (port ouvert)
    │
    ├─ [VPN Server] (nouveau VPS, 1 CPU 2GB RAM)
    │   └─ WireGuard 0.0.0.0:51820/udp
    │
    └─ [monitoring-uber] (185.103.167.138)
         ├─ Client VPN (10.0.0.2)
         └─ Services: Wazuh, Dozzle, Beszel, S3 (VPN only)

VPN Network: 10.0.0.0/24
├─ VPN Server: 10.0.0.1
├─ monitoring-uber: 10.0.0.2
└─ Admins: 10.0.0.3+

Configuration

Mode: VPN + Internet normal (pas de kill switch)

  • Admins connectés au VPN → accès à services VPN (10.0.0.0/24)
  • Admins gardent aussi accès à Internet normal (pas de restriction)
  • Si VPN tombe → retrouvent Internet automatiquement

Implementation Steps

Phase 1: VPN Server Setup (nouveau VPS)

# 1. Login to VPS
ssh root@<VPN_SERVER_IP>

# 2. Run firewall setup
chmod +x /path/to/firewall-vpn-server.sh
./firewall-vpn-server.sh

# 3. Setup WireGuard server
chmod +x /path/to/wireguard-server-setup.sh
./wireguard-server-setup.sh

# Output will show:
# - Server Public Key (note this)
# - Example: aBcDeFgHiJkLmNoPqRsTuVwXyZ1234567890AbCdE=

Save the Server Public Key — you'll need it for clients.

Phase 2: monitoring-uber VPN Client

# 1. Login to monitoring-uber
ssh root@185.103.167.138

# 2. Run firewall setup
chmod +x /path/to/firewall-monitoring-uber.sh
./firewall-monitoring-uber.sh

# 3. Setup WireGuard client
# Syntax: wireguard-client-setup.sh <VPN_SERVER_IP> <VPN_SERVER_PUBKEY>
chmod +x /path/to/wireguard-client-setup.sh
./wireguard-client-setup.sh <VPN_SERVER_IP> "<SERVER_PUBKEY>"

# Example:
# ./wireguard-client-setup.sh 123.45.67.89 "aBcDeFgHiJkLmNoPqRsTuVwXyZ1234567890AbCdE="

# Output will show:
# - Client Public Key (note this)
# - Example: XyZ9876543210AbCdEfGhIjKlMnOpQrStUvWxYz=

Phase 3: Add monitoring-uber to VPN Server

# Back on VPS, add monitoring-uber as a peer
ssh root@<VPN_SERVER_IP>

# Use the Client Public Key from Phase 2
wg set wg0 peer <CLIENT_PUBKEY> allowed-ips 10.0.0.2/32

# Verify
wg show

# Example output:
# interface: wg0
#   public key: aBcDeFgHiJkLmNoPqRsTuVwXyZ1234567890AbCdE=
#   private key: (hidden)
#   listening port: 51820
#
# peer: XyZ9876543210AbCdEfGhIjKlMnOpQrStUvWxYz=
#   endpoint: <monitoring-uber-ip>:xxxxx
#   allowed ips: 10.0.0.2/32
#   latest handshake: X seconds ago
#   transfer: X B received, X B sent

Phase 4: Verify VPN Connection

# On monitoring-uber
ping 10.0.0.1

# Should respond
# PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
# 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=XX.X ms

# Check interface
ip addr show wg0

Phase 5: Rebind Services to VPN IP

# On monitoring-uber
chmod +x /path/to/rebind-services-to-vpn.sh
./rebind-services-to-vpn.sh

# This will update docker-compose-security.yml:
# - Wazuh Dashboard: 0.0.0.0:443 → 10.0.0.2:443
# - Dozzle: 0.0.0.0:8080 → 10.0.0.2:8080
# - Beszel: 0.0.0.0:9090 → 10.0.0.2:9090
# - S3/RustFS: 0.0.0.0:9000/9001 → 10.0.0.2:9000/9001
# - Wazuh Manager: stays on 0.0.0.0:1514 (for agents)

# Restart services
cd /home/ubuntu/docker
docker compose -f docker-compose-security.yml down
docker compose -f docker-compose-security.yml up -d

# Verify
docker ps

Phase 6: Ajouter un admin VPN

La clé privée ne doit jamais quitter la machine de l'admin. La procédure se fait en deux temps.

Étape A — Sur la machine de l'admin (à faire par l'admin)

Installer WireGuard si besoin :

Générer les clés localement :

# Linux / Mac
wg genkey | tee privatekey | wg pubkey > publickey
cat privatekey   # à garder secret
cat publickey    # à envoyer à l'administrateur VPN
# Windows (PowerShell, WireGuard installé)
cd "C:\Program Files\WireGuard"
.\wireguard.exe /genkey | Out-File -Encoding ascii privatekey.txt
Get-Content privatekey.txt | .\wireguard.exe /pubkey | Out-File -Encoding ascii publickey.txt
type publickey.txt   # à envoyer à l'administrateur VPN

Créer le fichier de config admin_nom.conf sur sa machine :

[Interface]
Address = 10.0.0.X/32       # IP assignée par l'administrateur VPN
PrivateKey = <SA_CLE_PRIVEE>
DNS = 8.8.8.8

[Peer]
PublicKey = VQa6g1foaXhJgYWbwyJ9R/EAmmXg0nOnhPhbIIPLlmg=
AllowedIPs = 10.0.0.0/24
Endpoint = 45.150.111.158:51820
PersistentKeepalive = 25

Importer ce fichier dans l'app WireGuard → Tunnel prêt, pas encore actif.

Étape B — Sur le serveur VPN (à faire par l'administrateur)

L'admin envoie sa clé publique et l'administrateur l'ajoute :

ssh root@45.150.111.158

# Assigner une IP libre (voir tableau ci-dessous) et ajouter le peer
wg set wg0 peer <PUBKEY_ADMIN> allowed-ips 10.0.0.X/32

# Persister la config (survie au reboot)
wg-quick save wg0

# Vérifier
wg show

L'admin peut maintenant activer le tunnel dans l'app WireGuard.

IPs assignées

Admin IP VPN Clé publique
admin1 10.0.0.3 (voir admin1.conf)
admin2 10.0.0.10 SL6qEf2K0/3a26wBkvQpOmgILHxxLS1N8M5hJAqfRCc=

Prochaine IP libre : 10.0.0.11

Phase 7: Admin Connection

Each admin:

  1. Download WireGuard app: https://www.wireguard.com/install/
  2. Import config file (admin1.conf, admin2.conf, etc.)
  3. Connect to VPN
  4. Access services:

Firewall Rules Summary

VPS VPN Server

Protocol Port Source Action
UDP 51820 Any ACCEPT (WireGuard)
TCP 22 Any ACCEPT (SSH)
ICMP echo-request Any ACCEPT
Any Any Any REJECT

NAT masquerade enabled for VPN → Internet routing.

monitoring-uber (185.103.167.138)

Protocol Port Source Action
TCP 1514 185.103.166.119 ACCEPT (Prod Wazuh Agent)
TCP 1514 185.103.166.112 ACCEPT (Pre-prod Wazuh Agent)
UDP 51820 Any ACCEPT (VPN)
TCP 443 10.0.0.0/24 ACCEPT (Wazuh Dashboard — VPN)
TCP 8080 10.0.0.0/24 ACCEPT (Dozzle — VPN)
TCP 9090 10.0.0.0/24 ACCEPT (Beszel — VPN)
TCP 9000-9001 10.0.0.0/24 ACCEPT (S3 — VPN)
TCP 22 Any ACCEPT (SSH)
Any Any Any DROP (Deny all)

Troubleshooting

VPN connection not establishing

# On monitoring-uber
systemctl status wg-quick@wg0
journalctl -u wg-quick@wg0 -n 20

# Restart
systemctl restart wg-quick@wg0

Can't access services over VPN

# On monitoring-uber, check bindings
netstat -tlnp | grep -E "(443|8080|9090|9000)"

# Should show 10.0.0.2 (not 0.0.0.0)

Wazuh agents can't connect

Make sure firewall allows 1514/tcp from prod/pre-prod:

# On monitoring-uber
iptables -L INPUT -v | grep 1514

Should show rules for prod (185.103.166.119) and pre-prod (185.103.166.112).

Persistence & Boot

All rules are saved with:

  • iptables-save/etc/iptables/rules.v4
  • WireGuard: systemctl enable wg-quick@wg0

Both survive reboots.

Next Steps

  • Deploy VPS VPN Server
  • Run firewall + WireGuard setup on VPS
  • Get Server Public Key
  • Deploy firewall + WireGuard client on monitoring-uber
  • Add monitoring-uber peer on VPS
  • Verify VPN connection (ping 10.0.0.1)
  • Rebind services to VPN IP
  • Restart docker containers
  • Generate admin client configs
  • Add admin peers on VPS
  • Test admin VPN connection
  • Test service access (Wazuh, Dozzle, Beszel, S3)