WAN / Internet : : Vodafone-Kabel : WAN : Router IP 176.199.xxx.xxx:51820 : .-----+-----. | Router | Vodafone Station mit Port Forwarding 51820 TCP/UDP) '-----+-----' | WAN | OPNsense IP 192.168.0.10/24 | .-----+------. | OPNsense | '-----+------' | LAN | 192.168.222.1/24 | .-----+------. | LAN-Switch | '-----+------' | ...-----+------... NAS 192.168.222.10, SmartHome Server 192.168.222.40
VPN -> WireGuard================Local Configuration-------------------Name meinWireGuardServerPublic Key 1 OQEnOxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxPrivate Key 1 yMUiLxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxListen Port 51820Tunnel Address 192.168.112.1/24Peers meinHandyEndpoint--------Name meinHandyPublic Key 2 Nj0jGxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxShared Secret VXSrZxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxAllowed IPs 192.168.112.2/32Interfaces -> Assignments=========================VPN0 wg0----------------------Enable checkedLock checkedDevice wg0Description VPN0Block bogon networks checkedIPv4 Config Type NoneIPv6 Config Type NoneSystem -> Gateways -> Single============================Disabled uncheckedName WireGuard_LANDescription Interface Wireguard GatewayInterface VPN0Address Family IPv4IP address dynamicDisable Gateway Mon checkedPriority 255Firewall -> NAT -> Port Forward===============================Interface WANTCP/IP IPv4Protocol UDPDestination WAN addressDest port range from: other-51820 to: other-51820Redirect target IP Single host - 192.168.112.1Redirect Port 51820Description WireGuard WAN to LANFirewall -> NAT -> Outbound===========================Mode HybridManual rule-----------Interface WANTCP/IP Version IPv4Protocol UDPSource address WireGuard netFirewall -> Rules -> WireGuard==============================Action PassQuick checkedInterface WireGuardDirection inTCP/IP Version IPv4Protocol any| Source WireGuard netServices -> Unbound DNS -> General==================================Network interface All
[Interface]PrivateKey = uJSOdxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxAddress = 192.168.112.2/32DNS = 192.168.112.1[Peer]PublicKey = OQEnOxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxPresharedKey = VXSrZxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxAllowedIPs = 0.0.0.0/0Endpoint = 176.199.xxx.xxx:51820