Chuyển đến nội dung chính

Lesson 11: VPN - WireGuard and OpenVPN

Guide to configuring VPN on VyOS with WireGuard and OpenVPN, including performance and security comparison, site-to-site and remote access labs, and routing and firewall for VPN.

VPN - WireGuard and OpenVPN

Introduction to VPN on VyOS: WireGuard and OpenVPN

VPN (Virtual Private Network) is a secure connectivity solution for inter-site links and remote access. VyOS supports several modern VPN types such as WireGuard, OpenVPN, and IPsec. This lesson focuses on WireGuard and OpenVPN, two popular solutions with strong performance, security, and flexible deployment models.

WireGuard: Site-to-Site VPN

WireGuard is a modern VPN protocol that is simple and high-performance. To configure site-to-site between two VyOS routers:

# Tạo key pair trên mỗi VyOS
run generate wireguard key
# Lấy public key: run generate wireguard pubkey key <private-key>

Cấu hình WireGuard interface

set interfaces wireguard wg0 address '10.10.10.1/24' set interfaces wireguard wg0 port '51820' set interfaces wireguard wg0 private-key '<private-key>'

Thêm peer

set interfaces wireguard wg0 peer <peer-public-key> allowed-ips '10.10.10.2/32' set interfaces wireguard wg0 peer <peer-public-key> endpoint 'WAN_IP_PEER:51820'

Do the same on the other site, changing IP addresses and keys.

WireGuard: Remote Access VPN

Allows clients (laptop, phone) to access the internal network through WireGuard:

set interfaces wireguard wg0 address '10.10.20.1/24'
set interfaces wireguard wg0 port '51820'
set interfaces wireguard wg0 private-key '<server-private-key>'
set interfaces wireguard wg0 peer <client-public-key> allowed-ips '10.10.20.2/32'

The client is configured accordingly using the server public key.

OpenVPN: Site-to-Site with Pre-Shared Key

set interfaces openvpn vtun0 mode site-to-site
set interfaces openvpn vtun0 local-address '10.20.20.1'
set interfaces openvpn vtun0 remote-address '10.20.20.2'
set interfaces openvpn vtun0 shared-secret-key-file '/config/auth/ovpn.key'
set interfaces openvpn vtun0 local-port '1194'
set interfaces openvpn vtun0 remote-host '<peer-wan-ip>'

OpenVPN: Remote Access with Certificates

set interfaces openvpn vtun1 mode server
set interfaces openvpn vtun1 server subnet '10.30.30.0/24'
set interfaces openvpn vtun1 tls ca-cert-file '/config/auth/ca.crt'
set interfaces openvpn vtun1 tls cert-file '/config/auth/server.crt'
set interfaces openvpn vtun1 tls key-file '/config/auth/server.key'
set interfaces openvpn vtun1 client-cert-required

WireGuard, OpenVPN, and IPsec comparison

  • WireGuard: High performance, simple configuration, small codebase, strong support on VyOS 1.4/1.5.
  • OpenVPN: Flexible with many modes and certificate support, but lower performance than WireGuard.
  • IPsec: Industry standard with deep integration, but typically more complex to configure.

Routing and Firewall for VPN

After setting up the tunnel, route traffic correctly and open firewall policies:

set protocols static route 192.168.2.0/24 next-hop 10.10.10.2
set firewall name VPN-IN default-action accept
set interfaces wireguard wg0 firewall in name VPN-IN

Hands-on lab: WireGuard site-to-site between 2 VyOS routers

  1. On each VyOS router, generate a key pair and exchange public keys.
  2. Configure interface wg0 with private addressing, port, and private key.
  3. Add peers with public keys and endpoint of the opposite site.
  4. Route internal networks through the tunnel.
  5. Validate connectivity: show interfaces wireguard, ping through the tunnel.
# Kiểm tra trạng thái WireGuard
show interfaces wireguard
# Kiểm tra routing
show ip route

Summary

This lesson helps you master VPN configuration on VyOS with WireGuard and OpenVPN, compare trade-offs, and practice site-to-site and remote access with routing and firewall integration. Complete the lab to build practical operational confidence.