Harden WireGuard VPN configuration

- Add IPv6 ip6tables rules to prevent IPv6 traffic leaks (forwarding was
  enabled but only IPv4 masquerade existed)
- Tighten FORWARD chain: only allow wg0→internet and established return,
  instead of blanket ACCEPT from wg0
- Scope NAT masquerade to VPN subnet only
- Block VPN clients from server-local services (SSH/80/443) via INPUT rules
- Set UFW DEFAULT_FORWARD_POLICY=ACCEPT (required for VPN routing; base
  hardening sets default deny which blocks forwarded packets)
- Add SaveConfig = false to prevent runtime state overwriting config
- Add reload ufw handler

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
n0mad1k
2026-03-09 15:59:02 -04:00
parent 3a909867af
commit 20bcecbcec
3 changed files with 48 additions and 9 deletions
+5
View File
@@ -18,3 +18,8 @@
- name: Include WireGuard configuration tasks
include_tasks: tasks/configure.yml
handlers:
- name: reload ufw
ufw:
state: reloaded