I have a web server with a few TBs of data at the computer behind NAT. I want to expose it to Internet via VPS I have at Azure.
So, I thought WireGuard would be a great tool for that, but I can't figure out the config on how to do that.
Here is wg0.conf on that behind-NAT server:
[Interface]
PrivateKey = OBUNhf6***
Address = 192.168.10.2/24
[Peer]
PublicKey = sUukxiqVNJQpcUVLYu/+fmHH+K9qD7Ol9CipOdlOc3c=
AllowedIPs = 192.168.10.1/24
Endpoint = 13.66.155.255:8101
PersistentKeepalive = 25
Running curl on the same computer, show that web server works fine on port 9000:
$ curl -s http://192.168.10.2:9000/
<html><head>
<title>Welcome to nginx!</title>
...
That 13.66.155.255 endpoint - is IP of the VPS.
So, now, I'm configuring my Ubuntu 19.10 VPS on Azure. So wg0.conf:
[Interface]
PrivateKey = sDH1wvnyRKE***
ListenPort = 8101
Address = 192.168.10.1/24
Table = 1234
PostUp = ip rule add ipproto tcp dport 9000 table 1234
PreDown = ip rule delete ipproto tcp dport 9000 table 1234
[Peer]
PublicKey = cnHwqyRLukwYoYw8nl+PH57ZsCKnMmStmXBAZSRNfx0=
AllowedIPs = 192.168.10.0/24
I started WireGuard on both computers. It looks like KeepAlive packets transmitted successfully (I see transfer increasing).
I can open that web-server from within VPS like this:
VPS# curl 192.168.10.2:9000
<html><head>
<title>Welcome to nginx!</title>
...
But I can't open that webserver from outside of VPS:
% curl http://13.66.155.255:9000/
curl: (7) Failed to connect to 13.66.155.255 port 9000: Connection refused
My Azure firewall (NSG) has ports 8101 and 9000 open.
My Ubuntu firewall disabled.
Kernel PF enabled: net.ipv4.ip_forward=1
What am I missing?
Should I have some kind of iptables configuration on top of that?