How to expose my behind-the-NAT web-server via Wireguard on public VPS

Viewed 1021

I have a web server with a few TBs of data at the computer behind NAT. I want to expose it to Internet via VPS I have at Azure.

So, I thought WireGuard would be a great tool for that, but I can't figure out the config on how to do that.

Here is wg0.conf on that behind-NAT server:

[Interface]
PrivateKey = OBUNhf6***
Address = 192.168.10.2/24

[Peer]
PublicKey = sUukxiqVNJQpcUVLYu/+fmHH+K9qD7Ol9CipOdlOc3c=
AllowedIPs = 192.168.10.1/24
Endpoint = 13.66.155.255:8101
PersistentKeepalive = 25

Running curl on the same computer, show that web server works fine on port 9000:

$ curl -s http://192.168.10.2:9000/
<html><head>
<title>Welcome to nginx!</title>
...

That 13.66.155.255 endpoint - is IP of the VPS. So, now, I'm configuring my Ubuntu 19.10 VPS on Azure. So wg0.conf:

[Interface]
PrivateKey = sDH1wvnyRKE***
ListenPort = 8101
Address = 192.168.10.1/24
Table = 1234
PostUp = ip rule add ipproto tcp dport 9000 table 1234
PreDown = ip rule delete ipproto tcp dport 9000 table 1234

[Peer]
PublicKey = cnHwqyRLukwYoYw8nl+PH57ZsCKnMmStmXBAZSRNfx0=
AllowedIPs = 192.168.10.0/24

I started WireGuard on both computers. It looks like KeepAlive packets transmitted successfully (I see transfer increasing).

I can open that web-server from within VPS like this:

VPS# curl 192.168.10.2:9000
<html><head>
<title>Welcome to nginx!</title>
...

But I can't open that webserver from outside of VPS:

% curl http://13.66.155.255:9000/        
curl: (7) Failed to connect to 13.66.155.255 port 9000: Connection refused

My Azure firewall (NSG) has ports 8101 and 9000 open.
My Ubuntu firewall disabled.
Kernel PF enabled: net.ipv4.ip_forward=1

What am I missing? Should I have some kind of iptables configuration on top of that?

0 Answers
Related