<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Wireguard on Sysadmin Tales</title>
    <link>https://blog.ssb-tech.net/tags/wireguard/</link>
    <description>Recent content in Wireguard on Sysadmin Tales</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:39:10 -0400</lastBuildDate>
    <atom:link href="https://blog.ssb-tech.net/tags/wireguard/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Wireguard configuration concepts</title>
      <link>https://blog.ssb-tech.net/posts/on-wireguard/</link>
      <pubDate>Sun, 26 Oct 2025 15:04:55 -0400</pubDate>
      <guid>https://blog.ssb-tech.net/posts/on-wireguard/</guid>
      <description>&lt;h1 id=&#34;wireguard-concepts&#34;&gt;Wireguard concepts&lt;/h1&gt;&#xA;&lt;h2 id=&#34;the-point-of-this-post&#34;&gt;The point of this post&lt;/h2&gt;&#xA;&lt;p&gt;This is intended as a high level starting point for someone who is new to using Wireguard.&lt;/p&gt;&#xA;&lt;p&gt;If you spot any errors or inaccuracies, feel free to open a pull request in the &lt;a href=&#34;https://github.com/bladewdr/ssb-tech-blog&#34;&gt;Github repo&lt;/a&gt;, or leave a comment.&lt;/p&gt;&#xA;&lt;h2 id=&#34;overview&#34;&gt;Overview&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.wireguard.com/&#34;&gt;Wireguard&lt;/a&gt; is a modern VPN protocol.&lt;/p&gt;&#xA;&lt;p&gt;Instead of using a traditional client server model, Wireguard uses a peer-to-peer mechanism. Authentication is handled with private and public key pairs, and optionally a pre-shared key.&lt;/p&gt;&#xA;&lt;h2 id=&#34;wireguard-configuration-on-linux&#34;&gt;Wireguard configuration on Linux&lt;/h2&gt;&#xA;&lt;p&gt;There are many ways to configure Wireguard on Linux, but the one that I typically use is by setting up a file in &lt;code&gt;/etc/wireguard&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;On Linux, this is the default location that the &lt;code&gt;wg-quick&lt;/code&gt; userspace utility looks for Wireguard interface configurations.&lt;/p&gt;&#xA;&lt;p&gt;The interface configuration can contain both the definition for the interface as well as any peers.&lt;/p&gt;&#xA;&lt;h3 id=&#34;anatomy-of-the-wireguard-configuration-file&#34;&gt;Anatomy of the Wireguard configuration file&lt;/h3&gt;&#xA;&lt;p&gt;Consider the following configuration file: &lt;code&gt;/etc/wireguard/demo.conf&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;When using &lt;code&gt;wg-quick&lt;/code&gt;, the interface name will be generated from the name of the configuration file. In this case, the interface name would be &lt;code&gt;demo&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Sample configuration file:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;[Interface]&#xA;&#xA;Address = 192.168.99.5/24&#xA;PrivateKey = 2COm4EMxP5tcF9cpgCxBAsSGRwrjoMmWjkr+emGtylY=&#xA;ListenPort = 51820&#xA;&#xA;[Peer]&#xA;&#xA;PublicKey = Tlm3payEVQWCj7GK7Y7usejF4mix5FBULZryxfu9kxY=&#xA;PreSharedKey = chooseabetterkey&#xA;AllowedIPs = 192.168.99.8/32,10.10.33.0/24&#xA;Endpoint = demo.wireguard.com:51820&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Lets break down this config file into its components.&lt;/p&gt;&#xA;&lt;p&gt;Wireguard uses an INI-like syntax.&lt;/p&gt;&#xA;&lt;p&gt;There are 2 top level blocks that can be configured, &lt;code&gt;[Interface]&lt;/code&gt; and &lt;code&gt;[Peer]&lt;/code&gt;. There can be multiple &lt;code&gt;[Peer]&lt;/code&gt; definitions, but only one &lt;code&gt;[Interface]&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;h4 id=&#34;the-interface-block&#34;&gt;The Interface Block&lt;/h4&gt;&#xA;&lt;dl&gt;&#xA;&lt;dt&gt;&lt;strong&gt;Address&lt;/strong&gt;&lt;/dt&gt;&#xA;&lt;dd&gt;What address do you want this particular peer to have? Make sure you set the correct CIDR notation for your subnet size. This one is &lt;code&gt;/24&lt;/code&gt; for a 254 address subnet.&lt;/dd&gt;&#xA;&lt;dt&gt;&lt;strong&gt;PrivateKey&lt;/strong&gt;&lt;/dt&gt;&#xA;&lt;dd&gt;The private key is a secret! I&amp;rsquo;ve generated this one just for this demo, it will be discarded after.&lt;/dd&gt;&#xA;&lt;dd&gt;&#xA;&lt;p&gt;But make sure you secure these properly!&lt;/p&gt;&#xA;&lt;/dd&gt;&#xA;&lt;dt&gt;&lt;strong&gt;ListenPort&lt;/strong&gt;&lt;/dt&gt;&#xA;&lt;dd&gt;The default listen port is 51820, but you can set it to anything you want. This is the network port that Wireguard will use to listen on this interface.&lt;/dd&gt;&#xA;&lt;/dl&gt;&#xA;&lt;h4 id=&#34;the-peer-block&#34;&gt;The Peer Block&lt;/h4&gt;&#xA;&lt;dl&gt;&#xA;&lt;dt&gt;&lt;strong&gt;PublicKey&lt;/strong&gt;&lt;/dt&gt;&#xA;&lt;dd&gt;This is the public key associated with the &lt;em&gt;peer&amp;rsquo;s&lt;/em&gt; private key, &lt;em&gt;not&lt;/em&gt; the private key of this interface.&lt;/dd&gt;&#xA;&lt;dt&gt;&lt;strong&gt;PreSharedKey&lt;/strong&gt;&lt;/dt&gt;&#xA;&lt;dd&gt;Preshared keys are optional but good for additional security. This is a key that needs to match on both sides of the connection.&lt;/dd&gt;&#xA;&lt;dt&gt;&lt;strong&gt;AllowedIPs&lt;/strong&gt;&lt;/dt&gt;&#xA;&lt;dd&gt;The AllowedIPs stanza is an interesting one. It is what Wireguard uses to make internal routing decisions, but those packets need to arrive at the Wireguard interface first.&lt;/dd&gt;&#xA;&lt;dd&gt;&#xA;&lt;p&gt;This is the reason I like to use wg-quick to set up my interfaces - if you don&amp;rsquo;t, you&amp;rsquo;ll need to add the routes yourself. This is personal preference.&lt;/p&gt;&#xA;&lt;/dd&gt;&#xA;&lt;dd&gt;&#xA;&lt;p&gt;The configuration above would allow this peer to have the 192.168.99.8 IP on the Wireguard internal subnet, and any traffic destined for 10.10.33.0/24 would also get passed along.&lt;/p&gt;&#xA;&lt;/dd&gt;&#xA;&lt;dd&gt;&#xA;&lt;p&gt;Note how I&amp;rsquo;m using &lt;code&gt;/32&lt;/code&gt; for the Wireguard internal subnet here. This is because I only want that &lt;em&gt;one&lt;/em&gt; IP to be valid for this peer. The subnet is still a &lt;code&gt;/24&lt;/code&gt; as configured on the interface itself.&lt;/p&gt;&#xA;&lt;/dd&gt;&#xA;&lt;dt&gt;&lt;strong&gt;Endpoint&lt;/strong&gt;&lt;/dt&gt;&#xA;&lt;dd&gt;Endpoint is technically an optional field.&lt;/dd&gt;&#xA;&lt;dd&gt;&#xA;&lt;p&gt;But it does need to be set on at least one side of each connection.&lt;/p&gt;&#xA;&lt;/dd&gt;&#xA;&lt;dd&gt;&#xA;&lt;p&gt;At least one of the peers needs to have a public IP address that&amp;rsquo;s reachable on the internet. (And the &lt;code&gt;ListenPort&lt;/code&gt; needs to be open.)&lt;/p&gt;&#xA;&lt;/dd&gt;&#xA;&lt;/dl&gt;&#xA;&lt;p&gt;There are other stanzas that can be used in the configuration file, but these are the basic ones.&lt;/p&gt;&#xA;&lt;p&gt;You can see the &lt;a href=&#34;https://www.man7.org/linux/man-pages/man8/wg.8.html&#34;&gt;wg&lt;/a&gt; and &lt;a href=&#34;https://www.man7.org/linux/man-pages/man8/wg-quick.8.html&#34;&gt;wg-quick&lt;/a&gt; man pages for more information on configuration file syntax.&lt;/p&gt;&#xA;&lt;h3 id=&#34;using-wg-quick-with-systemd&#34;&gt;Using wg-quick with systemd&lt;/h3&gt;&#xA;&lt;p&gt;When installing Wireguard on Linux, it comes with a template &lt;a href=&#34;https://en.wikipedia.org/wiki/Systemd&#34;&gt;systemd&lt;/a&gt; unit file for &lt;code&gt;wg-quick&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This is a wrapper that allows you to quickly set Wireguard configurations that load at startup.&lt;/p&gt;&#xA;&lt;p&gt;To start up our config file from earlier using wg-quick, you can do it like so:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo systemctl start wg-quick@demo&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Where the text after the &lt;code&gt;@&lt;/code&gt; symbol will always been the config file name without its &lt;code&gt;.conf&lt;/code&gt; extension. For more info on this, see the &lt;a href=&#34;https://wiki.archlinux.org/title/Systemd#Using_units&#34;&gt;Arch Wiki page on systemd&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;If you want to make the configuration start at boot, you can enable the systemd unit.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo systemctl enable wg-quick@demo&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class=&#34;callout callout-note&#34; role=&#34;note&#34;&gt;&lt;div class=&#34;callout-title&#34;&gt;Note&lt;/div&gt;&lt;div class=&#34;callout-content&#34;&gt;Yes, you can have multiple Wireguard interfaces on one machine. Just make sure that they listen on different ports.&lt;/div&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;general-usage-notes&#34;&gt;General usage notes&lt;/h2&gt;&#xA;&lt;p&gt;While Wireguard as a protocol is peer-to-peer, many people do still use it in a client-server architecture.&lt;/p&gt;&#xA;&lt;p&gt;One use case for this is if you&amp;rsquo;re using Wireguard to set up your own privacy VPN endpoint.&lt;/p&gt;&#xA;&lt;div class=&#34;callout callout-note&#34; role=&#34;note&#34;&gt;&lt;div class=&#34;callout-title&#34;&gt;Note&lt;/div&gt;&lt;div class=&#34;callout-content&#34;&gt;If you do use Wireguard as a VPN server, remember that you also need to enable &lt;a href=&#34;https://askubuntu.com/questions/311053/how-to-make-ip-forwarding-permanent&#34;&gt;IP forwarding&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&#xA;</description>
    </item>
    <item>
      <title>Setting up OpnSense as an AirVPN client</title>
      <link>https://blog.ssb-tech.net/posts/airvpn-on-opnsense/</link>
      <pubDate>Tue, 03 Dec 2024 22:41:53 -0500</pubDate>
      <guid>https://blog.ssb-tech.net/posts/airvpn-on-opnsense/</guid>
      <description>&lt;p&gt;I recently set up my OpnSense firewall at home with a connection to AirVPN using Wireguard.&lt;/p&gt;&#xA;&lt;p&gt;It was a bit more complicated than when I did it for Mullvad last year, so I figured I&amp;rsquo;d document it here for anyone who finds this useful.&lt;/p&gt;&#xA;&lt;h2 id=&#34;1-device-creation&#34;&gt;1. Device Creation&lt;/h2&gt;&#xA;&lt;p&gt;Log into your AirVPN account and navigate to the client area. Click on&#xA;Manage Devices. You can either edit the existing &amp;ldquo;default&amp;rdquo; device or&#xA;create a new one. Either way, I recommend editing the name of the device&#xA;so that you know what it is, 6 months down the line. I called mine&#xA;&amp;ldquo;Opnsense&amp;rdquo;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;While you&amp;rsquo;re here, I recommend opening up a Notepad or equivalent and&#xA;copying and pasting the public key that&amp;rsquo;s on this page. We&amp;rsquo;ll need it later.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;AirVPN devices page&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/airvpn-on-opnsense/images/airvpn-devices.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;2-generate-wireguard-configuration-file&#34;&gt;2. Generate Wireguard configuration file&lt;/h2&gt;&#xA;&lt;p&gt;Next, head back to the client area and head into the Config Generator.&lt;/p&gt;&#xA;&lt;p&gt;For OS, you&amp;rsquo;ll want to choose &amp;ldquo;Router&amp;rdquo;. You&amp;rsquo;ll also want to decide which&#xA;device (if you have more than one) that this configuration will apply to.&lt;/p&gt;&#xA;&lt;p&gt;Pick the &amp;ldquo;Wireguard&amp;rdquo; protocol.&lt;/p&gt;&#xA;&lt;p&gt;Pick a server as well - I picked Switzerland.&lt;/p&gt;&#xA;&lt;p&gt;Once you&amp;rsquo;re done, click the Generate button at the bottom of the page.&#xA;This will download a Wireguard configuration file - save this, we&amp;rsquo;ll need&#xA;it in a moment.&lt;/p&gt;&#xA;&lt;h2 id=&#34;3-create-wireguard-tunnel-in-opnsense&#34;&gt;3. Create Wireguard tunnel in Opnsense.&lt;/h2&gt;&#xA;&lt;p&gt;Next, we&amp;rsquo;ll be heading into Opnsense. Log in and navigate to the VPN&#xA;section. Under Wireguard, create a peer.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Name: AirVPN &#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Public Key: you can get this from the wireguard configuration file you downloaded in step 2.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Pre-Shared Key: you can get this from the wireguard configuration file you&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;downloaded in Step 2. &#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Allowed IPs: 0.0.0.0/0 &#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Endpoint Address: Get this from the config file as well.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Endpoint port: Get this from the config file as well. It&amp;#39;s usually 1637.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keepalive Interval: You can either set this to 15 or leave it blank.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Save, and next we&amp;rsquo;ll head over to Instances. Configure a new instance with the following options:&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Make sure you enable advanced features.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Name: AirVPNLocal&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Public Key: Here you&amp;#39;ll want to put the public key we got in step 1. This is the public key of OPNSENSE.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Private Key: Grab this from the config file. It will be under the Interface section.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Tunnel address: Set this to the /32 address that was in the config file. It will be something in the 10.128.0.0/10 range.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Peer: Select the AirVPN peer we created earlier.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;MTU: 1320&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Disable Routes: Checked &#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Make sure you have Disable Routes checked, it&amp;rsquo;s important.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;Hit Save. Don&amp;rsquo;t forget to check the box to enable Wireguard, and hit apply at the bottom of the page.&lt;/p&gt;&#xA;&lt;p&gt;Once done, head over to the &amp;ldquo;Status&amp;rdquo; page - the tunnel should show a status of &amp;ldquo;Up&amp;rdquo; now, but we&amp;rsquo;ve still got some work to do before we can use it.&lt;/p&gt;&#xA;&lt;h2 id=&#34;4-create-an-interface&#34;&gt;4. Create an interface.&lt;/h2&gt;&#xA;&lt;p&gt;Head over to Interfaces &amp;gt; Assignments.&lt;/p&gt;&#xA;&lt;p&gt;Under &amp;ldquo;Assign a new interface&amp;rdquo;, pick the Wireguard device we just created. If it&amp;rsquo;s your first one, it&amp;rsquo;ll be &lt;code&gt;wg0&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Click on the interface, Enable it. I also recommend giving it a descriptive name. Mine is called &amp;ldquo;airvpn_wg&amp;rdquo;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;5-create-a-gateway&#34;&gt;5. Create a gateway.&lt;/h2&gt;&#xA;&lt;p&gt;Next we have to create a gateway for AirVPN clients to use.&lt;/p&gt;&#xA;&lt;p&gt;Head over to System &amp;gt; Gateways &amp;gt; Configuration.&lt;/p&gt;&#xA;&lt;p&gt;Create a new gateway and give it a descriptive name. I called mine AIRVPN_GW.&lt;/p&gt;&#xA;&lt;p&gt;Here are the other settings you&amp;rsquo;ll need to configure on this gateway.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Interface: airvpn_wg&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Address family: IPv4&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;IP Address: 10.128.0.1&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Far Gateway: checked&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Disable Gateway Monitoring: checked.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Click Save, and then Apply.&lt;/p&gt;&#xA;&lt;h2 id=&#34;6-create-outbound-nat-rule&#34;&gt;6. Create Outbound NAT rule.&lt;/h2&gt;&#xA;&lt;p&gt;Most Wireguard VPN providers will require you to configure outbound NAT, and AirVPN is no exception.&lt;/p&gt;&#xA;&lt;p&gt;Go to Firewall &amp;gt; NAT &amp;gt; Outbound and add a rule.&lt;/p&gt;&#xA;&lt;p&gt;Configure only the following settings and leave everything else default.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Interface: airvpn_wg&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Source Address: LAN net (or whatever you&amp;#39;re using.)&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Description: Outbound NAT for AirVPN&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;7-configure-policy-routing&#34;&gt;7. Configure Policy Routing&lt;/h2&gt;&#xA;&lt;p&gt;How we&amp;rsquo;re going to accomplish this is we&amp;rsquo;re going to create an alias for the devices we want to route out over the VPN tunnel.&lt;/p&gt;&#xA;&lt;p&gt;Call it VPN_Required or whatever you like.&lt;/p&gt;&#xA;&lt;p&gt;Once you&amp;rsquo;ve created the alias, navigate to Firewall &amp;gt; Rules &amp;gt; Your network.&lt;/p&gt;&#xA;&lt;p&gt;Create a pass rule with the following settings defined:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Interface: LAN&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Protocol: Any&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Source: VPN_Required&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Destination: Any&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Gateway: AIRVPN_GW&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Advanced features:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  Set local tag: vpntraffic&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Next head to Rules &amp;gt; Floating and define a Block rule.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Interface: Your WAN interface&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Source: Any&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Protocol: Any&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Destination: Any&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Advanced features:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  Match local tag: vpntraffic&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This block rule will serve as a &amp;ldquo;kill switch&amp;rdquo; preventing our VPN traffic from leaking if the tunnel goes down for some reason.&lt;/p&gt;&#xA;&lt;h2 id=&#34;8-test-it&#34;&gt;8. Test It&lt;/h2&gt;&#xA;&lt;p&gt;I recommend testing the connection at this point. Add your current device&amp;rsquo;s IP address to the alias you&amp;rsquo;re using for policy routing for testing purposes.&lt;/p&gt;&#xA;&lt;p&gt;Go to sites like &lt;a href=&#34;https://ipleak.net/&#34;&gt;https://ipleak.net/&lt;/a&gt; and make sure that everything is reported correctly. Make sure you don&amp;rsquo;t have any DNS leaks, either - it should show DNS servers in the same region as the AirVPN server that you chose.&lt;/p&gt;&#xA;&lt;h2 id=&#34;9-bonus-points---port-forwarding&#34;&gt;9. Bonus Points - Port Forwarding&lt;/h2&gt;&#xA;&lt;p&gt;If you have a need for port forwarding, AirVPN supports up to 5 ports per account.&lt;/p&gt;&#xA;&lt;p&gt;Head on back to the Client Area on their website and click on Ports.&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;If you&amp;rsquo;re forwarding ports for a protocol like Bittorrent, you&amp;rsquo;ll need to use the &lt;code&gt;:1&lt;/code&gt; pool of addresses.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;I suggest using AirVPN&amp;rsquo;s tool on the same page to find a free port in that range.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;AirVPN port search tool&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/airvpn-on-opnsense/images/airvpn-port-checker.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Once you&amp;rsquo;ve determined which port to use, configure it for yourself. Configure which device it&amp;rsquo;s for, set the protocol to TCP+UDP.&lt;/p&gt;&#xA;&lt;p&gt;I recommend using ipv4 only.&lt;/p&gt;&#xA;&lt;p&gt;On Opnsense, configure a rule on the airvpn_wg interface. (Firewall &amp;gt; Rules &amp;gt; airvpn_wg)&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Action: Pass&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Protocol: TCP/UDP&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Destination: The IP address of your box of Linux ISOs.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Port: the port you defined in AirVPN.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Reply-To: AIRVPN_GW&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;You&amp;rsquo;ll also want to configure a port forward under NAT &amp;gt; Port Forward.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Interface: airvpn_wg&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Protocol: TCP/UDP&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Destination: airvpn_wg address&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Destination port range: the port you defined in AirVPN.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Redirect target IP: The IP address of your box of Linux ISOs.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Redirect target port: the port you defined in AirVPN.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Now, in your Bittorrent client, make sure you turn off port randomization, and set the port to the same one.&lt;/p&gt;&#xA;&lt;p&gt;You may also have to allow that port through the system firewall, if there is one.&lt;/p&gt;&#xA;&lt;p&gt;If you&amp;rsquo;re running something like Transmission in Docker, don&amp;rsquo;t forget to publish the port in your docker compose.&lt;/p&gt;&#xA;</description>
    </item>
  </channel>
</rss>
