Upload toolkit into server:
scp -i /path/to/key/ sisa.tar.gz user@server_ip:/home/user/
SSH into your server:
ssh -i /path/to/key/ user@server_ip
Extract and run:
tar -xvf sisa.tar.gz
cd server-administration
sudo ./main.sh
From menu:
1) System Update and Upgrade
Then reboot the system:
2) Reboot Server
From menu:
3) Software Installation → 1) Basic Software Install
Installs (You can customize the apps to be installed by editing setting.conf ):
Edit:
nano settings.conf
Set:
SERVER_USERS=(
"client1"
)
declare -A USER_SSH_KEYS
USER_SSH_KEYS["client1"]="CLIENT_SSH_KEY"
Edit:
nano settings.conf
Set:
WG_INTERFACE="wg0"
WG_SERVER_ADDRESS="x.x.x.x/24"
WG_LISTEN_PORT="51820"
WG_NETWORK_CIDR="x.x.x.x/24"
Add VPN client (don't forget to add IP and Key for added clients):
WG_CLIENTS=("client1")
declare -A WG_CLIENT_IPS
WG_CLIENT_IPS["client1"]="x.x.x.x/32"
declare -A WG_CLIENT_PUBLIC_KEYS
WG_CLIENT_PUBLIC_KEYS["client1"]="CLIENT_PUBLIC_KEY_HERE"
From menu:
UFW Setup → UFW Setup for VPN Server
Then:
Enable UFW
From menu:
WireGuard VPN Server Setup → WireGuard Setup
This will:
/etc/wireguard/wg0.confSave the server public key
From menu:
WireGuard VPN Server Setup → Add VPN Clients
From menu:
WireGuard VPN Server Setup → Start VPN
Verify:
wg show
[Interface]
PrivateKey = CLIENT_PRIVATE_KEY
Address = 10.46.0.2/32
[Peer]
PublicKey = SERVER_PUBLIC_KEY
Endpoint = SERVER_IP:51820
AllowedIPs = 10.46.0.0/24
PersistentKeepalive = 25
ping x.x.x.1
- VPN server operational
- Base software installed
- Firewall secured
- Internal VPN network working