The objective of this project is to securely configure remote access to a Linux server using WireGuard for encrypted network-layer access and SSH key-based authentication for user access.
Password-based authentication is disabled to enforce a hardened access model.
| Device | Device | VPN IP | Role |
|---|---|---|---|
| Server | data-repository-server-01-dev | 10.44.0.1/24 | WireGuard Endpoint |
| Laptop | Client1 (Michael) | 10.44.0.2/24 | Remote Access Device |
| Laptop | DataAnalyst001Admin (Erin) | 10.44.0.3/24 | Remote Access Device |
| Laptop | SysAdmin001 (Mouhamed) | 10.44.0.4/24 | Remote Access Device |
This layered model ensures both device-level and user-level security controls.
sudo apt update
sudo apt install -y wireguard
Edit /etc/sysctl.conf and uncomment:
net.ipv4.ip_forward=1
Apply changes:
sudo sysctl -p
cd /etc/wireguard/
sudo wg genkey | sudo tee server.key | sudo wg pubkey | sudo tee server.pub
sudo chmod 600 -R /etc/wireguard/
Edit the configuration file:
sudo vi /etc/wireguard/wg0.conf
Add the following:
[Interface]
Address = 10.44.0.1/24
ListenPort = 51820
PrivateKey = <SERVER_PRIVATE_KEY>
[Peer]
PublicKey = <CLIENT_PUBLIC_KEY>
AllowedIPs = 10.44.0.2/32
sudo systemctl enable wg-quick@wg0
sudo systemctl start wg-quick@wg0
sudo adduser bob
sudo passwd -l bob
Create SSH directory:
sudo mkdir -p /home/bob/.ssh
Add Bob’s public key to:
/home/bob/.ssh/authorized_keys
Set proper permissions:
sudo chown -R bob:bob /home/bob/.ssh
sudo chmod 700 /home/bob/.ssh
sudo chmod 600 /home/bob/.ssh/authorized_keys
Installation depends on the operating system in use.
(Depends on the OS in use)
[Interface]
PrivateKey = <CLIENT_PRIVATE_KEY>
Address = 10.44.0.2/24
[Peer]
PublicKey = <SERVER_PUBLIC_KEY>
Endpoint = <SERVER_PUBLIC_IP>:51820
AllowedIPs = 10.44.0.0/24
PersistentKeepalive = 25
ssh-keygen -t ed25519
Send the client public key to the system administrator.
Activate WireGuard on the client side (depending on the OS in use).
If configured correctly:
bob using SSH key-based authenticationThis implementation provides a layered and hardened remote access solution using:
Password-based access is disabled, enforcing a key-only authentication model.
This design follows the principle of least privilege and modern secure access best practices.