42 lines
1.4 KiB
Bash
Executable file
42 lines
1.4 KiB
Bash
Executable file
#!/usr/bin/bash
|
|
set -euo pipefail
|
|
. data/dest.env
|
|
cat <<EOF >> /etc/sysctl.conf
|
|
net.ipv6.conf.all.forwarding = 1
|
|
net.ipv4.ip_forward = 1
|
|
net.ipv4.conf.all.forwarding = 1
|
|
EOF
|
|
for v in 6 ""; do
|
|
ip${v}tables -P FORWARD DROP
|
|
ip${v}tables -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
|
ip${v}tables -A FORWARD -i awg0 -j ACCEPT
|
|
ip${v}tables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
|
|
done
|
|
for sock in tcp:25 80 443 2235=22 udp:443; do
|
|
if [[ "$sock" == *:* ]]; then
|
|
PORT=${sock#*:}
|
|
PROTO=${sock%:*}
|
|
else
|
|
PORT=$sock
|
|
fi
|
|
if [[ "$PORT" == *=* ]]; then
|
|
DPORT=${PORT#*=}
|
|
PORT=${PORT%=*}
|
|
else
|
|
DPORT=$PORT
|
|
fi
|
|
ip6tables -t nat -A PREROUTING -m addrtype --dst-type LOCAL \
|
|
-p $PROTO --dport $PORT -j DNAT --to-destination [$DEST6]:$DPORT
|
|
ip6tables -A FORWARD -d $DEST6 -p $PROTO --dport $DPORT -j ACCEPT
|
|
iptables -t nat -A PREROUTING -m addrtype --dst-type LOCAL \
|
|
-p $PROTO --dport $PORT -j DNAT --to-destination $DEST4:$DPORT
|
|
iptables -A FORWARD -d $DEST4 -p $PROTO --dport $DPORT -j ACCEPT
|
|
done
|
|
export DEBIAN_FRONTEND=noninteractive
|
|
add-apt-repository -y ppa:amnezia/ppa
|
|
apt-get install -y software-properties-common python3-launchpadlib gnupg2 \
|
|
linux-headers-$(uname -r) amneziawg amneziawg-tools iptables-persistent
|
|
mv data/awg0.conf /etc/amnezia/amneziawg
|
|
systemctl enable awg-quick@awg0
|
|
apt-get autoremove --purge -y
|
|
apt-get clean
|