From f4fc62bf03650c83fa5630f9973db513210126a8 Mon Sep 17 00:00:00 2001 From: root Date: Thu, 16 Dec 2021 16:35:48 +0100 Subject: [PATCH] vpn --- SDIS29/vpn/journald.conf | 44 +++++++++++++++++++ SDIS29/vpn/rsyslog.conf | 92 ++++++++++++++++++++++++++++++++++++++++ SDIS29/vpn/wg0.conf | 21 +++++++++ 3 files changed, 157 insertions(+) create mode 100644 SDIS29/vpn/journald.conf create mode 100644 SDIS29/vpn/rsyslog.conf create mode 100644 SDIS29/vpn/wg0.conf diff --git a/SDIS29/vpn/journald.conf b/SDIS29/vpn/journald.conf new file mode 100644 index 0000000..e23ec85 --- /dev/null +++ b/SDIS29/vpn/journald.conf @@ -0,0 +1,44 @@ +# This file is part of systemd. +# +# systemd is free software; you can redistribute it and/or modify it +# under the terms of the GNU Lesser General Public License as published by +# the Free Software Foundation; either version 2.1 of the License, or +# (at your option) any later version. +# +# Entries in this file show the compile time defaults. +# You can change settings by editing this file. +# Defaults can be restored by simply deleting this file. +# +# See journald.conf(5) for details. + +[Journal] +#Storage=auto +#Compress=yes +#Seal=yes +#SplitMode=uid +#SyncIntervalSec=5m +#RateLimitIntervalSec=30s +#RateLimitBurst=10000 +#SystemMaxUse= +#SystemKeepFree= +#SystemMaxFileSize= +#SystemMaxFiles=100 +#RuntimeMaxUse= +#RuntimeKeepFree= +#RuntimeMaxFileSize= +#RuntimeMaxFiles=100 +#MaxRetentionSec= +#MaxFileSec=1month +ForwardToSyslog=yes +#ForwardToKMsg=no +#ForwardToConsole=no +#ForwardToWall=yes +#TTYPath=/dev/console +#MaxLevelStore=debug +#MaxLevelSyslog=debug +#MaxLevelKMsg=notice +#MaxLevelConsole=info +#MaxLevelWall=emerg +#LineMax=48K +#ReadKMsg=yes +#Audit=no diff --git a/SDIS29/vpn/rsyslog.conf b/SDIS29/vpn/rsyslog.conf new file mode 100644 index 0000000..d3d0755 --- /dev/null +++ b/SDIS29/vpn/rsyslog.conf @@ -0,0 +1,92 @@ +# /etc/rsyslog.conf configuration file for rsyslog +# +# For more information install rsyslog-doc and see +# /usr/share/doc/rsyslog-doc/html/configuration/index.html + + +################# +#### MODULES #### +################# + +module(load="imuxsock") # provides support for local system logging +module(load="imklog") # provides kernel logging support +#module(load="immark") # provides --MARK-- message capability + +# provides UDP syslog reception +module(load="imudp") +input(type="imudp" port="514") + +# provides TCP syslog reception +#module(load="imtcp") +#input(type="imtcp" port="514") + + +########################### +#### GLOBAL DIRECTIVES #### +########################### + +# +# Use traditional timestamp format. +# To enable high precision timestamps, comment out the following line. +# +$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat + +# +# Set the default permissions for all log files. +# +$FileOwner root +$FileGroup adm +$FileCreateMode 0640 +$DirCreateMode 0755 +$Umask 0022 + +# +# Where to place spool and state files +# +$WorkDirectory /var/spool/rsyslog + +# +# Include all config files in /etc/rsyslog.d/ +# +$IncludeConfig /etc/rsyslog.d/*.conf + + +############### +#### RULES #### +############### + +# +# First some standard log files. Log by facility. +# +auth,authpriv.* /var/log/auth.log +*.*;auth,authpriv.none -/var/log/syslog +#cron.* /var/log/cron.log +daemon.* -/var/log/daemon.log +kern.* -/var/log/kern.log +lpr.* -/var/log/lpr.log +mail.* -/var/log/mail.log +user.* -/var/log/user.log + +# +# Logging for the mail system. Split it up so that +# it is easy to write scripts to parse these files. +# +mail.info -/var/log/mail.info +mail.warn -/var/log/mail.warn +mail.err /var/log/mail.err + +# +# Some "catch-all" log files. +# +*.=debug;\ + auth,authpriv.none;\ + mail.none -/var/log/debug +*.=info;*.=notice;*.=warn;\ + auth,authpriv.none;\ + cron,daemon.none;\ + mail.none -/var/log/messages + +# +# Emergencies are sent to everybody logged in. +# +*.emerg :omusrmsg:* diff --git a/SDIS29/vpn/wg0.conf b/SDIS29/vpn/wg0.conf new file mode 100644 index 0000000..024aa0c --- /dev/null +++ b/SDIS29/vpn/wg0.conf @@ -0,0 +1,21 @@ +[Interface] + +# VPN server private IP address +Address = 10.0.2.1/24 +# Clef privee serveur +PrivateKey = EOBiuF/rtF0LoYzTUWiJgfDXIU292jiY/INHJoQbCno= +ListenPort = 51820 + +[Peer] + +# Clef publique client +PublicKey = ABBhn4p6vzj9swWqVXKw1De2OldsTpeEivx2DKfmNR8= +# Adresses IP que le client VPN est autorisé à utiliser +AllowedIPs = 10.0.2.1/24 + +[Peer] + +# Clef publique client +PublicKey = 0iV6dUPJtqUd0jpE7GAKMBrmfOjWp0hxcEi2Ue+ACkw= +# Adresses IP que le client VPN est autorisé à utiliser +AllowedIPs = 10.0.2.1/24