Files
configpolicy/hosts
Dustin C. Hatch a1ca06a3c5 Move VPN server to dedicated VM
The VPN capability of the UniFi Security Gateway is extremely limited.
It does not support road-warrior IPsec/IKEv2 configuration, and its
OpenVPN configuration is inflexible. As with DHCP, the best solution is
to simply move service to another machine.

To that end, I created a new VM, *vpn0.pyrocufflink.blue*, to host both
strongSwan and OpenVPN. For this to work, the necessary TCP/UDP ports
need to be forwarded, of course, and all of the remote subnets need
static routes on the gateway, specifying this machine as the next hop.
Additionally, ICMP redirects need to be disabled, to prevent confusing
the routing tables of devices on the same subnet as the VPN gateway.
2018-10-07 21:42:18 -05:00

124 lines
1.7 KiB
INI

[all:vars]
ansible_python_interpreter=/usr/bin/python3
[ansible]
cm0.pyrocufflink.blue
[aria2]
file0.pyrocufflink.blue
[burp-client]
file0.pyrocufflink.blue
[burp-server]
burp0.pyrocufflink.blue
[certbot]
git0.pyrocufflink.blue
web0.pyrocufflink.blue
[dch-gw]
gw0 ansible_host=172.31.0.1
[dch-proxy]
rprx0.pyrocufflink.blue
[dch-vpn]
vpn0.pyrocufflink.blue
[dhcpcd:children]
dch-gw
vm-hosts
[dhcpd:children]
pyrocufflink-dhcp
[file-servers]
file0.pyrocufflink.blue
[gitea]
git0.pyrocufflink.blue
[jenkins-slave]
cm0.pyrocufflink.blue
[koji:children]
koji-builder
koji-hub
[koji-builder]
koji0.pyrocufflink.blue
[koji-hub]
koji0.pyrocufflink.blue
[koji-web]
koji0.pyrocufflink.blue
[named-server:children]
pyrocufflink-dns
[ntpd]
dc0.pyrocufflink.blue
[postgresql:children]
zabbix-server
[public-web]
web0.pyrocufflink.blue
[pyrocufflink]
burp0.pyrocufflink.blue
cm0.pyrocufflink.blue
dc0.pyrocufflink.blue
dc1.pyrocufflink.blue
dns0.pyrocufflink.blue
dns1.pyrocufflink.blue
file0.pyrocufflink.blue
git0.pyrocufflink.blue
jenkins0.pyrocufflink.blue
koji0.pyrocufflink.blue
proxy0.pyrocufflink.blue
rprx0.pyrocufflink.blue
smtp1.pyrocufflink.blue
vmhost0.pyrocufflink.blue
vpn0.pyrocufflink.blue
web0.pyrocufflink.blue
zbx0.pyrocufflink.blue
[pyrocufflink-dhcp]
dns1.pyrocufflink.blue
[pyrocufflink-dns]
dns0.pyrocufflink.blue
dns1.pyrocufflink.blue
[radius:children]
samba-dc
[radvd:children]
dch-gw
[samba-dc]
dc0.pyrocufflink.blue
dc1.pyrocufflink.blue
[smtp-relay]
smtp1.pyrocufflink.blue
[smtp-relay:children]
zabbix-server
[squid]
proxy0.pyrocufflink.blue
[zabbix-server]
zbx0.pyrocufflink.blue
[zabbix:children]
dch-gw
pyrocufflink
[vm-hosts]
vmhost0.pyrocufflink.blue