{"id":41,"date":"2026-05-12T01:58:35","date_gmt":"2026-05-11T17:58:35","guid":{"rendered":"https:\/\/blog.kwitsukasa.top\/?p=41"},"modified":"2026-05-12T01:58:35","modified_gmt":"2026-05-11T17:58:35","slug":"vps-%e5%ae%b6%e5%ae%bdnas-wireguard-%e5%85%ac%e7%bd%91ipv4%e6%96%b9%e6%a1%88","status":"publish","type":"post","link":"https:\/\/blog.kwitsukasa.top\/?p=41","title":{"rendered":"VPS + \u5bb6\u5bbdNAS + WireGuard \u516c\u7f51IPV4\u65b9\u6848"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">1. \u67b6\u6784\u8bf4\u660e<\/h2>\n\n\n\n<p>\u76ee\u6807\u94fe\u8def\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u817e\u8baf\u4e91\u8f7b\u91cf\u670d\u52a1\u5668\n  \u2193 WireGuard \u96a7\u9053\n\u5bb6\u5bbd\u98de\u725b OS<\/code><\/pre>\n\n\n\n<p>\u7528\u9014\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>1. \u817e\u8baf\u4e91\u4f5c\u4e3a\u516c\u7f51 IPv4 \u5165\u53e3\n2. \u98de\u725b OS \u4e3b\u52a8\u8fde\u63a5\u817e\u8baf\u4e91\n3. \u5bb6\u91cc\u8def\u7531\u5668\u4e0d\u5f00\u653e\u4efb\u4f55\u5165\u7ad9\u7aef\u53e3\n4. \u540e\u7eed\u7531\u817e\u8baf\u4e91 Caddy \u53cd\u4ee3\u98de\u725b\u670d\u52a1<\/code><\/pre>\n\n\n\n<p>\u6700\u7ec8\u67b6\u6784\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u516c\u7f51\u7528\u6237\n  \u2193\n\u817e\u8baf\u4e91\u516c\u7f51 IPv4\n  \u2193\n\u817e\u8baf\u4e91 Caddy\n  \u2193\n\u817e\u8baf\u4e91 WireGuard Server\uff1a10.66.66.1\n  \u2193\n\u98de\u725b WireGuard Client\uff1a10.66.66.2\n  \u2193\n\u98de\u725b OS \u670d\u52a1<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">2. \u6700\u7ec8\u91c7\u7528\u65b9\u6848<\/h2>\n\n\n\n<p>\u6700\u7ec8\u91c7\u7528\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u817e\u8baf\u4e91\uff1a\n  \u539f\u751f WireGuard Server\n  Docker Caddy\n\n\u98de\u725b OS\uff1a\n  \u539f\u751f WireGuard Client\n  Docker \u4e1a\u52a1\u670d\u52a1\n\nWireGuard \u7aef\u53e3\uff1a\n  UDP 51820\n\nWireGuard \u7f51\u6bb5\uff1a\n  10.66.66.0\/24<\/code><\/pre>\n\n\n\n<p>\u4e0d\u63a8\u8350\u4f7f\u7528 Docker \u8fd0\u884c WireGuard\u3002 \u539f\u56e0\u662f\u817e\u8baf\u4e91\u548c\u98de\u725b Docker \u73af\u5883\u90fd\u66fe\u51fa\u73b0\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>RTNETLINK answers: Operation not permitted<\/code><\/pre>\n\n\n\n<p>\u8be5\u9519\u8bef\u8868\u793a\u5bb9\u5668\u6ca1\u6709\u6743\u9650\u521b\u5efa\u6216\u914d\u7f6e WireGuard \u7f51\u5361\u3002\u6700\u7ec8\u4e24\u7aef\u6539\u7528\u539f\u751f WireGuard \u540e\u89e3\u51b3\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">3. \u7f51\u7edc\u89c4\u5212<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>\u817e\u8baf\u4e91\u516c\u7f51 IPv4\uff1a&lt;PUBLIC_IPV4&gt;\n\u817e\u8baf\u4e91 WireGuard IP\uff1a10.66.66.1\/24\n\u98de\u725b WireGuard IP\uff1a10.66.66.2\/24\nWireGuard UDP \u7aef\u53e3\uff1a51820<\/code><\/pre>\n\n\n\n<p>\u5bb6\u91cc\u8def\u7531\u5668\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u4e0d\u5f00\u653e 80\n\u4e0d\u5f00\u653e 443\n\u4e0d\u5f00\u653e 51820\n\u4e0d\u505a\u7aef\u53e3\u8f6c\u53d1<\/code><\/pre>\n\n\n\n<p>\u98de\u725b\u4e3b\u52a8\u8fde\u63a5\u817e\u8baf\u4e91\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u98de\u725b OS \u2192 \u817e\u8baf\u4e91\u516c\u7f51 IPv4:51820\/udp<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">4. \u817e\u8baf\u4e91\u9632\u706b\u5899\u653e\u884c<\/h2>\n\n\n\n<p>\u817e\u8baf\u4e91\u8f7b\u91cf\u5e94\u7528\u670d\u52a1\u5668\u63a7\u5236\u53f0\u653e\u884c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>TCP 22\nTCP 80\nTCP 443\nUDP 51820<\/code><\/pre>\n\n\n\n<p>\u7cfb\u7edf UFW \u653e\u884c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ufw default deny incoming\nufw default allow outgoing\n\nufw allow 22\/tcp\nufw allow 80\/tcp\nufw allow 443\/tcp\nufw allow 51820\/udp\n\nufw --force enable\nufw status<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">5. \u817e\u8baf\u4e91\u5b89\u88c5 WireGuard<\/h2>\n\n\n\n<p>\u817e\u8baf\u4e91 Debian \u6267\u884c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>apt update\n\napt install -y wireguard wireguard-tools curl wget vim ufw tcpdump dnsutils<\/code><\/pre>\n\n\n\n<p>\u5f00\u542f\u5185\u6838\u8f6c\u53d1\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>cat &gt; \/etc\/sysctl.d\/99-wireguard.conf &lt;&lt;'EOF'\nnet.ipv4.ip_forward=1\nnet.ipv4.conf.all.src_valid_mark=1\nEOF\n\nsysctl --system<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">6. \u817e\u8baf\u4e91\u751f\u6210 WireGuard \u670d\u52a1\u7aef\u5bc6\u94a5<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>mkdir -p \/etc\/wireguard\ncd \/etc\/wireguard\numask 077\n\nwg genkey | tee server_private.key | wg pubkey &gt; server_public.key\n\ncat server_public.key<\/code><\/pre>\n\n\n\n<p>\u4fdd\u5b58\u8f93\u51fa\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;SERVER_PUBLIC_KEY&gt;<\/code><\/pre>\n\n\n\n<p>\u670d\u52a1\u7aef\u79c1\u94a5\u4fdd\u5b58\u5728\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/etc\/wireguard\/server_private.key<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">7. \u817e\u8baf\u4e91\u521b\u5efa\u4e34\u65f6 wg0 \u914d\u7f6e<\/h2>\n\n\n\n<p>\u5148\u5199\u5165\u670d\u52a1\u7aef\u914d\u7f6e\uff0c\u7b49\u98de\u725b\u751f\u6210\u5ba2\u6237\u7aef\u516c\u94a5\u540e\u518d\u8865 Peer\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SERVER_PRIVATE_KEY=\"$(cat \/etc\/wireguard\/server_private.key)\"\n\ncat &gt; \/etc\/wireguard\/wg0.conf &lt;&lt;EOF\n&#91;Interface]\nAddress = 10.66.66.1\/24\nListenPort = 51820\nPrivateKey = ${SERVER_PRIVATE_KEY}\n\n# \u7b49\u98de\u725b\u751f\u6210 CLIENT_PUBLIC_KEY \u540e\u6dfb\u52a0 Peer\nEOF<\/code><\/pre>\n\n\n\n<p>\u542f\u52a8 WireGuard\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>systemctl enable wg-quick@wg0\nsystemctl restart wg-quick@wg0\nwg<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">8. \u817e\u8baf\u4e91\u521b\u5efa\u6dfb\u52a0\u98de\u725b Peer \u7684\u811a\u672c<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>cat &gt; \/root\/server-add-client.sh &lt;&lt;'EOF'\n#!\/usr\/bin\/env bash\nset -euo pipefail\n\nif &#91; $# -lt 1 ]; then\n  echo \"\u7528\u6cd5\uff1abash \/root\/server-add-client.sh &lt;CLIENT_PUBLIC_KEY&gt;\"\n  exit 1\nfi\n\nCLIENT_PUBLIC_KEY=\"$1\"\nSERVER_PRIVATE_KEY=\"$(cat \/etc\/wireguard\/server_private.key)\"\n\ncat &gt; \/etc\/wireguard\/wg0.conf &lt;&lt;EOF_WG\n&#91;Interface]\nAddress = 10.66.66.1\/24\nListenPort = 51820\nPrivateKey = ${SERVER_PRIVATE_KEY}\n\n&#91;Peer]\nPublicKey = ${CLIENT_PUBLIC_KEY}\nAllowedIPs = 10.66.66.2\/32\nPersistentKeepalive = 25\nEOF_WG\n\nsystemctl restart wg-quick@wg0\nsleep 2\nwg\nEOF\n\nchmod +x \/root\/server-add-client.sh<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">9. \u98de\u725b OS \u5b89\u88c5 WireGuard<\/h2>\n\n\n\n<p>\u98de\u725b OS \u5df2\u786e\u8ba4\u5e95\u5c42\u4e3a Debian 12\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Debian GNU\/Linux 12 bookworm\napt \u53ef\u7528<\/code><\/pre>\n\n\n\n<p>\u98de\u725b\u6267\u884c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>apt update\n\napt install -y wireguard wireguard-tools curl wget vim<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">10. \u98de\u725b\u751f\u6210 WireGuard \u5ba2\u6237\u7aef\u5bc6\u94a5<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>mkdir -p \/etc\/wireguard\ncd \/etc\/wireguard\numask 077\n\nwg genkey | tee client_private.key | wg pubkey &gt; client_public.key\n\ncat client_public.key<\/code><\/pre>\n\n\n\n<p>\u4fdd\u5b58\u8f93\u51fa\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;CLIENT_PUBLIC_KEY&gt;<\/code><\/pre>\n\n\n\n<p>\u5ba2\u6237\u7aef\u79c1\u94a5\u4fdd\u5b58\u5728\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/etc\/wireguard\/client_private.key<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">11. \u98de\u725b\u5199\u5165 wg0 \u914d\u7f6e<\/h2>\n\n\n\n<p>\u5c06 <code>&lt;SERVER_PUBLIC_KEY&gt;<\/code> \u66ff\u6362\u6210\u817e\u8baf\u4e91\u8f93\u51fa\u7684\u670d\u52a1\u7aef\u516c\u94a5\u3002<\/p>\n\n\n\n<p>\u5c06 <code>&lt;PUBLIC_IPV4&gt;<\/code> \u66ff\u6362\u6210\u817e\u8baf\u4e91\u516c\u7f51 IPv4\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>CLIENT_PRIVATE_KEY=\"$(cat \/etc\/wireguard\/client_private.key)\"\n\ncat &gt; \/etc\/wireguard\/wg0.conf &lt;&lt;EOF\n&#91;Interface]\nAddress = 10.66.66.2\/24\nPrivateKey = ${CLIENT_PRIVATE_KEY}\n\n&#91;Peer]\nPublicKey = &lt;SERVER_PUBLIC_KEY&gt;\nEndpoint = &lt;PUBLIC_IPV4&gt;:51820\nAllowedIPs = 10.66.66.0\/24\nPersistentKeepalive = 25\nEOF<\/code><\/pre>\n\n\n\n<p>\u542f\u52a8\u98de\u725b WireGuard\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>systemctl enable wg-quick@wg0\nsystemctl restart wg-quick@wg0\nwg<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">12. \u817e\u8baf\u4e91\u6dfb\u52a0\u98de\u725b Peer<\/h2>\n\n\n\n<p>\u56de\u5230\u817e\u8baf\u4e91\uff0c\u5c06\u98de\u725b\u8f93\u51fa\u7684 <code>&lt;CLIENT_PUBLIC_KEY&gt;<\/code> \u6dfb\u52a0\u8fdb\u670d\u52a1\u7aef\u914d\u7f6e\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>bash \/root\/server-add-client.sh &lt;CLIENT_PUBLIC_KEY&gt;<\/code><\/pre>\n\n\n\n<p>\u67e5\u770b\u72b6\u6001\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>wg<\/code><\/pre>\n\n\n\n<p>\u6210\u529f\u65f6\u5e94\u770b\u5230\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>latest handshake: xx seconds ago\ntransfer: xxx received, xxx sent<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">13. \u9a8c\u8bc1 WireGuard \u96a7\u9053<\/h2>\n\n\n\n<p>\u817e\u8baf\u4e91\u6267\u884c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ping -c 4 10.66.66.2<\/code><\/pre>\n\n\n\n<p>\u6210\u529f\u7ed3\u679c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>4 packets transmitted, 4 received<\/code><\/pre>\n\n\n\n<p>\u67e5\u770b\u8def\u7531\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ip route get 10.66.66.2<\/code><\/pre>\n\n\n\n<p>\u5e94\u770b\u5230\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>10.66.66.2 dev wg0 src 10.66.66.1<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">14. \u98de\u725b\u542f\u52a8\u4e34\u65f6\u6d4b\u8bd5\u670d\u52a1<\/h2>\n\n\n\n<p>\u98de\u725b\u6267\u884c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>docker run -d \\\n  --name test-web \\\n  --restart unless-stopped \\\n  -p 18080:80 \\\n  nginx:alpine<\/code><\/pre>\n\n\n\n<p>\u817e\u8baf\u4e91\u6d4b\u8bd5\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>curl -I http:\/\/10.66.66.2:18080<\/code><\/pre>\n\n\n\n<p>\u5982\u679c\u8fd4\u56de\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>HTTP\/1.1 200 OK<\/code><\/pre>\n\n\n\n<p>\u8bf4\u660e\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u817e\u8baf\u4e91 \u2192 WireGuard \u2192 \u98de\u725b\u670d\u52a1<\/code><\/pre>\n\n\n\n<p>\u5df2\u7ecf\u6253\u901a\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">15. \u540e\u7eed\u670d\u52a1\u8bbf\u95ee\u65b9\u5f0f<\/h2>\n\n\n\n<p>\u540e\u7eed\u817e\u8baf\u4e91 Caddy \u53ef\u4ee5\u53cd\u4ee3\u98de\u725b\u670d\u52a1\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>10.66.66.2:\u670d\u52a1\u7aef\u53e3<\/code><\/pre>\n\n\n\n<p>\u4f8b\u5982\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u98de\u725b\u7ba1\u7406\u540e\u53f0\uff1a10.66.66.2:5666\nWordPress\uff1a10.66.66.2:48080\nMCS Web\uff1a10.66.66.2:23333\nMinIO Console\uff1a10.66.66.2:9001\nMinIO API\uff1a10.66.66.2:9000<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">16. \u5e38\u7528\u7ef4\u62a4\u547d\u4ee4<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u817e\u8baf\u4e91<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>wg\nsystemctl status wg-quick@wg0\nsystemctl restart wg-quick@wg0\nping -c 4 10.66.66.2<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u98de\u725b OS<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>wg\nsystemctl status wg-quick@wg0\nsystemctl restart wg-quick@wg0<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u67e5\u770b\u7aef\u53e3<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>ss -tulpn | grep -E '51820|80|443'<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u6293\u5305\u6392\u67e5<\/h3>\n\n\n\n<p>\u817e\u8baf\u4e91\u6293 WireGuard \u5305\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>tcpdump -ni any udp port 51820<\/code><\/pre>\n\n\n\n<p>\u98de\u725b\u91cd\u542f WireGuard\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>systemctl restart wg-quick@wg0<\/code><\/pre>\n\n\n\n<p>\u5982\u679c\u817e\u8baf\u4e91\u80fd\u770b\u5230\u98de\u725b\u6765\u7684 UDP \u5305\uff0c\u4f46\u6ca1\u6709\u63e1\u624b\uff0c\u591a\u534a\u662f\u5bc6\u94a5\u4e0d\u5339\u914d\u3002 \u5982\u679c\u817e\u8baf\u4e91\u770b\u4e0d\u5230 UDP \u5305\uff0c\u591a\u534a\u662f\u9632\u706b\u5899\u6216 Endpoint \u914d\u7f6e\u95ee\u9898\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">17. \u5e38\u89c1\u95ee\u9898<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">17.1 Docker WireGuard \u62a5\u6743\u9650\u9519\u8bef<\/h3>\n\n\n\n<p>\u9519\u8bef\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>RTNETLINK answers: Operation not permitted<\/code><\/pre>\n\n\n\n<p>\u539f\u56e0\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Docker \u5bb9\u5668\u65e0\u6743\u9650\u521b\u5efa\u6216\u914d\u7f6e wg0 \u7f51\u5361<\/code><\/pre>\n\n\n\n<p>\u89e3\u51b3\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u4e24\u7aef\u90fd\u6539\u7528\u539f\u751f WireGuard<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">17.2 latest-handshake \u4e3a 0<\/h3>\n\n\n\n<p>\u68c0\u67e5\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>wg\ntcpdump -ni any udp port 51820<\/code><\/pre>\n\n\n\n<p>\u91cd\u70b9\u786e\u8ba4\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u817e\u8baf\u4e91\u63a7\u5236\u53f0\u662f\u5426\u653e\u884c UDP 51820\nUFW \u662f\u5426\u653e\u884c UDP 51820\n\u98de\u725b Endpoint \u662f\u5426\u4e3a &lt;PUBLIC_IPV4&gt;:51820\n\u670d\u52a1\u7aef Peer PublicKey \u662f\u5426\u4e3a\u98de\u725b client_public.key\n\u5ba2\u6237\u7aef Peer PublicKey \u662f\u5426\u4e3a\u817e\u8baf\u4e91 server_public.key<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">17.3 ping \u4e0d\u901a 10.66.66.2<\/h3>\n\n\n\n<p>\u817e\u8baf\u4e91\u6267\u884c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ip route get 10.66.66.2\nwg<\/code><\/pre>\n\n\n\n<p>\u5e94\u770b\u5230\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>10.66.66.2 dev wg0 src 10.66.66.1<\/code><\/pre>\n\n\n\n<p>\u5982\u679c\u6709\u8def\u7531\u4f46 ping \u4e0d\u901a\uff0c\u901a\u5e38\u662f\u63e1\u624b\u672a\u6210\u529f\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">17.4 curl \u98de\u725b\u670d\u52a1\u4e0d\u901a<\/h3>\n\n\n\n<p>\u5982\u679c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ping -c 4 10.66.66.2<\/code><\/pre>\n\n\n\n<p>\u901a\uff0c\u4f46\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>curl -I http:\/\/10.66.66.2:\u7aef\u53e3<\/code><\/pre>\n\n\n\n<p>\u4e0d\u901a\uff0c\u5219\u95ee\u9898\u5728\u98de\u725b\u670d\u52a1\u672c\u8eab\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>1. \u670d\u52a1\u672a\u542f\u52a8\n2. \u7aef\u53e3\u5199\u9519\n3. Docker \u6ca1\u6620\u5c04\u7aef\u53e3\n4. \u670d\u52a1\u53ea\u76d1\u542c 127.0.0.1\n5. \u670d\u52a1\u53ea\u76d1\u542c\u5c40\u57df\u7f51 IP\uff0c\u6ca1\u6709\u76d1\u542c WireGuard \u53ef\u8bbf\u95ee\u5730\u5740<\/code><\/pre>\n\n\n\n<p>\u98de\u725b\u68c0\u67e5\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ss -tlnp\ndocker ps<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">18. \u6700\u7ec8\u6210\u529f\u72b6\u6001<\/h2>\n\n\n\n<p>\u6210\u529f\u72b6\u6001\u5e94\u6ee1\u8db3\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u817e\u8baf\u4e91 wg \u6709 latest handshake\n\u817e\u8baf\u4e91 ping 10.66.66.2 \u6210\u529f\n\u817e\u8baf\u4e91 curl http:\/\/10.66.66.2:18080 \u6210\u529f\n\u98de\u725b\u65e0\u9700\u5f00\u653e\u8def\u7531\u5668\u7aef\u53e3<\/code><\/pre>\n\n\n\n<p>\u6700\u7ec8\u94fe\u8def\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u817e\u8baf\u4e91\u516c\u7f51 IPv4\n  \u2193\n\u817e\u8baf\u4e91 WireGuard Server 10.66.66.1\n  \u2193\n\u98de\u725b WireGuard Client 10.66.66.2\n  \u2193\n\u98de\u725b Docker \/ \u7cfb\u7edf\u670d\u52a1<\/code><\/pre>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. \u67b6\u6784\u8bf4\u660e \u76ee\u6807\u94fe\u8def\uff1a \u7528\u9014\uff1a \u6700\u7ec8\u67b6\u6784\uff1a 2. \u6700\u7ec8\u91c7\u7528\u65b9\u6848 \u6700\u7ec8\u91c7\u7528\uff1a \u4e0d\u63a8\u8350\u4f7f\u7528 Docker \u8fd0\u884c [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[10],"class_list":["post-41","post","type-post","status-publish","format-standard","hentry","category-nas","tag-nas"],"_links":{"self":[{"href":"https:\/\/blog.kwitsukasa.top\/index.php?rest_route=\/wp\/v2\/posts\/41","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.kwitsukasa.top\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.kwitsukasa.top\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.kwitsukasa.top\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.kwitsukasa.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=41"}],"version-history":[{"count":3,"href":"https:\/\/blog.kwitsukasa.top\/index.php?rest_route=\/wp\/v2\/posts\/41\/revisions"}],"predecessor-version":[{"id":44,"href":"https:\/\/blog.kwitsukasa.top\/index.php?rest_route=\/wp\/v2\/posts\/41\/revisions\/44"}],"wp:attachment":[{"href":"https:\/\/blog.kwitsukasa.top\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=41"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.kwitsukasa.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=41"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.kwitsukasa.top\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=41"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}