Skip to content
Back to skills

Wireguard Mesh Vpn Routing

BSecurity

Design, deploy, and maintain zero-trust mesh VPNs and site-to-site overlay networks using WireGuard. Configure cryptographic key pairs, AllowedIPs subnet routing, persistent keepalives, NAT traversal, and automated tunnel configurations using wg-quick. Trigger when setting up secure cross-cloud VPC peering, remote access tunnels, or encrypted overlays.

  • 8 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 29, 2026
ai-agentsrustgobashnodeawsgcp

Works with

  • cli

Security analysis

B88/100
  • criticalSends environment variables or credentials to an external URL

Pro shows the line behind each finding and how to fix it

Scanned September 29, 2026

npx -y skills add hamzabellouch/agent-skills --skill wireguard-mesh-vpn-routing --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Wireguard Mesh Vpn Routing?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Wireguard Mesh Vpn Routing
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/hamzabellouch-wireguard-mesh-vpn-routing/badge)](https://www.skillsdirectory.com/skills/hamzabellouch-wireguard-mesh-vpn-routing)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: wireguard-mesh-vpn-routing
metadata:
  category: Network Engineering and Edge Routing
description: Design, deploy, and maintain zero-trust mesh VPNs and site-to-site overlay networks using WireGuard. Configure cryptographic key pairs, AllowedIPs subnet routing, persistent keepalives, NAT traversal, and automated tunnel configurations using wg-quick. Trigger when setting up secure cross-cloud VPC peering, remote access tunnels, or encrypted overlays.
compatibility: Linux Kernel 5.6+, WireGuard Tools (`wg`, `wg-quick`)
---

# WireGuard Mesh VPN & Routing Skill Guide

This skill provides step-by-step guidance for configuring, automating, and troubleshooting WireGuard kernel-based VPN tunnels for site-to-site and point-to-point mesh networks.

---

## 1. Cryptographic Mesh Architecture

WireGuard relies on **Noise Protocol Framework (Curve25519, ChaCha20-Poly1305, BLAKE2s)**. Every peer is identified solely by its public key.

```text
[ Cloud Node A (AWS) ]                  [ Cloud Node B (GCP) ]
Public IP: 198.51.100.1                 Public IP: 203.0.113.5
WireGuard IP: 10.100.0.1/24             WireGuard IP: 10.100.0.2/24
      |                                       |
      +========== Encrypted UDP Tunnel ======+
                  (Port 51820)
                       |
        Routing: AllowedIPs = 10.100.0.0/24
```

---

## 2. Production WireGuard Configuration Patterns

### A. Hub / Gateway Node Configuration (`/etc/wireguard/wg0.conf`)

```ini
[Interface]
# Gateway internal overlay address
Address = 10.100.0.1/24
ListenPort = 51820
PrivateKey = <GATEWAY_PRIVATE_KEY>

# Forwarding & NAT iptables rules
PostUp = iptables -A FORWARD -i wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i wg0 -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
SaveConfig = false

# Peer 1: Remote Cloud Worker
[Peer]
PublicKey = <WORKER_NODE_PUBLIC_KEY>
AllowedIPs = 10.100.0.2/32
PersistentKeepalive = 25

# Peer 2: Branch Office Gateway (Subnet Routing)
[Peer]
PublicKey = <BRANCH_GW_PUBLIC_KEY>
# Route both the tunnel IP and the remote office LAN
AllowedIPs = 10.100.0.3/32, 192.168.50.0/24
PersistentKeepalive = 25
```

### B. Automated Peer Provisioning Script (Bash / Linux)

```bash
#!/usr/bin/env bash
set -euo pipefail

PEER_NAME="${1:?Usage: $0 <peer_name> <tunnel_ip>}"
PEER_IP="${2:?Usage: $0 <peer_name> <tunnel_ip>}"

CONFIG_DIR="/etc/wireguard/peers/${PEER_NAME}"
mkdir -p "${CONFIG_DIR}"
chmod 700 "${CONFIG_DIR}"

# 1. Generate keypair
wg genkey | tee "${CONFIG_DIR}/privatekey" | wg pubkey > "${CONFIG_DIR}/publickey"
wg genpsk > "${CONFIG_DIR}/preshared.key"

PRIV_KEY=$(cat "${CONFIG_DIR}/privatekey")
PUB_KEY=$(cat "${CONFIG_DIR}/publickey")
PSK=$(cat "${CONFIG_DIR}/preshared.key")

echo "Created keys for ${PEER_NAME}:"
echo "Public Key: ${PUB_KEY}"

# 2. Generate client wg-quick configuration
cat <<EOF > "${CONFIG_DIR}/${PEER_NAME}.conf"
[Interface]
Address = ${PEER_IP}/24
PrivateKey = ${PRIV_KEY}
DNS = 10.100.0.1

[Peer]
PublicKey = $(cat /etc/wireguard/server_publickey)
PresharedKey = ${PSK}
Endpoint = vpn.example.com:51820
AllowedIPs = 10.100.0.0/24
PersistentKeepalive = 25
EOF

chmod 600 "${CONFIG_DIR}/${PEER_NAME}.conf"
echo "Configuration generated at ${CONFIG_DIR}/${PEER_NAME}.conf"
```

---

## 3. Operational Best Practices

1. **Kernel Forwarding:** Ensure `net.ipv4.ip_forward = 1` is persistently enabled in `/etc/sysctl.d/99-wireguard.conf`.
2. **NAT Keepalive:** For peers behind dynamic NAT or firewalls, set `PersistentKeepalive = 25` to keep NAT mappings alive.
3. **Restricted AllowedIPs:** Avoid setting `AllowedIPs = 0.0.0.0/0` unless routing all internet traffic (full tunnel); for inter-service communication, specify only the cluster subnets.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…