wireguard.go 4.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179
  1. package proxy
  2. import (
  3. "context"
  4. "fmt"
  5. "log"
  6. "net"
  7. "runtime"
  8. "strconv"
  9. "github.com/c-robinson/iplib"
  10. "github.com/gravitl/netmaker/nm-proxy/common"
  11. "github.com/gravitl/netmaker/nm-proxy/packet"
  12. "github.com/gravitl/netmaker/nm-proxy/server"
  13. "github.com/gravitl/netmaker/nm-proxy/wg"
  14. )
  15. func NewProxy(config Config) *Proxy {
  16. p := &Proxy{Config: config}
  17. p.Ctx, p.Cancel = context.WithCancel(context.Background())
  18. return p
  19. }
  20. // proxyToRemote proxies everything from Wireguard to the RemoteKey peer
  21. func (p *Proxy) ProxyToRemote() {
  22. buf := make([]byte, 1500)
  23. go func() {
  24. <-p.Ctx.Done()
  25. defer p.LocalConn.Close()
  26. defer p.RemoteConn.Close()
  27. }()
  28. for {
  29. select {
  30. case <-p.Ctx.Done():
  31. log.Printf("----------> stopped proxying to remote peer %s due to closed connection\n", p.Config.RemoteKey)
  32. if runtime.GOOS == "darwin" {
  33. host, _, err := net.SplitHostPort(p.LocalConn.LocalAddr().String())
  34. if err != nil {
  35. log.Println("Failed to split host: ", p.LocalConn.LocalAddr().String(), err)
  36. return
  37. }
  38. if host == "127.0.0.1" {
  39. return
  40. }
  41. _, err = common.RunCmd(fmt.Sprintf("ifconfig lo0 -alias %s 255.255.255.255", host), true)
  42. if err != nil {
  43. log.Println("Failed to add alias: ", err)
  44. }
  45. }
  46. return
  47. default:
  48. n, err := p.LocalConn.Read(buf)
  49. if err != nil {
  50. log.Println("ERRR READ: ", err)
  51. continue
  52. }
  53. peers := common.WgIFaceMap[p.Config.WgInterface.Name]
  54. if peerI, ok := peers[p.Config.RemoteKey]; ok {
  55. log.Println("PROCESSING PKT BEFORE SENDING")
  56. buf, n, err = packet.ProcessPacketBeforeSending(buf, n, peerI.Config.RemoteWgPort)
  57. if err != nil {
  58. log.Println("failed to process pkt before sending: ", err)
  59. }
  60. } else {
  61. log.Printf("Peer: %s not found in config\n", p.Config.RemoteKey)
  62. }
  63. // test(n, buf)
  64. log.Printf("PROXING TO REMOTE!!!---> %s >>>>> %s\n", server.NmProxyServer.Server.LocalAddr().String(), p.RemoteConn.RemoteAddr().String())
  65. host, port, _ := net.SplitHostPort(p.RemoteConn.RemoteAddr().String())
  66. portInt, _ := strconv.Atoi(port)
  67. _, err = server.NmProxyServer.Server.WriteToUDP(buf[:n], &net.UDPAddr{
  68. IP: net.ParseIP(host),
  69. Port: portInt,
  70. })
  71. if err != nil {
  72. log.Println("Failed to send to remote: ", err)
  73. }
  74. }
  75. }
  76. }
  77. func (p *Proxy) updateEndpoint() error {
  78. udpAddr, err := net.ResolveUDPAddr("udp", p.LocalConn.LocalAddr().String())
  79. if err != nil {
  80. return err
  81. }
  82. log.Println("--------> UDPADDR: ", udpAddr)
  83. // add local proxy connection as a Wireguard peer
  84. err = p.Config.WgInterface.UpdatePeer(p.Config.RemoteKey, p.Config.AllowedIps, wg.DefaultWgKeepAlive,
  85. udpAddr, p.Config.PreSharedKey)
  86. if err != nil {
  87. return err
  88. }
  89. return nil
  90. }
  91. func (p *Proxy) Start(remoteConn net.Conn) error {
  92. p.RemoteConn = remoteConn
  93. var err error
  94. wgPort, err := p.Config.WgInterface.GetListenPort()
  95. if err != nil {
  96. log.Printf("Failed to get listen port for iface: %s,Err: %v\n", p.Config.WgInterface.Name, err)
  97. return err
  98. }
  99. addr, err := GetFreeIp("127.0.0.1/8", *wgPort)
  100. if err != nil {
  101. log.Println("Failed to get freeIp: ", err)
  102. return err
  103. }
  104. wgAddr := "127.0.0.1"
  105. if runtime.GOOS == "darwin" {
  106. wgAddr = addr
  107. }
  108. p.LocalConn, err = net.DialUDP("udp", &net.UDPAddr{
  109. IP: net.ParseIP(addr),
  110. Port: common.NmProxyPort,
  111. }, &net.UDPAddr{
  112. IP: net.ParseIP(wgAddr),
  113. Port: *wgPort,
  114. })
  115. if err != nil {
  116. log.Fatalf("failed dialing to local Wireguard port,Err: %v\n", err)
  117. }
  118. log.Printf("Dialing to local Wireguard port %s --> %s\n", p.LocalConn.LocalAddr().String(), p.LocalConn.RemoteAddr().String())
  119. err = p.updateEndpoint()
  120. if err != nil {
  121. log.Printf("error while updating Wireguard peer endpoint [%s] %v\n", p.Config.RemoteKey, err)
  122. return err
  123. }
  124. go p.ProxyToRemote()
  125. return nil
  126. }
  127. func GetFreeIp(cidrAddr string, dstPort int) (string, error) {
  128. //ensure AddressRange is valid
  129. if _, _, err := net.ParseCIDR(cidrAddr); err != nil {
  130. log.Println("UniqueAddress encountered an error")
  131. return "", err
  132. }
  133. net4 := iplib.Net4FromStr(cidrAddr)
  134. newAddrs := net4.FirstAddress()
  135. log.Println("COUNT: ", net4.Count())
  136. for {
  137. if runtime.GOOS == "darwin" {
  138. _, err := common.RunCmd(fmt.Sprintf("ifconfig lo0 alias %s 255.255.255.255", newAddrs.String()), true)
  139. if err != nil {
  140. log.Println("Failed to add alias: ", err)
  141. }
  142. }
  143. conn, err := net.DialUDP("udp", &net.UDPAddr{
  144. IP: net.ParseIP(newAddrs.String()),
  145. Port: common.NmProxyPort,
  146. }, &net.UDPAddr{
  147. IP: net.ParseIP("127.0.0.1"),
  148. Port: dstPort,
  149. })
  150. if err == nil {
  151. conn.Close()
  152. return newAddrs.String(), nil
  153. }
  154. newAddrs, err = net4.NextIP(newAddrs)
  155. if err != nil {
  156. return "", err
  157. }
  158. }
  159. }