wireguard.go 5.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203
  1. package proxy
  2. import (
  3. "context"
  4. "errors"
  5. "fmt"
  6. "log"
  7. "net"
  8. "runtime"
  9. "strings"
  10. "github.com/c-robinson/iplib"
  11. "github.com/gravitl/netmaker/nm-proxy/common"
  12. "github.com/gravitl/netmaker/nm-proxy/packet"
  13. "github.com/gravitl/netmaker/nm-proxy/server"
  14. "github.com/gravitl/netmaker/nm-proxy/wg"
  15. )
  16. func NewProxy(config Config) *Proxy {
  17. p := &Proxy{Config: config}
  18. p.Ctx, p.Cancel = context.WithCancel(context.Background())
  19. return p
  20. }
  21. // proxyToRemote proxies everything from Wireguard to the RemoteKey peer
  22. func (p *Proxy) ProxyToRemote() {
  23. buf := make([]byte, 1500)
  24. go func() {
  25. <-p.Ctx.Done()
  26. log.Println("Closing connection for: ", p.LocalConn.LocalAddr().String())
  27. p.LocalConn.Close()
  28. }()
  29. for {
  30. select {
  31. case <-p.Ctx.Done():
  32. log.Printf("----------> stopped proxying to remote peer %s due to closed connection\n", p.Config.RemoteKey)
  33. if runtime.GOOS == "darwin" {
  34. host, _, err := net.SplitHostPort(p.LocalConn.LocalAddr().String())
  35. if err != nil {
  36. log.Println("Failed to split host: ", p.LocalConn.LocalAddr().String(), err)
  37. return
  38. }
  39. if host != "127.0.0.1" {
  40. _, err = common.RunCmd(fmt.Sprintf("ifconfig lo0 -alias %s 255.255.255.255", host), true)
  41. if err != nil {
  42. log.Println("Failed to add alias: ", err)
  43. }
  44. }
  45. }
  46. return
  47. default:
  48. n, err := p.LocalConn.Read(buf)
  49. if err != nil {
  50. log.Println("ERRR READ: ", err)
  51. continue
  52. }
  53. peers := common.WgIFaceMap[p.Config.WgInterface.Name]
  54. if peerI, ok := peers[p.Config.RemoteKey]; ok {
  55. var srcPeerKeyHash, dstPeerKeyHash string
  56. buf, n, srcPeerKeyHash, dstPeerKeyHash = packet.ProcessPacketBeforeSending(buf, n, peerI.Config.LocalKey, peerI.Config.Key)
  57. if err != nil {
  58. log.Println("failed to process pkt before sending: ", err)
  59. }
  60. log.Printf("PROXING TO REMOTE!!!---> %s >>>>> %s [[ SrcPeerHash: %s, DstPeerHash: %s ]]\n",
  61. server.NmProxyServer.Server.LocalAddr().String(), p.RemoteConn.String(), srcPeerKeyHash, dstPeerKeyHash)
  62. } else {
  63. log.Printf("Peer: %s not found in config\n", p.Config.RemoteKey)
  64. p.Cancel()
  65. continue
  66. }
  67. //test(n, buf)
  68. _, err = server.NmProxyServer.Server.WriteToUDP(buf[:n], p.RemoteConn)
  69. if err != nil {
  70. log.Println("Failed to send to remote: ", err)
  71. }
  72. }
  73. }
  74. }
  75. func test(n int, buffer []byte) {
  76. data := buffer[:n]
  77. srcKeyHash := data[n-32 : n-16]
  78. dstKeyHash := data[n-16:]
  79. log.Printf("--------> TEST PACKET [ SRCKEYHASH: %x ], [ DSTKEYHASH: %x ] \n", srcKeyHash, dstKeyHash)
  80. }
  81. func (p *Proxy) updateEndpoint() error {
  82. udpAddr, err := net.ResolveUDPAddr("udp", p.LocalConn.LocalAddr().String())
  83. if err != nil {
  84. return err
  85. }
  86. // add local proxy connection as a Wireguard peer
  87. log.Printf("---> ## Updating Peer: %+v\n", p.Config)
  88. err = p.Config.WgInterface.UpdatePeer(p.Config.RemoteKey, p.Config.AllowedIps, wg.DefaultWgKeepAlive,
  89. udpAddr, p.Config.PreSharedKey)
  90. if err != nil {
  91. return err
  92. }
  93. return nil
  94. }
  95. func (p *Proxy) Start(remoteConn *net.UDPAddr) error {
  96. p.RemoteConn = remoteConn
  97. var err error
  98. // err = p.Config.WgInterface.GetWgIface(p.Config.WgInterface.Name)
  99. // if err != nil {
  100. // log.Println("Failed to get iface: ", p.Config.WgInterface.Name, err)
  101. // return err
  102. // }
  103. // wgAddr, err := GetInterfaceIpv4Addr(p.Config.WgInterface.Name)
  104. // if err != nil {
  105. // log.Println("failed to get interface addr: ", err)
  106. // return err
  107. // }
  108. log.Printf("----> WGIFACE: %+v\n", p.Config.WgInterface)
  109. addr, err := GetFreeIp(common.DefaultCIDR, p.Config.WgInterface.Port)
  110. if err != nil {
  111. log.Println("Failed to get freeIp: ", err)
  112. return err
  113. }
  114. wgListenAddr, err := GetInterfaceListenAddr(p.Config.WgInterface.Port)
  115. if err != nil {
  116. log.Println("failed to get wg listen addr: ", err)
  117. return err
  118. }
  119. if runtime.GOOS == "darwin" {
  120. wgListenAddr.IP = net.ParseIP(addr)
  121. }
  122. log.Println("--------->#### Wg Listen Addr: ", wgListenAddr.String())
  123. p.LocalConn, err = net.DialUDP("udp", &net.UDPAddr{
  124. IP: net.ParseIP(addr),
  125. Port: common.NmProxyPort,
  126. }, wgListenAddr)
  127. if err != nil {
  128. log.Printf("failed dialing to local Wireguard port,Err: %v\n", err)
  129. return err
  130. }
  131. log.Printf("Dialing to local Wireguard port %s --> %s\n", p.LocalConn.LocalAddr().String(), p.LocalConn.RemoteAddr().String())
  132. err = p.updateEndpoint()
  133. if err != nil {
  134. log.Printf("error while updating Wireguard peer endpoint [%s] %v\n", p.Config.RemoteKey, err)
  135. return err
  136. }
  137. go p.ProxyToRemote()
  138. return nil
  139. }
  140. func GetFreeIp(cidrAddr string, dstPort int) (string, error) {
  141. //ensure AddressRange is valid
  142. if dstPort == 0 {
  143. return "", errors.New("dst port should be set")
  144. }
  145. if _, _, err := net.ParseCIDR(cidrAddr); err != nil {
  146. log.Println("UniqueAddress encountered an error")
  147. return "", err
  148. }
  149. net4 := iplib.Net4FromStr(cidrAddr)
  150. newAddrs := net4.FirstAddress()
  151. log.Println("COUNT: ", net4.Count())
  152. for {
  153. if runtime.GOOS == "darwin" {
  154. _, err := common.RunCmd(fmt.Sprintf("ifconfig lo0 alias %s 255.255.255.255", newAddrs.String()), true)
  155. if err != nil {
  156. log.Println("Failed to add alias: ", err)
  157. }
  158. }
  159. conn, err := net.DialUDP("udp", &net.UDPAddr{
  160. IP: net.ParseIP(newAddrs.String()),
  161. Port: common.NmProxyPort,
  162. }, &net.UDPAddr{
  163. IP: net.ParseIP("127.0.0.1"),
  164. Port: dstPort,
  165. })
  166. if err != nil {
  167. log.Println("----> GetFreeIP ERR: ", err)
  168. if strings.Contains(err.Error(), "can't assign requested address") ||
  169. strings.Contains(err.Error(), "address already in use") || strings.Contains(err.Error(), "cannot assign requested address") {
  170. var nErr error
  171. newAddrs, nErr = net4.NextIP(newAddrs)
  172. if nErr != nil {
  173. return "", nErr
  174. }
  175. } else {
  176. return "", err
  177. }
  178. }
  179. if err == nil {
  180. conn.Close()
  181. return newAddrs.String(), nil
  182. }
  183. }
  184. }