Closed MikPisula closed 9 months ago
@MikPisula Hello! Thank you for your detailed suggestion. Currently, this project has no plan to support UFW. Your suggestion will be considered for future improvements. You are welcome to adapt this project to your needs according to the license.
Checklist
Describe the enhancement request UFW is the default firewall configuration tool for Ubuntu. As such it is widely used on many Ubuntu-based servers for firewalling. Currently
wireguard-install
completely bypasses UFW by adding rules through thewg-iptables
service.As per the ubuntu manpages UFW supports the forwarding and filtering functionality required by the Wireguard VPN. Some of it can be accomplished through the
ufw
command, while the rest has to be performed through direct modification of/etc/ufw/before.rules
.On a host with UFW installed and enabled, instead of creating the
wireguard-iptables
service, wireguard-install should append the post-routing rules to/etc/ufw/before.rules
:and run the following commands:
I think that the last rule in
wireguard-iptables
can be ommited, as/etc/ufw/before.rules
already has the following:but that would require verification.
Is your enhancement request related to a problem? Please describe. UFW clashing with
wireguard-iptables
.Additional context N/A