Open MGelbana opened 1 year ago
Describe the bug
Even thought I following the steps mentioned here, I'm not able to access the internet after enabling Wireguard on my laptop.
Full log
./algo PLAY [localhost] ******************************************************************************************************************************************************************************************* TASK [Gathering Facts] ************************************************************************************************************************************************************************************* ok: [localhost] TASK [Playbook dir stat] *********************************************************************************************************************************************************************************** ok: [localhost] TASK [Ensure Ansible is not being run in a world writable directory] *************************************************************************************************************************************** ok: [localhost] => { "changed": false, "msg": "All assertions passed" } [DEPRECATION WARNING]: Use 'ansible.utils.ipaddr' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. [WARNING]: The value '' is not a valid IP address or network, passing this value to ipaddr filter might result in breaking change in future. TASK [Ensure the requirements installed] ******************************************************************************************************************************************************************* ok: [localhost] TASK [Set required ansible version as a fact] ************************************************************************************************************************************************************** ok: [localhost] => (item=ansible==6.1.0) TASK [Just get the list from default pip] ****************************************************************************************************************************************************************** ok: [localhost] TASK [Verify Python meets Algo VPN requirements] *********************************************************************************************************************************************************** ok: [localhost] => { "changed": false, "msg": "All assertions passed" } TASK [Verify Ansible meets Algo VPN requirements] ********************************************************************************************************************************************************** ok: [localhost] => { "changed": false, "msg": "All assertions passed" } [WARNING]: Found variable using reserved name: no_log PLAY [Ask user for the input] ****************************************************************************************************************************************************************************** TASK [Gathering Facts] ************************************************************************************************************************************************************************************* ok: [localhost] [Cloud prompt] What provider would you like to use? 1. DigitalOcean 2. Amazon Lightsail 3. Amazon EC2 4. Microsoft Azure 5. Google Compute Engine 6. Hetzner Cloud 7. Vultr 8. Scaleway 9. OpenStack (DreamCompute optimised) 10. CloudStack (Exoscale optimised) 11. Linode 12. Install to existing Ubuntu 18.04 or 20.04 server (for more advanced users) Enter the number of your desired provider : 3^M TASK [Cloud prompt] **************************************************************************************************************************************************************************************** ok: [localhost] TASK [Set facts based on the input] ************************************************************************************************************************************************************************ ok: [localhost] [VPN server name prompt] Name the vpn server [algo] : ^M TASK [VPN server name prompt] ****************************************************************************************************************************************************************************** ok: [localhost] [Cellular On Demand prompt] Do you want macOS/iOS clients to enable "Connect On Demand" when connected to cellular networks? [y/N] : ^M TASK [Cellular On Demand prompt] *************************************************************************************************************************************************************************** ok: [localhost] [Wi-Fi On Demand prompt] Do you want macOS/iOS clients to enable "Connect On Demand" when connected to Wi-Fi? [y/N] : ^M TASK [Wi-Fi On Demand prompt] ****************************************************************************************************************************************************************************** ok: [localhost] [Retain the PKI prompt] Do you want to retain the keys (PKI)? (required to add users in the future, but less secure) [y/N] : ^M TASK [Retain the PKI prompt] ******************************************************************************************************************************************************************************* ok: [localhost] [DNS adblocking prompt] Do you want to enable DNS ad blocking on this VPN server? [y/N] : ^M TASK [DNS adblocking prompt] ******************************************************************************************************************************************************************************* ok: [localhost] [SSH tunneling prompt] Do you want each user to have their own account for SSH tunneling? [y/N] : ^M TASK [SSH tunneling prompt] ******************************************************************************************************************************************************************************** ok: [localhost] TASK [Set facts based on the input] ************************************************************************************************************************************************************************ ok: [localhost] PLAY [Provision the server] ******************************************************************************************************************************************************************************** TASK [Gathering Facts] ************************************************************************************************************************************************************************************* ok: [localhost] --> Please include the following block of text when reporting issues: Algo running on: Ubuntu 22.04.2 LTS Created from git fork. Last commit: 45fe0f5 change dockerhub docs references Python 3.10.6 Runtime variables: algo_provider "ec2" algo_ondemand_cellular "False" algo_ondemand_wifi "False" algo_ondemand_wifi_exclude "X251bGw=" algo_dns_adblocking "False" algo_ssh_tunneling "False" wireguard_enabled "True" dns_encryption "True" TASK [Display the invocation environment] ****************************************************************************************************************************************************************** changed: [localhost] TASK [Install the requirements] **************************************************************************************************************************************************************************** ok: [localhost] TASK [Generate the SSH private key] ************************************************************************************************************************************************************************ ok: [localhost] TASK [Generate the SSH public key] ************************************************************************************************************************************************************************* ok: [localhost] TASK [Copy the private SSH key to /tmp] ******************************************************************************************************************************************************************** ok: [localhost] TASK [Include a provisioning role] ************************************************************************************************************************************************************************* TASK [cloud-ec2 : Install requirements] ******************************************************************************************************************************************************************** changed: [localhost] [cloud-ec2 : pause] Enter your AWS Access Key ID (http://docs.aws.amazon.com/general/latest/gr/managing-aws-access-keys.html) Note: Make sure to use an IAM user with an acceptable policy attached (see https://github.com/trailofbits/algo/blob/master/docs/deploy-from-ansible.md) (output is hidden): TASK [cloud-ec2 : pause] *********************************************************************************************************************************************************************************** ok: [localhost] [cloud-ec2 : pause] Enter your AWS Secret Access Key (http://docs.aws.amazon.com/general/latest/gr/managing-aws-access-keys.html) (output is hidden): TASK [cloud-ec2 : pause] *********************************************************************************************************************************************************************************** ok: [localhost] TASK [cloud-ec2 : set_fact] ******************************************************************************************************************************************************************************** ok: [localhost] TASK [cloud-ec2 : Get regions] ***************************************************************************************************************************************************************************** ok: [localhost] TASK [cloud-ec2 : Set facts about the regions] ************************************************************************************************************************************************************* ok: [localhost] TASK [cloud-ec2 : Set the default region] ****************************************************************************************************************************************************************** ok: [localhost] [cloud-ec2 : pause] What region should the server be located in? (https://docs.aws.amazon.com/general/latest/gr/rande.html#ec2_region) 1. ap-northeast-1 2. ap-northeast-2 3. ap-northeast-3 4. ap-south-1 5. ap-southeast-1 6. ap-southeast-2 7. ca-central-1 8. eu-central-1 9. eu-north-1 10. eu-west-1 11. eu-west-2 12. eu-west-3 13. sa-east-1 14. us-east-1 15. us-east-2 16. us-west-1 17. us-west-2 Enter the number of your desired region [14] : ^[[A^M TASK [cloud-ec2 : pause] *********************************************************************************************************************************************************************************** ok: [localhost] TASK [cloud-ec2 : Set algo_region and stack_name facts] **************************************************************************************************************************************************** ok: [localhost] TASK [cloud-ec2 : Locate official AMI for region] ********************************************************************************************************************************************************** ok: [localhost] TASK [cloud-ec2 : Set the ami id as a fact] **************************************************************************************************************************************************************** ok: [localhost] TASK [cloud-ec2 : Deploy the template] ********************************************************************************************************************************************************************* changed: [localhost] TASK [cloud-ec2 : set_fact] ******************************************************************************************************************************************************************************** ok: [localhost] TASK [Set subjectAltName as a fact] ************************************************************************************************************************************************************************ ok: [localhost] TASK [Add the server to an inventory group] **************************************************************************************************************************************************************** changed: [localhost] TASK [Additional variables for the server] ***************************************************************************************************************************************************************** changed: [localhost] TASK [Wait until SSH becomes ready...] ********************************************************************************************************************************************************************* ok: [localhost] TASK [Linux | set OS specific facts] *********************************************************************************************************************************************************************** ok: [localhost] TASK [Set config paths as facts] *************************************************************************************************************************************************************************** ok: [localhost] TASK [Update config paths] ********************************************************************************************************************************************************************************* changed: [localhost] TASK [debug] *********************************************************************************************************************************************************************************************** ok: [localhost] => { "IP_subject_alt_name": "44.240.141.177" } TASK [Wait 600 seconds for target connection to become reachable/usable] *********************************************************************************************************************************** ok: [localhost -> 44.240.141.177] => (item=44.240.141.177) PLAY [Configure the server and install required software] ************************************************************************************************************************************************** TASK [Wait until the cloud-init completed] ***************************************************************************************************************************************************************** ok: [44.240.141.177] TASK [Ensure the config directory exists] ****************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] TASK [Dump the ssh config] ********************************************************************************************************************************************************************************* changed: [44.240.141.177 -> localhost] TASK [common : Check the system] *************************************************************************************************************************************************************************** ok: [44.240.141.177] TASK [common : include_tasks] ****************************************************************************************************************************************************************************** included: /home/mgelbana/workspace/repos/open/algo/roles/common/tasks/ubuntu.yml for 44.240.141.177 TASK [common : Gather facts] ******************************************************************************************************************************************************************************* ok: [44.240.141.177] TASK [common : Install software updates] ******************************************************************************************************************************************************************* ok: [44.240.141.177] TASK [common : Check if reboot is required] **************************************************************************************************************************************************************** changed: [44.240.141.177] TASK [common : Install unattended-upgrades] **************************************************************************************************************************************************************** ok: [44.240.141.177] TASK [common : Configure unattended-upgrades] ************************************************************************************************************************************************************** changed: [44.240.141.177] TASK [common : Periodic upgrades configured] *************************************************************************************************************************************************************** changed: [44.240.141.177] TASK [common : Disable MOTD on login and SSHD] ************************************************************************************************************************************************************* changed: [44.240.141.177] => (item={'regexp': '^session.*optional.*pam_motd.so.*', 'line': '# MOTD DISABLED', 'file': '/etc/pam.d/login'}) changed: [44.240.141.177] => (item={'regexp': '^session.*optional.*pam_motd.so.*', 'line': '# MOTD DISABLED', 'file': '/etc/pam.d/sshd'}) [WARNING]: Module remote_tmp /root/.ansible/tmp did not exist and was created with a mode of 0700, this may cause issues when running as another user. To avoid this, create the remote_tmp dir with the correct permissions manually TASK [common : Ensure fallback resolvers are set] ********************************************************************************************************************************************************** changed: [44.240.141.177] [DEPRECATION WARNING]: Use 'ansible.utils.ipmath' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. TASK [common : Loopback for services configured] *********************************************************************************************************************************************************** changed: [44.240.141.177] TASK [common : systemd services enabled and started] ******************************************************************************************************************************************************* ok: [44.240.141.177] => (item=systemd-networkd) ok: [44.240.141.177] => (item=systemd-resolved) RUNNING HANDLER [common : restart systemd-networkd] ******************************************************************************************************************************************************** changed: [44.240.141.177] RUNNING HANDLER [common : restart systemd-resolved] ******************************************************************************************************************************************************** changed: [44.240.141.177] TASK [common : Check apparmor support] ********************************************************************************************************************************************************************* ok: [44.240.141.177] TASK [common : Set fact if apparmor enabled] *************************************************************************************************************************************************************** ok: [44.240.141.177] TASK [common : Define facts] ******************************************************************************************************************************************************************************* ok: [44.240.141.177] TASK [common : Set facts] ********************************************************************************************************************************************************************************** ok: [44.240.141.177] TASK [common : Set IPv6 support as a fact] ***************************************************************************************************************************************************************** ok: [44.240.141.177] TASK [common : Check size of MTU] ************************************************************************************************************************************************************************** ok: [44.240.141.177] TASK [common : Set OS specific facts] ********************************************************************************************************************************************************************** ok: [44.240.141.177] TASK [common : Install tools] ****************************************************************************************************************************************************************************** changed: [44.240.141.177] TASK [common : include_tasks] ****************************************************************************************************************************************************************************** included: /home/mgelbana/workspace/repos/open/algo/roles/common/tasks/iptables.yml for 44.240.141.177 [DEPRECATION WARNING]: Use 'ansible.utils.ipmath' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. TASK [common : Iptables configured] ************************************************************************************************************************************************************************ changed: [44.240.141.177] => (item={'src': 'rules.v4.j2', 'dest': '/etc/iptables/rules.v4'}) [DEPRECATION WARNING]: Use 'ansible.utils.ipaddr' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. [DEPRECATION WARNING]: Use 'ansible.utils.next_nth_usable' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. [DEPRECATION WARNING]: Use 'ansible.utils.ipmath' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. TASK [common : Iptables configured] ************************************************************************************************************************************************************************ changed: [44.240.141.177] => (item={'src': 'rules.v6.j2', 'dest': '/etc/iptables/rules.v6'}) TASK [common : Sysctl tuning] ****************************************************************************************************************************************************************************** changed: [44.240.141.177] => (item={'item': 'net.ipv4.ip_forward', 'value': 1}) changed: [44.240.141.177] => (item={'item': 'net.ipv4.conf.all.forwarding', 'value': 1}) changed: [44.240.141.177] => (item={'item': 'net.ipv6.conf.all.forwarding', 'value': 1}) RUNNING HANDLER [common : restart iptables] **************************************************************************************************************************************************************** changed: [44.240.141.177] TASK [dns : Include tasks for Ubuntu] ********************************************************************************************************************************************************************** included: /home/mgelbana/workspace/repos/open/algo/roles/dns/tasks/ubuntu.yml for 44.240.141.177 TASK [dns : Install dnscrypt-proxy] ************************************************************************************************************************************************************************ changed: [44.240.141.177] TASK [dns : Ubuntu | Configure AppArmor policy for dnscrypt-proxy] ***************************************************************************************************************************************** changed: [44.240.141.177] TASK [dns : Ubuntu | Enforce the dnscrypt-proxy AppArmor policy] ******************************************************************************************************************************************* ok: [44.240.141.177] TASK [dns : Ubuntu | Ensure that the dnscrypt-proxy service directory exist] ******************************************************************************************************************************* changed: [44.240.141.177] TASK [dns : Ubuntu | Add custom requirements to successfully start the unit] ******************************************************************************************************************************* changed: [44.240.141.177] TASK [dns : dnscrypt-proxy ip-blacklist configured] ******************************************************************************************************************************************************** changed: [44.240.141.177] [DEPRECATION WARNING]: Use 'ansible.utils.ipmath' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. TASK [dns : dnscrypt-proxy configured] ********************************************************************************************************************************************************************* changed: [44.240.141.177] [WARNING]: flush_handlers task does not support when conditional RUNNING HANDLER [dns : restart dnscrypt-proxy] ************************************************************************************************************************************************************* changed: [44.240.141.177] TASK [dns : dnscrypt-proxy enabled and started] ************************************************************************************************************************************************************ ok: [44.240.141.177] TASK [wireguard : Ensure the required directories exist] *************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=configs/44.240.141.177/wireguard//.pki//preshared) changed: [44.240.141.177 -> localhost] => (item=configs/44.240.141.177/wireguard//.pki//private) changed: [44.240.141.177 -> localhost] => (item=configs/44.240.141.177/wireguard//.pki//public) changed: [44.240.141.177 -> localhost] => (item=configs/44.240.141.177/wireguard//apple/ios) changed: [44.240.141.177 -> localhost] => (item=configs/44.240.141.177/wireguard//apple/macos) TASK [wireguard : Include tasks for Ubuntu] **************************************************************************************************************************************************************** included: /home/mgelbana/workspace/repos/open/algo/roles/wireguard/tasks/ubuntu.yml for 44.240.141.177 TASK [wireguard : WireGuard installed] ********************************************************************************************************************************************************************* changed: [44.240.141.177] TASK [wireguard : Set OS specific facts] ******************************************************************************************************************************************************************* ok: [44.240.141.177] TASK [wireguard : Generate private keys] ******************************************************************************************************************************************************************* changed: [44.240.141.177] => (item=phone) changed: [44.240.141.177] => (item=laptop) changed: [44.240.141.177] => (item=desktop) changed: [44.240.141.177] => (item=44.240.141.177) TASK [wireguard : Save private keys] *********************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] TASK [wireguard : Touch the lock file] ********************************************************************************************************************************************************************* changed: [44.240.141.177] => (item=phone) changed: [44.240.141.177] => (item=laptop) changed: [44.240.141.177] => (item=desktop) changed: [44.240.141.177] => (item=44.240.141.177) TASK [wireguard : Generate preshared keys] ***************************************************************************************************************************************************************** changed: [44.240.141.177] => (item=phone) changed: [44.240.141.177] => (item=laptop) changed: [44.240.141.177] => (item=desktop) changed: [44.240.141.177] => (item=44.240.141.177) TASK [wireguard : Save preshared keys] ********************************************************************************************************************************************************************* changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] TASK [wireguard : Touch the preshared lock file] *********************************************************************************************************************************************************** changed: [44.240.141.177] => (item=phone) changed: [44.240.141.177] => (item=laptop) changed: [44.240.141.177] => (item=desktop) changed: [44.240.141.177] => (item=44.240.141.177) TASK [wireguard : Generate public keys] ******************************************************************************************************************************************************************** ok: [44.240.141.177] => (item=phone) ok: [44.240.141.177] => (item=laptop) ok: [44.240.141.177] => (item=desktop) ok: [44.240.141.177] => (item=44.240.141.177) TASK [wireguard : Save public keys] ************************************************************************************************************************************************************************ changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] TASK [wireguard : WireGuard user list updated] ************************************************************************************************************************************************************* changed: [44.240.141.177 -> localhost] => (item=phone) changed: [44.240.141.177 -> localhost] => (item=laptop) changed: [44.240.141.177 -> localhost] => (item=desktop) TASK [wireguard : set_fact] ******************************************************************************************************************************************************************************** ok: [44.240.141.177 -> localhost] [DEPRECATION WARNING]: Use 'ansible.utils.ipmath' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. TASK [wireguard : WireGuard users config generated] ******************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=[0, 'phone']) changed: [44.240.141.177 -> localhost] => (item=[1, 'laptop']) changed: [44.240.141.177 -> localhost] => (item=[2, 'desktop']) TASK [wireguard : include_tasks] *************************************************************************************************************************************************************************** included: /home/mgelbana/workspace/repos/open/algo/roles/wireguard/tasks/mobileconfig.yml for 44.240.141.177 => (item=ios) included: /home/mgelbana/workspace/repos/open/algo/roles/wireguard/tasks/mobileconfig.yml for 44.240.141.177 => (item=macos) [DEPRECATION WARNING]: Use 'ansible.utils.ipmath' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. TASK [wireguard : WireGuard apple mobileconfig generated] ************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=[0, 'phone']) changed: [44.240.141.177 -> localhost] => (item=[1, 'laptop']) changed: [44.240.141.177 -> localhost] => (item=[2, 'desktop']) [DEPRECATION WARNING]: Use 'ansible.utils.ipmath' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. TASK [wireguard : WireGuard apple mobileconfig generated] ************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=[0, 'phone']) changed: [44.240.141.177 -> localhost] => (item=[1, 'laptop']) changed: [44.240.141.177 -> localhost] => (item=[2, 'desktop']) [DEPRECATION WARNING]: Use 'ansible.utils.ipmath' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. TASK [wireguard : Generate QR codes] *********************************************************************************************************************************************************************** ok: [44.240.141.177 -> localhost] => (item=[0, 'phone']) ok: [44.240.141.177 -> localhost] => (item=[1, 'laptop']) ok: [44.240.141.177 -> localhost] => (item=[2, 'desktop']) [DEPRECATION WARNING]: Use 'ansible.utils.ipv4' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. [DEPRECATION WARNING]: Use 'ansible.utils.ipmath' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. [DEPRECATION WARNING]: Use 'ansible.utils.ipv6' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. [DEPRECATION WARNING]: Use 'ansible.utils.ipaddr' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. TASK [wireguard : WireGuard configured] ******************************************************************************************************************************************************************** changed: [44.240.141.177] TASK [wireguard : WireGuard enabled and started] *********************************************************************************************************************************************************** changed: [44.240.141.177] RUNNING HANDLER [wireguard : restart wireguard] ************************************************************************************************************************************************************ changed: [44.240.141.177] TASK [strongswan : include_tasks] ************************************************************************************************************************************************************************** included: /home/mgelbana/workspace/repos/open/algo/roles/strongswan/tasks/ubuntu.yml for 44.240.141.177 TASK [strongswan : Set OS specific facts] ****************************************************************************************************************************************************************** ok: [44.240.141.177] TASK [strongswan : Ubuntu | Install strongSwan] ************************************************************************************************************************************************************ changed: [44.240.141.177] TASK [strongswan : Ubuntu | Charon profile for apparmor configured] **************************************************************************************************************************************** changed: [44.240.141.177] TASK [strongswan : Ubuntu | Enforcing ipsec with apparmor] ************************************************************************************************************************************************* ok: [44.240.141.177] => (item=/usr/lib/ipsec/charon) ok: [44.240.141.177] => (item=/usr/lib/ipsec/lookip) ok: [44.240.141.177] => (item=/usr/lib/ipsec/stroke) TASK [strongswan : Ubuntu | Enable services] *************************************************************************************************************************************************************** ok: [44.240.141.177] => (item=apparmor) ok: [44.240.141.177] => (item=strongswan-starter) ok: [44.240.141.177] => (item=netfilter-persistent) TASK [strongswan : Ubuntu | Ensure that the strongswan service directory exists] *************************************************************************************************************************** changed: [44.240.141.177] TASK [strongswan : Ubuntu | Setup the cgroup limitations for the ipsec daemon] ***************************************************************************************************************************** changed: [44.240.141.177] TASK [strongswan : Ensure that the strongswan user exists] ************************************************************************************************************************************************* ok: [44.240.141.177] TASK [strongswan : Install strongSwan] ********************************************************************************************************************************************************************* ok: [44.240.141.177] TASK [strongswan : Setup the config files from our templates] ********************************************************************************************************************************************** changed: [44.240.141.177] => (item={'src': 'strongswan.conf.j2', 'dest': 'strongswan.conf', 'owner': 'root', 'group': 'root', 'mode': '0644'}) [DEPRECATION WARNING]: Use 'ansible.utils.ipmath' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. changed: [44.240.141.177] => (item={'src': 'ipsec.conf.j2', 'dest': 'ipsec.conf', 'owner': 'root', 'group': 'root', 'mode': '0644'}) changed: [44.240.141.177] => (item={'src': 'ipsec.secrets.j2', 'dest': 'ipsec.secrets', 'owner': 'strongswan', 'group': 'root', 'mode': '0600'}) changed: [44.240.141.177] => (item={'src': 'charon.conf.j2', 'dest': 'strongswan.d/charon.conf', 'owner': 'root', 'group': 'root', 'mode': '0644'}) TASK [strongswan : Get loaded plugins] ********************************************************************************************************************************************************************* ok: [44.240.141.177] TASK [strongswan : Disable unneeded plugins] *************************************************************************************************************************************************************** changed: [44.240.141.177] => (item=connmark) changed: [44.240.141.177] => (item=eap-mschapv2) changed: [44.240.141.177] => (item=rc2) changed: [44.240.141.177] => (item=mgf1) changed: [44.240.141.177] => (item=updown) changed: [44.240.141.177] => (item=gmp) changed: [44.240.141.177] => (item=aesni) changed: [44.240.141.177] => (item=md5) changed: [44.240.141.177] => (item=counters) changed: [44.240.141.177] => (item=agent) changed: [44.240.141.177] => (item=drbg) changed: [44.240.141.177] => (item=fips-prf) changed: [44.240.141.177] => (item=sha1) changed: [44.240.141.177] => (item=bypass-lan) changed: [44.240.141.177] => (item=xcbc) changed: [44.240.141.177] => (item=dnskey) changed: [44.240.141.177] => (item=xauth-generic) changed: [44.240.141.177] => (item=sshkey) changed: [44.240.141.177] => (item=resolve) changed: [44.240.141.177] => (item=attr) changed: [44.240.141.177] => (item=pkcs1) changed: [44.240.141.177] => (item=constraints) TASK [strongswan : Ensure that required plugins are enabled] *********************************************************************************************************************************************** changed: [44.240.141.177] => (item=kernel-netlink) changed: [44.240.141.177] => (item=sha2) changed: [44.240.141.177] => (item=revocation) changed: [44.240.141.177] => (item=random) changed: [44.240.141.177] => (item=pkcs8) changed: [44.240.141.177] => (item=pkcs7) changed: [44.240.141.177] => (item=nonce) changed: [44.240.141.177] => (item=gcm) changed: [44.240.141.177] => (item=pkcs12) changed: [44.240.141.177] => (item=aes) changed: [44.240.141.177] => (item=pubkey) changed: [44.240.141.177] => (item=hmac) changed: [44.240.141.177] => (item=pem) changed: [44.240.141.177] => (item=socket-default) changed: [44.240.141.177] => (item=pgp) changed: [44.240.141.177] => (item=stroke) changed: [44.240.141.177] => (item=x509) changed: [44.240.141.177] => (item=openssl) TASK [strongswan : debug] ********************************************************************************************************************************************************************************** ok: [44.240.141.177 -> localhost] => { "subjectAltName": "IP:44.240.141.177,IP:2600:1f14:b07:cc00:1794:68e8:5159:5845" } TASK [strongswan : Ensure the pki directories exist] ******************************************************************************************************************************************************* changed: [44.240.141.177 -> localhost] => (item=ecparams) changed: [44.240.141.177 -> localhost] => (item=certs) changed: [44.240.141.177 -> localhost] => (item=crl) changed: [44.240.141.177 -> localhost] => (item=newcerts) changed: [44.240.141.177 -> localhost] => (item=private) changed: [44.240.141.177 -> localhost] => (item=public) changed: [44.240.141.177 -> localhost] => (item=reqs) TASK [strongswan : Ensure the config directories exist] **************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=apple) changed: [44.240.141.177 -> localhost] => (item=manual) TASK [strongswan : Ensure the files exist] ***************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=.rnd) changed: [44.240.141.177 -> localhost] => (item=private/.rnd) changed: [44.240.141.177 -> localhost] => (item=index.txt) changed: [44.240.141.177 -> localhost] => (item=index.txt.attr) changed: [44.240.141.177 -> localhost] => (item=serial) TASK [strongswan : Generate the openssl server configs] **************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] TASK [strongswan : Build the CA pair] ********************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] TASK [strongswan : Copy the CA certificate] **************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] TASK [strongswan : Generate the serial number] ************************************************************************************************************************************************************* changed: [44.240.141.177 -> localhost] TASK [strongswan : Build the server pair] ****************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] TASK [strongswan : Build the client's pair] **************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=phone) changed: [44.240.141.177 -> localhost] => (item=laptop) changed: [44.240.141.177 -> localhost] => (item=desktop) TASK [strongswan : Build openssh public keys] ************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=phone) changed: [44.240.141.177 -> localhost] => (item=laptop) changed: [44.240.141.177 -> localhost] => (item=desktop) TASK [strongswan : Build the client's p12] ***************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=phone) changed: [44.240.141.177 -> localhost] => (item=laptop) changed: [44.240.141.177 -> localhost] => (item=desktop) TASK [strongswan : Build the client's p12 with the CA cert included] *************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=phone) changed: [44.240.141.177 -> localhost] => (item=laptop) changed: [44.240.141.177 -> localhost] => (item=desktop) TASK [strongswan : Copy the p12 certificates] ************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=phone) changed: [44.240.141.177 -> localhost] => (item=laptop) changed: [44.240.141.177 -> localhost] => (item=desktop) TASK [strongswan : Get active users] *********************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] TASK [strongswan : Copy the keys to the strongswan directory] ********************************************************************************************************************************************** changed: [44.240.141.177] => (item={'src': 'cacert.pem', 'dest': 'cacerts/ca.crt', 'owner': 'strongswan', 'group': 'root', 'mode': '0600'}) changed: [44.240.141.177] => (item={'src': 'certs/44.240.141.177.crt', 'dest': 'certs/44.240.141.177.crt', 'owner': 'strongswan', 'group': 'root', 'mode': '0600'}) changed: [44.240.141.177] => (item={'src': 'private/44.240.141.177.key', 'dest': 'private/44.240.141.177.key', 'owner': 'strongswan', 'group': 'root', 'mode': '0600'}) TASK [strongswan : Register p12 PayloadContent] ************************************************************************************************************************************************************ ok: [44.240.141.177 -> localhost] => (item=phone) ok: [44.240.141.177 -> localhost] => (item=laptop) ok: [44.240.141.177 -> localhost] => (item=desktop) TASK [strongswan : Set facts for mobileconfigs] ************************************************************************************************************************************************************ ok: [44.240.141.177 -> localhost] TASK [strongswan : Build the mobileconfigs] **************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] => (item=None) changed: [44.240.141.177 -> localhost] TASK [strongswan : Build the client ipsec config file] ***************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=phone) changed: [44.240.141.177 -> localhost] => (item=laptop) changed: [44.240.141.177 -> localhost] => (item=desktop) TASK [strongswan : Build the client ipsec secret file] ***************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] => (item=phone) changed: [44.240.141.177 -> localhost] => (item=laptop) changed: [44.240.141.177 -> localhost] => (item=desktop) TASK [strongswan : Restrict permissions for the local private directories] ********************************************************************************************************************************* ok: [44.240.141.177 -> localhost] TASK [strongswan : strongSwan started] ********************************************************************************************************************************************************************* ok: [44.240.141.177] RUNNING HANDLER [strongswan : restart strongswan] ********************************************************************************************************************************************************** changed: [44.240.141.177] RUNNING HANDLER [strongswan : daemon-reload] *************************************************************************************************************************************************************** ok: [44.240.141.177] TASK [Dump the configuration] ****************************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] TASK [Linux | Delete the PKI directory] ******************************************************************************************************************************************************************** changed: [44.240.141.177 -> localhost] [DEPRECATION WARNING]: Use 'ansible.utils.ipmath' module instead. This feature will be removed from ansible.netcommon in a release after 2024-01-01. Deprecation warnings can be disabled by setting deprecation_warnings=False in ansible.cfg. TASK [debug] *********************************************************************************************************************************************************************************************** ok: [44.240.141.177] => { "msg": [ [ "\"# Congratulations! #\"", "\"# Your Algo server is running. #\"", "\"# Config files and certificates are in the ./configs/ directory. #\"", "\"# Go to https://whoer.net/ after connecting #\"", "\"# and ensure that all your traffic passes through the VPN. #\"", "\"# Local DNS resolver 172.24.175.190, fd00::8:afbe #\"", "" ], " \"# The p12 and SSH keys password for new users is @@bh8VT8_ #\"\n", " ", " \"# Shell access: ssh -F configs/44.240.141.177/ssh_config algo #\"\n" ] } PLAY RECAP ************************************************************************************************************************************************************************************************* 44.240.141.177 : ok=105 changed=66 unreachable=0 failed=0 skipped=38 rescued=0 ignored=0 localhost : ok=46 changed=6 unreachable=0 failed=0 skipped=7 rescued=0 ignored=0
Describe the bug
Even thought I following the steps mentioned here, I'm not able to access the internet after enabling Wireguard on my laptop.
Full log