sing-box/docs/configuration/outbound/wireguard.md

143 lines
2.4 KiB
Markdown
Raw Permalink Normal View History

2022-08-17 07:19:10 +00:00
### Structure
```json
{
2022-08-31 05:21:29 +00:00
"type": "wireguard",
"tag": "wireguard-out",
"server": "127.0.0.1",
"server_port": 1080,
2022-09-09 07:40:35 +00:00
"system_interface": false,
"interface_name": "wg0",
2022-08-31 05:21:29 +00:00
"local_address": [
"10.0.0.2/32"
],
"private_key": "YNXtAzepDqRv9H52osJVDQnznT5AM11eCK3ESpwSt04=",
"peers": [
{
"server": "127.0.0.1",
"server_port": 1080,
"public_key": "Z1XXLsKYkYxuiYjJIkRvtIKFepCYHTgON+GwPq7SOV4=",
"pre_shared_key": "31aIhAPwktDGpH4JDhA8GNvjFXEf/a6+UaQRyOAiyfM=",
"allowed_ips": [
"0.0.0.0/0"
],
"reserved": [0, 0, 0]
}
],
2022-08-31 05:21:29 +00:00
"peer_public_key": "Z1XXLsKYkYxuiYjJIkRvtIKFepCYHTgON+GwPq7SOV4=",
"pre_shared_key": "31aIhAPwktDGpH4JDhA8GNvjFXEf/a6+UaQRyOAiyfM=",
2022-10-29 10:00:05 +00:00
"reserved": [0, 0, 0],
"workers": 4,
2022-08-31 05:21:29 +00:00
"mtu": 1408,
"network": "tcp",
... // Dial Fields
2022-08-17 07:19:10 +00:00
}
```
2022-08-19 11:02:32 +00:00
!!! warning ""
2022-08-23 15:15:56 +00:00
WireGuard is not included by default, see [Installation](/#installation).
2022-08-19 11:02:32 +00:00
2022-09-15 04:20:38 +00:00
!!! warning ""
gVisor, which is required by the unprivileged WireGuard is not included by default, see [Installation](/#installation).
2022-08-31 05:21:29 +00:00
### Fields
2022-08-17 07:19:10 +00:00
#### server
==Required if multi-peer disabled==
2022-08-17 07:19:10 +00:00
The server address.
#### server_port
==Required if multi-peer disabled==
2022-08-17 07:19:10 +00:00
The server port.
2022-09-09 07:40:35 +00:00
#### system_interface
Use system tun support.
2022-09-15 04:20:38 +00:00
Requires privilege and cannot conflict with system interfaces.
Forced if gVisor not included in the build.
2022-09-09 07:40:35 +00:00
#### interface_name
Custom device name when `system_interface` enabled.
2022-08-17 07:19:10 +00:00
#### local_address
==Required==
2022-09-05 16:15:09 +00:00
List of IP (v4 or v6) address prefixes to be assigned to the interface.
2022-08-17 07:19:10 +00:00
#### private_key
==Required==
WireGuard requires base64-encoded public and private keys. These can be generated using the wg(8) utility:
```shell
wg genkey
echo "private key" || wg pubkey
```
#### peers
Multi-peer support.
If enabled, `server, server_port, peer_public_key, pre_shared_key` will be ignored.
#### peers.allowed_ips
WireGuard allowed IPs.
#### peers.reserved
WireGuard reserved field bytes.
`$outbound.reserved` will be used if empty.
2022-08-17 07:19:10 +00:00
#### peer_public_key
==Required if multi-peer disabled==
2022-08-17 07:19:10 +00:00
WireGuard peer public key.
#### pre_shared_key
WireGuard pre-shared key.
2022-10-29 10:00:05 +00:00
#### reserved
WireGuard reserved field bytes.
#### workers
WireGuard worker count.
CPU count is used by default.
2022-08-17 07:19:10 +00:00
#### mtu
WireGuard MTU.
1408 will be used if empty.
2022-08-17 07:19:10 +00:00
#### network
Enabled network
One of `tcp` `udp`.
Both is enabled by default.
### Dial Fields
2022-08-31 05:21:29 +00:00
See [Dial Fields](/configuration/shared/dial) for details.