远程办公时访问公司内网是许多开发者的刚需。本文记录使用 WireGuard 打通家庭网络与公司网络的完整过程,包括网络拓扑设计、OpenWrt 配置、跳板机部署和安全隔离策略。
一、背景与需求
当需要远程访问公司内网时,常见方案有两种:远程桌面(TeamViewer/RDP)和公司 VPN。远程桌面带宽消耗大、文件传输不便;公司 VPN 路由表覆盖、客户端冲突是两个实际问题。
解决思路:不让笔记本直连 VPN,而是让家庭网络的 OpenWrt 路由器通过 WireGuard 与公司内网建立永久隧道。所有设备通过家庭网络即可访问公司内网,无需安装 VPN 客户端。
二、方案设计
网络拓扑:
家庭网络 (192.168.1.0/24)
┌─────────┐
│ OpenWrt │── WireGuard 隧道 ──┐
│ 路由器 │ │
└────┬────┘ │
│ │
┌────┴────┐ ┌───────▼────────┐
│ 笔记本 │ │ 公司跳板机 │
│ (无需VPN)│ │ (CentOS VM) │
└─────────┘ └───────┬────────┘
│
┌──────▼───────┐
│ 公司内网服务 │
│ GitLab/DNS/..│
└──────────────┘
核心原则:单向访问——只允许家庭网→公司网,禁止反向。
三、环境准备
家庭网需要公网 IP(向运营商申请或购买 VPS 做端口转发)。公司需要一台 24 小时在线的跳板机,使用 CentOS 7 VM(1C1G)作为 WireGuard 客户端。
四、OpenWrt 端配置
4.1 Guest 防火墙区域
# /etc/config/firewall
config zone
option name 'guest'
option network 'wg0'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
config forwarding
option src 'guest'
option dest 'wan'
效果:wg0 上的 Peer 只能出站到 WAN,无法访问家庭内网设备。
4.2 WireGuard 接口
# /etc/config/network
config interface 'wg0'
option proto 'wireguard'
option listen_port '51820'
option private_key '<OpenWrt 私钥>'
list addresses '10.254.254.1/24'
config wireguard_wg0
option public_key '<跳板机公钥>'
option description '公司跳板机'
list allowed_ips '10.0.1.0/24'
list allowed_ips '10.0.2.0/24'
list allowed_ips '10.0.1.53/32'
公司 DNS 服务器 IP 必须包含在 AllowedIPs 中,否则域名解析不会进入隧道。
4.3 DNS 转发
# /etc/dnsmasq.conf
server=/example.corp/10.0.1.53
重启:/etc/init.d/dnsmasq restart
五、跳板机端配置
5.1 网络配置
nmcli con add con-name eth0 ifname eth0 type ethernet
nmcli con mod eth0 ipv4.addresses 10.0.1.100/24
nmcli con mod eth0 ipv4.gateway 10.0.1.1
nmcli con mod eth0 ipv4.dns "10.0.1.53"
nmcli con mod eth0 ipv4.method manual
nmcli con up eth0
5.2 安装与配置 WireGuard
yum install epel-release -y && yum install wireguard-tools -y
# /etc/wireguard/wg0.conf
[Interface]
Address = 10.254.254.2/24
PrivateKey = <跳板机私钥>
[Peer]
PublicKey = <OpenWrt 公钥>
Endpoint = <家庭公网IP>:51820
AllowedIPs = 10.254.254.0/24
PersistentKeepalive = 25
AllowedIPs 只指定 WG 网段而非 0.0.0.0/0,确保非隧道流量保持原有路由。
5.3 启动
systemctl enable wg-quick@wg0
systemctl start wg-quick@wg0
六、安全隔离
# 允许 LAN → wg0
iptables -A FORWARD -i br-lan -o wg0 -j ACCEPT
# 只允许已建立连接返回
iptables -A FORWARD -i wg0 -o br-lan -m state --state RELATED,ESTABLISHED -j ACCEPT
# 拒绝新连接
iptables -A FORWARD -i wg0 -o br-lan -j REJECT
跳板机加固:禁用密码登录、限制入站来源、每季度轮换密钥。
七、验证与排错
ping 10.254.254.2 # 跳板机连通性
ping 10.0.1.53 # 公司内网连通性
nslookup gitlab.example.corp # DNS 解析
wg show wg0 # 隧道状态
| 现象 | 排查方向 |
|---|---|
| 无 latest handshake | NAT 阻断 UDP 或 Endpoint 不可达 |
| 能 ping IP 但域名不通 | dnsmasq 未配置公司域名转发 |
| 部分服务无法访问 | AllowedIPs 遗漏目标 IP |
总结
| 对比维度 | 传统 VPN 客户端 | 本方案 |
|---|---|---|
| 终端安装 | 每台设备需安装 | 零终端配置 |
| 路由冲突 | VPN 覆盖路由表 | 家庭网络路由不变 |
| 多设备支持 | 逐个配置 | 所有家庭设备自动可用 |
WireGuard 的小代码量和简洁配置使其成为这类场景的理想选择。核心思路:将 VPN 隧道从终端设备上移到网络网关。