使用 WireGuard 打通家庭网与公司网

远程办公时访问公司内网是许多开发者的刚需。本文记录使用 WireGuard 打通家庭网络与公司网络的完整过程,包括网络拓扑设计、OpenWrt 配置、跳板机部署和安全隔离策略。

一、背景与需求

当需要远程访问公司内网时,常见方案有两种:远程桌面(TeamViewer/RDP)和公司 VPN。远程桌面带宽消耗大、文件传输不便;公司 VPN 路由表覆盖、客户端冲突是两个实际问题。

解决思路:不让笔记本直连 VPN,而是让家庭网络的 OpenWrt 路由器通过 WireGuard 与公司内网建立永久隧道。所有设备通过家庭网络即可访问公司内网,无需安装 VPN 客户端。

二、方案设计

网络拓扑:

家庭网络 (192.168.1.0/24)
┌─────────┐
│ OpenWrt │── WireGuard 隧道 ──┐
│ 路由器   │                    │
└────┬────┘                    │
     │                          │
┌────┴────┐            ┌───────▼────────┐
│ 笔记本   │            │  公司跳板机      │
│ (无需VPN)│           │  (CentOS VM)    │
└─────────┘            └───────┬────────┘
                               │
                        ┌──────▼───────┐
                        │ 公司内网服务   │
                        │ GitLab/DNS/..│
                        └──────────────┘

核心原则:单向访问——只允许家庭网→公司网,禁止反向。

三、环境准备

家庭网需要公网 IP(向运营商申请或购买 VPS 做端口转发)。公司需要一台 24 小时在线的跳板机,使用 CentOS 7 VM(1C1G)作为 WireGuard 客户端。

四、OpenWrt 端配置

4.1 Guest 防火墙区域

# /etc/config/firewall
config zone
    option name     'guest'
    option network  'wg0'
    option input    'REJECT'
    option output   'ACCEPT'
    option forward  'REJECT'

config forwarding
    option src      'guest'
    option dest     'wan'

效果:wg0 上的 Peer 只能出站到 WAN,无法访问家庭内网设备。

4.2 WireGuard 接口

# /etc/config/network
config interface 'wg0'
    option proto    'wireguard'
    option listen_port '51820'
    option private_key '<OpenWrt 私钥>'
    list addresses  '10.254.254.1/24'

config wireguard_wg0
    option public_key   '<跳板机公钥>'
    option description  '公司跳板机'
    list allowed_ips    '10.0.1.0/24'
    list allowed_ips    '10.0.2.0/24'
    list allowed_ips    '10.0.1.53/32'

公司 DNS 服务器 IP 必须包含在 AllowedIPs 中,否则域名解析不会进入隧道。

4.3 DNS 转发

# /etc/dnsmasq.conf
server=/example.corp/10.0.1.53

重启:/etc/init.d/dnsmasq restart

五、跳板机端配置

5.1 网络配置

nmcli con add con-name eth0 ifname eth0 type ethernet
nmcli con mod eth0 ipv4.addresses 10.0.1.100/24
nmcli con mod eth0 ipv4.gateway 10.0.1.1
nmcli con mod eth0 ipv4.dns "10.0.1.53"
nmcli con mod eth0 ipv4.method manual
nmcli con up eth0

5.2 安装与配置 WireGuard

yum install epel-release -y && yum install wireguard-tools -y
# /etc/wireguard/wg0.conf
[Interface]
Address = 10.254.254.2/24
PrivateKey = <跳板机私钥>

[Peer]
PublicKey = <OpenWrt 公钥>
Endpoint = <家庭公网IP>:51820
AllowedIPs = 10.254.254.0/24
PersistentKeepalive = 25

AllowedIPs 只指定 WG 网段而非 0.0.0.0/0,确保非隧道流量保持原有路由。

5.3 启动

systemctl enable wg-quick@wg0
systemctl start wg-quick@wg0

六、安全隔离

# 允许 LAN → wg0
iptables -A FORWARD -i br-lan -o wg0 -j ACCEPT
# 只允许已建立连接返回
iptables -A FORWARD -i wg0 -o br-lan -m state --state RELATED,ESTABLISHED -j ACCEPT
# 拒绝新连接
iptables -A FORWARD -i wg0 -o br-lan -j REJECT

跳板机加固:禁用密码登录、限制入站来源、每季度轮换密钥。

七、验证与排错

ping 10.254.254.2              # 跳板机连通性
ping 10.0.1.53                 # 公司内网连通性
nslookup gitlab.example.corp   # DNS 解析
wg show wg0                    # 隧道状态
现象 排查方向
无 latest handshake NAT 阻断 UDP 或 Endpoint 不可达
能 ping IP 但域名不通 dnsmasq 未配置公司域名转发
部分服务无法访问 AllowedIPs 遗漏目标 IP

总结

对比维度 传统 VPN 客户端 本方案
终端安装 每台设备需安装 零终端配置
路由冲突 VPN 覆盖路由表 家庭网络路由不变
多设备支持 逐个配置 所有家庭设备自动可用

WireGuard 的小代码量和简洁配置使其成为这类场景的理想选择。核心思路:将 VPN 隧道从终端设备上移到网络网关。