<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>slash-root.fr</title><link>https://beta.slash-root.fr/</link><description>Recent content on slash-root.fr</description><generator>Hugo -- gohugo.io</generator><language>fr-fr</language><lastBuildDate>Wed, 22 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://beta.slash-root.fr/index.xml" rel="self" type="application/rss+xml"/><item><title>OPNsense : Serveur WireGuard et client KDE en split tunnel</title><link>https://beta.slash-root.fr/post/opnsense-serveur-wireguard-et-client-kde-en-split-tunnel/</link><pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate><guid>https://beta.slash-root.fr/post/opnsense-serveur-wireguard-et-client-kde-en-split-tunnel/</guid><description>&lt;img src="https://beta.slash-root.fr/post/opnsense-serveur-wireguard-et-client-kde-en-split-tunnel/cover.png" alt="Featured image of post OPNsense : Serveur WireGuard et client KDE en split tunnel" /&gt;&lt;p&gt;L&amp;rsquo;objectif est simple : pouvoir depuis mon laptop KDE joindre les machines du LAN derrière un OPNsense via WireGuard, sans pour autant envoyer tout mon trafic internet dans le tunnel. Autrement dit, un split tunnel propre : seul le réseau derrière le pare-feu passe par le VPN, le reste reste sur ma connexion classique.&lt;/p&gt;
&lt;p&gt;Depuis OPNsense 24.1, WireGuard est intégré au core. Plus besoin de jouer avec le plugin &lt;code&gt;os-wireguard&lt;/code&gt;, c&amp;rsquo;est déjà ça de gagné. La procédure reste assez directe, mais quelques points de routage sont à surveiller pour ne pas finir avec tout le trafic déporté sur le VPN.&lt;/p&gt;
&lt;p&gt;Voici le plan utilisé dans cet article :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LAN derrière OPNsense&lt;/strong&gt; : &lt;code&gt;192.168.1.0/24&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Réseau du tunnel&lt;/strong&gt; : &lt;code&gt;10.10.10.0/24&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;OPNsense (interface WireGuard, IP au sein du tunnel VPN)&lt;/strong&gt; : &lt;code&gt;10.10.10.1/24&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Client KDE (IP au sein du tunnel VPN)&lt;/strong&gt; : &lt;code&gt;10.10.10.2/32&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Port UDP&lt;/strong&gt; : &lt;code&gt;51820&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;

 &lt;blockquote&gt;
 &lt;p&gt;&lt;strong&gt;Note :&lt;/strong&gt; cet article traite uniquement l&amp;rsquo;&lt;strong&gt;IPv4&lt;/strong&gt;. L&amp;rsquo;&lt;strong&gt;IPv6&lt;/strong&gt; n&amp;rsquo;est pas abordé ici.&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;p&gt;Let&amp;rsquo;s go !!!&lt;/p&gt;
&lt;h2 id="prérequis"&gt;&lt;a href="#pr%c3%a9requis" class="header-anchor"&gt;&lt;/a&gt;Prérequis
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;OPNsense accessible depuis Internet : IP publique sur son interface WAN, ou redirection du port UDP &lt;code&gt;51820&lt;/code&gt; depuis le routeur amont.&lt;/li&gt;
&lt;li&gt;Le client KDE dispose de &lt;code&gt;wireguard-tools&lt;/code&gt; et d&amp;rsquo;un NetworkManager gérant nativement WireGuard (à partir de la v1.16, ça marche out of the box sur la plupart des distros récentes).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="partie-1--opnsense-le-serveur-wireguard"&gt;&lt;a href="#partie-1--opnsense-le-serveur-wireguard" class="header-anchor"&gt;&lt;/a&gt;Partie 1 : OPNsense, le serveur WireGuard
&lt;/h2&gt;&lt;h3 id="création-de-linstance"&gt;&lt;a href="#cr%c3%a9ation-de-linstance" class="header-anchor"&gt;&lt;/a&gt;Création de l&amp;rsquo;instance
&lt;/h3&gt;&lt;p&gt;On commence par générer le serveur :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Aller dans &lt;strong&gt;VPN &amp;gt; WireGuard &amp;gt; Instances&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Cliquer sur &lt;strong&gt;+&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Remplir comme suit :&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Enabled : Coché
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Name : HomeWireGuard
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Public Key : Générer via la roue crantée
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Private Key : Générer en même temps
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Listen Port : 51820
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;MTU : 1420 (1412 si PPPoE)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Tunnel Address : 10.10.10.1/24
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Peers : Laisser vide pour l&amp;#39;instant
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Disable Routes : Décoché
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Le MTU de &lt;code&gt;1420&lt;/code&gt; tient compte de l&amp;rsquo;overhead d&amp;rsquo;encapsulation WireGuard (en-têtes IP/UDP/WireGuard, soit environ 60 à 80 octets). Ainsi, le paquet final reste sous les 1500 octets d&amp;rsquo;un lien Ethernet standard. En PPPoE, le MTU physique est souvent 1492, d&amp;rsquo;où la valeur &lt;code&gt;1412&lt;/code&gt;.&lt;/p&gt;

 &lt;blockquote&gt;
 &lt;p&gt;&lt;strong&gt;Note :&lt;/strong&gt; si on active le mode avancé, laissez le champ &lt;strong&gt;DNS Server&lt;/strong&gt; vide. Sinon WireGuard écrase la config DNS d&amp;rsquo;OPNsense et c&amp;rsquo;est la galère.&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;p&gt;Sauvegarder, rouvrir l&amp;rsquo;instance et &lt;strong&gt;copier la clé publique&lt;/strong&gt; générée. Elle servira à configurer le client KDE.&lt;/p&gt;
&lt;h3 id="création-du-peer-client"&gt;&lt;a href="#cr%c3%a9ation-du-peer-client" class="header-anchor"&gt;&lt;/a&gt;Création du peer client
&lt;/h3&gt;&lt;p&gt;Il faut maintenant déclarer le client. Pour ça, il faut sa clé publique. On peut la générer directement sur le client KDE (voir partie 2) et la copier ici, ou utiliser le &lt;strong&gt;Peer Generator&lt;/strong&gt; intégré à OPNsense. Moi je préfère générer les clés sur le client pour ne pas stocker la privée ailleurs.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Aller dans &lt;strong&gt;VPN &amp;gt; WireGuard &amp;gt; Peers&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Cliquer sur &lt;strong&gt;+&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Enabled : Coché
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Name : MonPC_KDE
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Public Key : &amp;lt;clé publique du client KDE&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Allowed IPs : 10.10.10.2/32
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Keepalive : 25
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Le &lt;code&gt;Keepalive&lt;/code&gt; à 25 secondes, c&amp;rsquo;est utile quand le client est derrière un NAT ou un pare-feu qui ferme les states trop vite.&lt;/p&gt;
&lt;p&gt;Sauvegarder, puis retourner dans &lt;strong&gt;VPN &amp;gt; WireGuard &amp;gt; Instances&lt;/strong&gt;, éditer &lt;code&gt;HomeWireGuard&lt;/code&gt; et sélectionner le peer &lt;code&gt;MonPC_KDE&lt;/code&gt;. &lt;strong&gt;Apply&lt;/strong&gt;.&lt;/p&gt;
&lt;h3 id="méthode-alternative--le-peer-generator"&gt;&lt;a href="#m%c3%a9thode-alternative--le-peer-generator" class="header-anchor"&gt;&lt;/a&gt;Méthode alternative : le Peer Generator
&lt;/h3&gt;&lt;p&gt;Si vous devez créer plusieurs clients, ou si vous voulez générer directement le fichier de config sans taper de clés à la main, OPNsense intègre un &lt;strong&gt;Peer Generator&lt;/strong&gt; sous &lt;strong&gt;VPN &amp;gt; WireGuard &amp;gt; Peer generator&lt;/strong&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Sélectionner l&amp;rsquo;instance &lt;code&gt;HomeWireGuard&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Remplir les champs :&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Name : MonPC_KDE
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Endpoint Address: &amp;lt;ip_publique_ou_domaine_opnsense&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Endpoint Port : 51820
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Allowed IPs : 10.10.10.2/32
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;DNS : laisser vide, ou 10.10.10.1 si vous voulez utiliser le DNS d&amp;#39;OPNsense
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;Cliquer sur &lt;strong&gt;Generate&lt;/strong&gt;. Le générateur crée :
&lt;ul&gt;
&lt;li&gt;la paire de clés du client&lt;/li&gt;
&lt;li&gt;le peer côté OPNsense (seule la clé publique est stockée)&lt;/li&gt;
&lt;li&gt;une config prête à copier/coller ou à scanner en QR code&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;

 &lt;blockquote&gt;
 &lt;p&gt;&lt;strong&gt;Attention :&lt;/strong&gt; la config générée met souvent &lt;code&gt;AllowedIPs = 0.0.0.0/0, ::/0&lt;/code&gt; côté client. Si vous voulez du split tunnel, il faut remplacer cette ligne par &lt;code&gt;AllowedIPs = 10.10.10.0/24, 192.168.1.0/24&lt;/code&gt; dans le fichier récupéré avant de l&amp;rsquo;importer dans NetworkManager. Sinon tout le trafic partira dans le tunnel.&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;Cliquer sur &lt;strong&gt;Store and generate next&lt;/strong&gt; pour valider le peer dans OPNsense, puis &lt;strong&gt;Apply&lt;/strong&gt; dans &lt;strong&gt;VPN &amp;gt; WireGuard &amp;gt; Peers&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;La clé privée n&amp;rsquo;est pas conservée sur le firewall : copiez-la dans &lt;code&gt;/etc/wireguard/wg0.conf&lt;/code&gt; sur le client, ou scannez le QR code depuis un téléphone.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;C&amp;rsquo;est nettement plus rapide quand il y a plusieurs road warriors à déployer.&lt;/p&gt;
&lt;h3 id="activation-de-wireguard"&gt;&lt;a href="#activation-de-wireguard" class="header-anchor"&gt;&lt;/a&gt;Activation de WireGuard
&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;VPN &amp;gt; WireGuard &amp;gt; General&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Cocher &lt;strong&gt;Enable&lt;/strong&gt;, puis &lt;strong&gt;Apply&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Si besoin, redémarrer WireGuard en le décochant/re-cochant.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="assigner-une-interface-recommandé"&gt;&lt;a href="#assigner-une-interface-recommand%c3%a9" class="header-anchor"&gt;&lt;/a&gt;Assigner une interface (recommandé)
&lt;/h3&gt;&lt;p&gt;Ce n&amp;rsquo;est pas strictement obligatoire pour un split tunnel, mais ça simplifie les règles firewall et ça crée l&amp;rsquo;alias &lt;code&gt;HomeWireGuard net&lt;/code&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Interfaces &amp;gt; Assignments&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Sélectionner le device &lt;code&gt;wg1&lt;/code&gt; (ou &lt;code&gt;wg0&lt;/code&gt; selon l&amp;rsquo;installation) et l&amp;rsquo;ajouter.&lt;/li&gt;
&lt;li&gt;Description : &lt;code&gt;HomeWireGuard&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Éditer l&amp;rsquo;interface :&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Enable : Coché
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Description : HomeWireGuard
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;IPv4 Configuration Type : None
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;IPv6 Configuration Type : None
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Save&lt;/strong&gt; puis &lt;strong&gt;Apply changes&lt;/strong&gt;. Redémarrer WireGuard si l&amp;rsquo;interface ne remonte pas proprement.&lt;/p&gt;
&lt;h3 id="règles-firewall"&gt;&lt;a href="#r%c3%a8gles-firewall" class="header-anchor"&gt;&lt;/a&gt;Règles firewall
&lt;/h3&gt;&lt;h4 id="1-autoriser-les-connexions-entrantes-sur-le-wan"&gt;&lt;a href="#1-autoriser-les-connexions-entrantes-sur-le-wan" class="header-anchor"&gt;&lt;/a&gt;1. Autoriser les connexions entrantes sur le WAN
&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Firewall &amp;gt; Rules &amp;gt; WAN&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Ajouter une règle :&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Action : Pass
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Quick : Coché
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Interface : WAN
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Direction : in
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Protocol : UDP
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Source : any
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Destination : WAN address
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Destination port: 51820
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id="2-autoriser-le-trafic-depuis-le-tunnel-vers-le-lan"&gt;&lt;a href="#2-autoriser-le-trafic-depuis-le-tunnel-vers-le-lan" class="header-anchor"&gt;&lt;/a&gt;2. Autoriser le trafic depuis le tunnel vers le LAN
&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Firewall &amp;gt; Rules &amp;gt; HomeWireGuard&lt;/strong&gt; (ou &lt;code&gt;WireGuard&lt;/code&gt; si vous n&amp;rsquo;avez pas assigné d&amp;rsquo;interface).&lt;/li&gt;
&lt;li&gt;Ajouter une règle :&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Action : Pass
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Quick : Coché
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Interface : HomeWireGuard
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Protocol : any
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Source : HomeWireGuard net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Destination : LAN net
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;C&amp;rsquo;est cette règle qui autorise le client KDE à joindre les machines du LAN.&lt;/p&gt;
&lt;h3 id="normalisation-mss-optionnel-mais-fortement-recommandé"&gt;&lt;a href="#normalisation-mss-optionnel-mais-fortement-recommand%c3%a9" class="header-anchor"&gt;&lt;/a&gt;Normalisation MSS (optionnel mais fortement recommandé)
&lt;/h3&gt;&lt;p&gt;Le &lt;strong&gt;MSS&lt;/strong&gt; (Maximum Segment Size) est la taille maximale de la charge utile d&amp;rsquo;un segment TCP. Comme WireGuard encapsule les paquets (en-têtes UDP/IP/WireGuard), le MTU utile du tunnel est réduit. Les hôtes du LAN peuvent négocier un MSS basé sur l&amp;rsquo;interface locale (1500 octets), ce qui donnerait des paquets trop gros une fois encapsulés. Le &lt;strong&gt;MSS clamping&lt;/strong&gt; force la valeur négociée à &lt;code&gt;MTU_tunnel - 40&lt;/code&gt; pour IPv4, soit &lt;code&gt;1380&lt;/code&gt; avec un MTU de &lt;code&gt;1420&lt;/code&gt;. L&amp;rsquo;IPv6 n&amp;rsquo;est pas traité ici.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Firewall &amp;gt; Settings &amp;gt; Normalization&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Ajouter une règle sur l&amp;rsquo;interface &lt;strong&gt;WireGuard (Group)&lt;/strong&gt; :&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Direction : Any
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Protocol : any
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Source : any
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Destination : any
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Description : WireGuard MSS Clamping IPv4
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Max mss : 1380
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="nat-outbound"&gt;&lt;a href="#nat-outbound" class="header-anchor"&gt;&lt;/a&gt;NAT outbound
&lt;/h3&gt;&lt;p&gt;Pour un split tunnel pur, &lt;strong&gt;pas besoin de NAT outbound&lt;/strong&gt;. OPNsense sait router le trafic entre &lt;code&gt;HomeWireGuard&lt;/code&gt; et &lt;code&gt;LAN&lt;/code&gt; car les deux réseaux lui sont directement attachés. Si jamais OPNsense n&amp;rsquo;est pas la passerelle par défaut du LAN, alors il faudra activer le NAT outbound ou ajouter une route statique sur le routeur intermédiaire.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="partie-2--kde-le-client-wireguard"&gt;&lt;a href="#partie-2--kde-le-client-wireguard" class="header-anchor"&gt;&lt;/a&gt;Partie 2 : KDE, le client WireGuard
&lt;/h2&gt;&lt;h3 id="génération-des-clés"&gt;&lt;a href="#g%c3%a9n%c3%a9ration-des-cl%c3%a9s" class="header-anchor"&gt;&lt;/a&gt;Génération des clés
&lt;/h3&gt;&lt;p&gt;Sur le poste KDE :&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;wg genkey | tee private.key | wg pubkey &amp;gt; public.key
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;&lt;code&gt;public.key&lt;/code&gt; : à copier dans le peer OPNsense (étape &amp;ldquo;Création du peer client&amp;rdquo;).&lt;/li&gt;
&lt;li&gt;&lt;code&gt;private.key&lt;/code&gt; : reste sur le client, ne jamais la balancer sur un chat.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="fichier-de-configuration-wg0conf"&gt;&lt;a href="#fichier-de-configuration-wg0conf" class="header-anchor"&gt;&lt;/a&gt;Fichier de configuration &lt;code&gt;wg0.conf&lt;/code&gt;
&lt;/h3&gt;&lt;p&gt;Créer &lt;code&gt;/etc/wireguard/wg0.conf&lt;/code&gt; :&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-ini" data-lang="ini"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;[Interface]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;PrivateKey&lt;/span&gt; &lt;span style="color:#f92672"&gt;=&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;lt;contenu de private.key&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;Address&lt;/span&gt; &lt;span style="color:#f92672"&gt;=&lt;/span&gt; &lt;span style="color:#e6db74"&gt;10.10.10.2/32&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# DNS optionnel, par exemple si vous voulez utiliser le DNS d&amp;#39;OPNsense&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# DNS = 10.10.10.1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;[Peer]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;PublicKey&lt;/span&gt; &lt;span style="color:#f92672"&gt;=&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;lt;clé publique d&amp;#39;OPNsense&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;AllowedIPs&lt;/span&gt; &lt;span style="color:#f92672"&gt;=&lt;/span&gt; &lt;span style="color:#e6db74"&gt;10.10.10.0/24, 192.168.1.0/24&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;Endpoint&lt;/span&gt; &lt;span style="color:#f92672"&gt;=&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;lt;ip_publique_ou_domaine_opnsense&amp;gt;:51820&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;PersistentKeepalive&lt;/span&gt; &lt;span style="color:#f92672"&gt;=&lt;/span&gt; &lt;span style="color:#e6db74"&gt;25&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
 &lt;blockquote&gt;
 &lt;p&gt;&lt;strong&gt;Le point crucial du split tunnel&lt;/strong&gt; : &lt;code&gt;AllowedIPs&lt;/code&gt; ne contient &lt;strong&gt;pas&lt;/strong&gt; &lt;code&gt;0.0.0.0/0&lt;/code&gt;. Seuls les réseaux à atteindre derrière OPNsense (&lt;code&gt;192.168.1.0/24&lt;/code&gt;) et le tunnel (&lt;code&gt;10.10.10.0/24&lt;/code&gt;) y figurent. Ainsi, seul ce trafic est routé vers &lt;code&gt;wg0&lt;/code&gt; ; le reste (internet) reste sur l&amp;rsquo;interface classique.&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;h3 id="import-dans-networkmanager"&gt;&lt;a href="#import-dans-networkmanager" class="header-anchor"&gt;&lt;/a&gt;Import dans NetworkManager
&lt;/h3&gt;&lt;h4 id="en-ligne-de-commande-plus-fiable"&gt;&lt;a href="#en-ligne-de-commande-plus-fiable" class="header-anchor"&gt;&lt;/a&gt;En ligne de commande (plus fiable)
&lt;/h4&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo nmcli connection import type wireguard file /etc/wireguard/wg0.conf
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Puis on s&amp;rsquo;assure que NetworkManager ne met pas cette connexion en passerelle par défaut :&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo nmcli connection modify wg0 ipv4.never-default yes
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id="en-graphique-kde-plasma"&gt;&lt;a href="#en-graphique-kde-plasma" class="header-anchor"&gt;&lt;/a&gt;En graphique (KDE Plasma)
&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Ouvrir &lt;strong&gt;Paramètres système &amp;gt; Connexions&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Ajouter une connexion &amp;gt; WireGuard&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Onglet &lt;strong&gt;WireGuard&lt;/strong&gt; :
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Private key&lt;/strong&gt; : coller la clé privée.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Peers&lt;/strong&gt; : ajouter le peer avec la clé publique d&amp;rsquo;OPNsense, l&amp;rsquo;endpoint, et &lt;code&gt;Allowed IPs = 10.10.10.0/24, 192.168.1.0/24&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Onglet &lt;strong&gt;IPv4&lt;/strong&gt; :
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Méthode&lt;/strong&gt; : &lt;code&gt;Manuel&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Adresse&lt;/strong&gt; : &lt;code&gt;10.10.10.2/32&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Laisser la &lt;strong&gt;passerelle vide&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Cocher &lt;strong&gt;Utiliser cette connexion uniquement pour les ressources de ce réseau&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Sauvegarder et activer.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Si l&amp;rsquo;option WireGuard n&amp;rsquo;apparaît pas dans l&amp;rsquo;interface graphique, vérifier que &lt;code&gt;wireguard-tools&lt;/code&gt; est bien installé et que NetworkManager est assez récent.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="vérifications"&gt;&lt;a href="#v%c3%a9rifications" class="header-anchor"&gt;&lt;/a&gt;Vérifications
&lt;/h2&gt;&lt;p&gt;Sur le client KDE, une fois connecté :&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ip route show
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;On doit voir quelque chose comme :&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;default via 192.168.0.1 dev eth0 proto dhcp metric 100
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;10.10.10.0/24 dev wg0 proto static scope link
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;192.168.1.0/24 dev wg0 proto static scope link
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;L&amp;rsquo;important : la route &lt;code&gt;default&lt;/code&gt; pointe toujours vers l&amp;rsquo;interface locale. Les routes &lt;code&gt;10.10.10.0/24&lt;/code&gt; et &lt;code&gt;192.168.1.0/24&lt;/code&gt; pointent vers &lt;code&gt;wg0&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Tests basiques :&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ping 10.10.10.1
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ping 192.168.1.x
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Vérifier que l&amp;rsquo;IP publique vue depuis le navigateur n&amp;rsquo;a pas changé (le trafic internet ne passe pas par le VPN) :&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;curl -4 ifconfig.me
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Côté OPNsense, on peut surveiller l&amp;rsquo;état dans &lt;strong&gt;VPN &amp;gt; WireGuard &amp;gt; Status&lt;/strong&gt;. On doit voir le peer &lt;code&gt;MonPC_KDE&lt;/code&gt; avec un handshake récent et du trafic RX/TX.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="conclusion"&gt;&lt;a href="#conclusion" class="header-anchor"&gt;&lt;/a&gt;Conclusion
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;OPNsense&lt;/strong&gt; : instance &lt;code&gt;HomeWireGuard&lt;/code&gt; (&lt;code&gt;10.10.10.1/24&lt;/code&gt;), peer &lt;code&gt;MonPC_KDE&lt;/code&gt; (&lt;code&gt;10.10.10.2/32&lt;/code&gt;), firewall WAN UDP &lt;code&gt;51820&lt;/code&gt; + règle &lt;code&gt;HomeWireGuard net → LAN net&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Client KDE&lt;/strong&gt; : &lt;code&gt;AllowedIPs = 10.10.10.0/24, 192.168.1.0/24&lt;/code&gt;, &lt;code&gt;ipv4.never-default yes&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Résultat&lt;/strong&gt; : les machines du LAN derrière OPNsense sont accessibles, mais internet continue de sortir par la connexion locale. Pas de fuites, pas de ralentissements inutiles.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Et si un jour vous voulez forcer tout le trafic par le VPN, il suffit de remplacer &lt;code&gt;AllowedIPs&lt;/code&gt; par &lt;code&gt;0.0.0.0/0&lt;/code&gt; côté client et d&amp;rsquo;ajouter le NAT outbound sur OPNsense. Mais ce n&amp;rsquo;est pas le sujet d&amp;rsquo;aujourd&amp;rsquo;hui.&lt;/p&gt;</description></item><item><title>KDE : double-clic sur un ISO pour le monter</title><link>https://beta.slash-root.fr/post/kde-double-clic-sur-un-iso-pour-le-monter/</link><pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate><guid>https://beta.slash-root.fr/post/kde-double-clic-sur-un-iso-pour-le-monter/</guid><description>&lt;img src="https://beta.slash-root.fr/post/kde-double-clic-sur-un-iso-pour-le-monter/cover.png" alt="Featured image of post KDE : double-clic sur un ISO pour le monter" /&gt;&lt;p&gt;Sous KDE, double-cliquer sur un &lt;code&gt;.iso&lt;/code&gt; ouvre Ark. C&amp;rsquo;est le comportement par défaut, et c&amp;rsquo;est chiant quand on veut juste monter l&amp;rsquo;image pour parcourir son contenu.&lt;/p&gt;
&lt;p&gt;Le problème vient de l&amp;rsquo;association MIME. On peut le confirmer :&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;xdg-mime query default application/x-iso9660-image
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Ça retourne &lt;code&gt;org.kde.ark.desktop&lt;/code&gt;. Ark est déclaré handler par défaut au niveau système pour ce type MIME, et KDE suit ça à la lettre.&lt;/p&gt;
&lt;h2 id="la-solution"&gt;&lt;a href="#la-solution" class="header-anchor"&gt;&lt;/a&gt;La solution
&lt;/h2&gt;&lt;p&gt;L&amp;rsquo;idée, c&amp;rsquo;est de créer un &lt;code&gt;.desktop&lt;/code&gt; qui monte l&amp;rsquo;ISO via &lt;code&gt;udisksctl&lt;/code&gt; et ouvre Dolphin sur le point de montage, puis de l&amp;rsquo;enregistrer comme handler MIME. Avec &lt;code&gt;NoDisplay=true&lt;/code&gt;, il ne remonte pas dans le menu des applications, il n&amp;rsquo;existe que pour ça.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Créer : &lt;code&gt;~/.local/share/applications/iso-mount.desktop&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;[Desktop Entry]
Type=Application
Name=Monter l&amp;#39;image ISO
Exec=bash -c &amp;#39;DEV=$(udisksctl loop-setup -f &amp;#34;%f&amp;#34; | grep -oP &amp;#34;/dev/loop\d+&amp;#34;); sleep 0.5; udisksctl mount -b &amp;#34;$DEV&amp;#34;; dolphin /run/media/$USER/&amp;#39;
Icon=media-optical
MimeType=application/x-iso9660-image;application/x-cd-image;
NoDisplay=true
Terminal=false
&lt;/code&gt;&lt;/pre&gt;&lt;ul&gt;
&lt;li&gt;Ensuite on enregistre l&amp;rsquo;association :&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;update-desktop-database ~/.local/share/applications/
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;xdg-mime default iso-mount.desktop application/x-iso9660-image
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;xdg-mime default iso-mount.desktop application/x-cd-image
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Sous KDE 6, &lt;code&gt;xdg-mime&lt;/code&gt; peut cracher un &lt;code&gt;qtpaths: commande introuvable&lt;/code&gt;. C&amp;rsquo;est un bug connu, ça n&amp;rsquo;empêche pas l&amp;rsquo;association d&amp;rsquo;être écrite correctement dans &lt;code&gt;~/.config/mimeapps.list&lt;/code&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On vérifie :&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;grep -i iso ~/.config/mimeapps.list
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;application/x-iso9660-image=iso-mount.desktop
application/x-cd-image=iso-mount.desktop
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;À partir de là, un double-clic sur un &lt;code&gt;.iso&lt;/code&gt; dans Dolphin monte l&amp;rsquo;image et ouvre le répertoire directement. Pour démonter, clic droit sur le périphérique dans le panneau latéral → &lt;em&gt;Démonter&lt;/em&gt;.&lt;/p&gt;</description></item></channel></rss>