Template: vpn-router/platform Type: select Choices: generic, azure, gcp Default: generic Description: Platform module Platform-specific additions to load. The router works without any of them; a module only adds what makes sense on its platform, such as the platform DNS resolver for road-warrior clients. Template: vpn-router/external_interface Type: string Default: Description: External network interface Name of the interface facing the untrusted network, for example eth0 or ens4. The addresses strongSwan binds on are read from it, so they are never configured separately. . Leave empty to configure the router later by editing /etc/vpn-router/vpn-router.conf. Template: vpn-router/internal_interface Type: string Default: Description: Internal network interface Name of the interface facing the protected network, for example eth1 or ens5. Routes for the local subnets are applied to it. Template: vpn-router/local_fqdn Type: string Default: Description: Local router FQDN Fully-qualified domain name of this router (for example router.example.com). Used as the road-warrior server identity and certificate common name. Template: vpn-router/local_id_mode Type: select Choices: fqdn, public_ip, internal_ip Default: fqdn Description: IKE local identity mode How to derive the IKE identity advertised to the remote site: . fqdn - use the FQDN, which must match what the peer expects. . public_ip - resolve the FQDN and use the address it returns. . internal_ip - use the internal NIC address. Template: vpn-router/local_cidrs Type: string Default: Description: Local subnet CIDR(s) Comma-separated list of local subnet CIDRs to advertise into the site-to-site tunnel (for example 10.0.0.0/24 or 10.0.0.0/24,10.0.1.0/24). Template: vpn-router/int_gateway_ip Type: string Default: Description: Internal network gateway IP Address of the next-hop gateway on the internal side, used to route the local subnets listed above. Template: vpn-router/remote_addrs Type: string Default: Description: Remote site WAN IP address(es) Comma-separated list of remote gateway addresses or FQDNs for the site-to-site IPSec tunnel. Template: vpn-router/remote_id Type: string Default: Description: Remote site IKE identity IKE identity of the remote peer, without a leading @. Template: vpn-router/remote_cidrs Type: string Default: Description: Remote subnet CIDR(s) Comma-separated list of remote subnet CIDRs reachable through the site-to-site tunnel (for example 192.168.0.0/24). Template: vpn-router/psk Type: password Description: Pre-shared key (PSK) Pre-shared key for the site-to-site IKEv2 tunnel. Must match the value configured on the remote peer. Stored base64-encoded in the configuration file and cleared from the debconf database after installation. Template: vpn-router/p2s_enabled Type: boolean Default: false Description: Enable road-warrior (P2S) access? If enabled, this router accepts IKEv2 EAP-TLS connections from individual clients. Certificates are taken from /etc/vpn-router/pki, and a local certificate authority is created there if that directory is empty. Template: vpn-router/p2s_address_pool Type: string Default: Description: Road-warrior address pool CIDR block assigned to road-warrior clients (for example 172.16.0.0/24). Template: vpn-router/p2s_ca_name Type: string Default: VPN Router CA Description: Road-warrior CA name Common name for the certificate authority created in /etc/vpn-router/pki when that directory is empty. Ignored when certificates are supplied. Template: vpn-router/wg_enabled Type: boolean Default: false Description: Enable WireGuard? If enabled, WireGuard is configured on wg0, a key pair is generated, and the matching firewall rule is installed. Peers are added by editing /etc/wireguard/wg0.conf. Template: vpn-router/wg_address Type: string Default: Description: WireGuard interface address Address and prefix length for the wg0 interface (for example 192.168.200.1/24). Template: vpn-router/wg_listen_port Type: string Default: 51820 Description: WireGuard listen port UDP port that WireGuard listens on.