{"id":4900,"date":"2026-08-29T22:00:40","date_gmt":"2026-08-29T13:00:40","guid":{"rendered":"https:\/\/donguri3.net\/server-tech\/deploy-webserver-using-wireguard-oci-2\/"},"modified":"2026-08-29T22:00:41","modified_gmt":"2026-08-29T13:00:41","slug":"deploy-webserver-using-wireguard-oci","status":"publish","type":"post","link":"https:\/\/donguri3.net\/en\/server-tech\/linux-server-network\/deploy-webserver-using-wireguard-oci\/","title":{"rendered":"Publishing a Web Server in an Apartment Network Using WireGuard and VPS (OCI)"},"content":{"rendered":"<p>This guide explains how to expose a Web server (OpenLiteSpeed) installed within an apartment or multi-dwelling unit (MDU) network environment by connecting it via a Virtual Private Network (VPN) to a Virtual Private Server (VPS) on Oracle Cloud Infrastructure (OCI). Access to the VPS is directly forwarded to the Web server using iptables NAT.<\/p>\n<h3>Architecture Diagram<\/h3>\n<p><a href=\"https:\/\/donguri3.net\/wp-content\/uploads\/2025\/02\/\u30de\u30f3\u30b7\u30e7\u30f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u3092\u516c\u958b-1.jpg\"><img decoding=\"async\" class=\"aligncenter wp-image-379 size-large\" src=\"https:\/\/donguri3.net\/wp-content\/uploads\/2025\/02\/\u30de\u30f3\u30b7\u30e7\u30f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u3092\u516c\u958b-1-1024x576.jpg\" alt=\"Publishing a Web Server in an Apartment Network Using WireGuard and VPS (OCI)\" width=\"1024\" height=\"576\" srcset=\"https:\/\/donguri3.net\/wp-content\/uploads\/2025\/02\/\u30de\u30f3\u30b7\u30e7\u30f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u3092\u516c\u958b-1-1024x576.jpg 1024w, https:\/\/donguri3.net\/wp-content\/uploads\/2025\/02\/\u30de\u30f3\u30b7\u30e7\u30f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u3092\u516c\u958b-1-300x169.jpg 300w, https:\/\/donguri3.net\/wp-content\/uploads\/2025\/02\/\u30de\u30f3\u30b7\u30e7\u30f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u3092\u516c\u958b-1-768x432.jpg 768w, https:\/\/donguri3.net\/wp-content\/uploads\/2025\/02\/\u30de\u30f3\u30b7\u30e7\u30f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u3092\u516c\u958b-1-1536x864.jpg 1536w, https:\/\/donguri3.net\/wp-content\/uploads\/2025\/02\/\u30de\u30f3\u30b7\u30e7\u30f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u3092\u516c\u958b-1-320x180.jpg 320w, https:\/\/donguri3.net\/wp-content\/uploads\/2025\/02\/\u30de\u30f3\u30b7\u30e7\u30f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u3092\u516c\u958b-1-530x298.jpg 530w, https:\/\/donguri3.net\/wp-content\/uploads\/2025\/02\/\u30de\u30f3\u30b7\u30e7\u30f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u3092\u516c\u958b-1-565x318.jpg 565w, https:\/\/donguri3.net\/wp-content\/uploads\/2025\/02\/\u30de\u30f3\u30b7\u30e7\u30f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u3092\u516c\u958b-1-710x399.jpg 710w, https:\/\/donguri3.net\/wp-content\/uploads\/2025\/02\/\u30de\u30f3\u30b7\u30e7\u30f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u3092\u516c\u958b-1-725x408.jpg 725w, https:\/\/donguri3.net\/wp-content\/uploads\/2025\/02\/\u30de\u30f3\u30b7\u30e7\u30f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u3092\u516c\u958b-1-160x90.jpg 160w, https:\/\/donguri3.net\/wp-content\/uploads\/2025\/02\/\u30de\u30f3\u30b7\u30e7\u30f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u3092\u516c\u958b-1.jpg 1920w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/p>\n<h3><strong>Objectives<\/strong><\/h3>\n<ul>\n<li>Expose a Web server set up inside an apartment or MDU network environment.<\/li>\n<li>Operate using free services with minimal cost possible.<\/li>\n<li>Reuse a Web server that was operated in the past.<\/li>\n<\/ul>\n<h3><strong>Goal<\/strong><\/h3>\n<ul>\n<li>Directly forward access to the VPS ports 80\/tcp (HTTP), 443\/tcp (HTTPS), and 443\/UDP (HTTP\/3) to the Web server.<\/li>\n<\/ul>\n<h3><strong>Challenges<\/strong><\/h3>\n<ul>\n<li>Apartments and condominiums are assigned private IP addresses, making it impossible to directly expose a Web server.<\/li>\n<li>Want to keep the cost of exposing a Web server down.<\/li>\n<li>Need to consider how to utilize the Web server used before moving in the new environment.<\/li>\n<\/ul>\n<h2>Building a VPN (Virtual Private Network)<\/h2>\n<p>A VPN (Virtual Private Network) is a technology that establishes a <strong>virtual private line<\/strong> over the internet to enable secure communication. Using a VPN allows networks in distant locations to connect via an <strong>encrypted communication path<\/strong>, reducing the risk of third parties snooping on data.<\/p>\n<p>Main use cases include the following:<\/p>\n<ul>\n<li><strong>Remote Access<\/strong>: Securely access the corporate network or home server from outside<\/li>\n<li><strong>Site-to-Site Connection<\/strong>: Connect networks in different locations via VPN to operate them as a single network<\/li>\n<li><strong>Enhanced Security<\/strong>: Encrypt data communication even in unsecured environments like public Wi-Fi<\/li>\n<\/ul>\n<p>This article explains how to <strong>expose a Web server in an apartment using a VPN<\/strong>. To achieve this, we will build a VPN utilizing <strong>&#8220;WireGuard&#8221;, a lightweight and high-speed VPN protocol<\/strong>.<\/p>\n<h3><strong>What is WireGuard?<\/strong><\/h3>\n<p>WireGuard is a simple and high-performance VPN protocol with the following features:<\/p>\n<ul>\n<li><strong>High Speed<\/strong>: Lower processing overhead and faster communication compared to traditional VPNs (IPsec and OpenVPN)<\/li>\n<li><strong>High Security<\/strong>: Adopts modern cryptographic technology for strong safety<\/li>\n<li><strong>Simple Configuration<\/strong>: Eliminates complex settings, making setup easy<\/li>\n<\/ul>\n<p>This article will detail <strong>how to introduce WireGuard to an Oracle Cloud Infrastructure (OCI) VPS and establish a VPN connection with the Web server in the apartment<\/strong>.<\/p>\n<h2>WireGuard Network Configuration<\/h2>\n<p>WireGuard uses two types of networks.<\/p>\n<ol start=\"1\">\n<li><strong>Communication network between WireGuard peers<\/strong>\n<ul>\n<li>A network for VPN peers to communicate within the WireGuard tunnel.<\/li>\n<li>Example: <code>10.1.232.0\/24<\/code><\/li>\n<\/ul>\n<\/li>\n<li><strong>Network for machines inside the WireGuard network<\/strong>\n<ul>\n<li>IP addresses assigned to each machine inside the VPN.<\/li>\n<li>Example: <code>192.168.100.0\/24<\/code><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>WireGuard uses the following ports.<\/p>\n<ol>\n<li><strong>Ports for communicating with the WireGuard Server<\/strong>\n<ul>\n<li>Ports used when creating the WireGuard tunnel<\/li>\n<li>Example: <code>51820\/UDP<\/code> (customizable)<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<h2>VPS Configuration<\/h2>\n<p>To use a VPS (Oracle Cloud Infrastructure, OCI) as a WireGuard relay node to securely communicate with your home server, the following conditions must be met:<\/p>\n<ul>\n<div>\n<li><strong>A Public IP must be assigned to the VPS<\/strong><\/li>\n<ul>\n<li>OCI free tier instances assign public IPs by default, but verification is required.<\/li>\n<li>You can check the public IP from &#8220;Instance Details&#8221; in the OCI Console.<\/li>\n<\/ul>\n<\/div>\n<li>\n<div><strong>Open necessary ports in the firewall (OCI Security List)<\/strong><\/div>\n<ul>\n<li>WireGuard communication (UDP port 51820)<\/li>\n<li>For Web server (TCP 80, 443)<\/li>\n<li>HTTP\/3 (UDP 443)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>WireGuard-Server Configuration<\/h2>\n<p>Run WireGuard-Server as a Docker container on the VPS.<\/p>\n<h3>Environment Variable Settings in <code>docker-compose.yml<\/code><\/h3>\n<p>docker-compose.yml:<\/p>\n<pre><code>version: '3'\nservices:\n  wireguard:\n    image: linuxserver\/wireguard\n    container_name: wireguard-server\n    cap_add:\n      - NET_ADMIN\n      - SYS_MODULE\n    environment:\n      - PUID=1000\n      - PGID=1000\n      - SERVERURL= &lt;IP OR DOMAIN&gt; #optional\n      - SERVERPORT=51820 #optional\n      - PEERS=1 #optional\n      - PEERDNS=8.8.8.8,10.1.232.1 #optional\n      - INTERNAL_SUBNET=10.1.232.0\/24 #optional\n      - ALLOWEDIPS=10.1.232.0\/24 #optional\n      - PERSISTENTKEEPALIVE_PEERS=all #optional\n      - LOG_CONFS=true #optional\n      - SERVER_ALLOWEDIPS_PEER_1=192.168.100.0\/24\n    volumes:\n      - .\/config:\/config\n\u3000\u3000\u3000- \/lib\/modules:\/lib\/modules #optional\n\u00a0 \u00a0 \u00a0ports:\n      - 80:80\n      - 443:443\n      - 443:443\/udp\n      - 51820:51820\/udp\n    restart: unless-stopped\n    sysctls:\n      - net.ipv4.conf.all.src_valid_mark=1<\/code><\/pre>\n<p>Running <code>docker-compose up -d<\/code> automatically generates WireGuard configuration files and related data inside the <code>config<\/code> directory. The directory structure will look like this. Since PEERS is set to &#8220;1&#8221; in docker-compose.yml, peer &#8220;1&#8221; is created in the config directory. If creating multiple peers, separate them with commas.<\/p>\n<pre><code><span style=\"background-color: inherit; color: inherit; font-family: inherit; font-size: var(--hcb--fz,14px);\">$ls -R config<\/span><\/code><code>\nconfig\/:\ncoredns peer1 server templates wg_confs\n\nconfig\/coredns:\nCorefile\n\nconfig\/peer1:\npeer1.conf peer1.png presharedkey-peer1 privatekey-peer1 publickey-peer1\n\nconfig\/server:\nprivatekey-server publickey-server\n\nconfig\/templates:\npeer.conf server.conf\n\nconfig\/wg_confs:\nwg0.conf<\/code><\/pre>\n<h2>WireGuard-Client Configuration<\/h2>\n<p>Run WireGuard-Client as a Docker container on your home server.<\/p>\n<h3>Configuring <code>wg0.conf<\/code><\/h3>\n<p>Create <code>wg0.conf<\/code> by referencing <code>config\/peer1\/peer1.conf<\/code> from the WireGuard-Server.<\/p>\n<pre><code>[Interface]\nAddress = 10.1.232.2\/24\nPrivateKey = &lt;Client private key: copied from peer1.conf&gt;\nListenPort = 51820\nDNS = 8.8.8.8,10.1.232.1\n\n[Peer]\nPublicKey = &lt;Server public key: copied from peer1.conf&gt;\nPresharedKey = &lt;Preshared key: copied from peer1.conf&gt;\nEndpoint = &lt;VPS IP address or domain&gt;:51820\nAllowedIPs = 10.1.232.0\/24\nPersistentKeepalive = 25<\/code><\/pre>\n<h3>Adding <code>PostUp<\/code> \/ <code>PostDown<\/code> to Interface in <code>wg0.conf<\/code><\/h3>\n<p>To apply NAT rules when WireGuard starts, add PostUp and PostDown to [Interface] in the WireGuard client&#8217;s wg0.conf.<\/p>\n<pre><code>PostUp = iptables -t nat -A POSTROUTING -d 192.168.100.0\/24 -j MASQUERADE\nPostDown = iptables -t nat -D POSTROUTING -d 192.168.100.0\/24 -j MASQUERADE<\/code><\/pre>\n<h2>Adding Web Server (OpenLiteSpeed) to the WireGuard Network<\/h2>\n<p>Use Docker <code>networks<\/code> to specify the OpenLiteSpeed IP (e.g., 192.168.100.3).<\/p>\n<h3>Network Settings in <code>docker-compose.yml<\/code><\/h3>\n<pre><code>services:\n  openlitespeed:\n    image: litespeedtech\/openlitespeed\n    container_name: openlitespeed\n    networks:\n      backbone:\n        ipv4_address: 192.168.100.3\n      ...\n      [Middle omitted]\n      ...\n\nnetworks:\n  backbone:\n    driver: bridge\n    ipam:\n      config:\n        - subnet: 192.168.100.0\/24\n<\/code><\/pre>\n<h2>iptables Configuration on WireGuard-Server<\/h2>\n<p>Configure iptables on the WireGuard-Server to forward VPS HTTP\/HTTPS traffic to OpenLiteSpeed on your home server. Rewrite PostUp\/PostDown in config\/wg_conf\/wg0.conf as follows. (Initial values of PostUp\/PostDown are written in a single line, but split here for better readability.)<\/p>\n<pre>PostUp = iptables -A FORWARD -i %i -j ACCEPT\nPostUp = iptables -A FORWARD -o %i -j ACCEPT\nPostUp = iptables -t nat -A POSTROUTING -o eth+ -j MASQUERADE\nPostUp = iptables -A FORWARD -i %i -o %i -j ACCEPT\nPostUp = iptables -t nat -A POSTROUTING -d 10.1.232.0\/24 -j MASQUERADE\nPostUp = iptables -t nat -A PREROUTING -i eth+ -p tcp --dport 80 -j DNAT --to-destination 192.168.100.3:80\nPostUp = iptables -t nat -A PREROUTING -i eth+ -p tcp --dport 443 -j DNAT --to-destination 192.168.100.3:443\nPostUp = iptables -t nat -A PREROUTING -i eth+ -p udp --dport 443 -j DNAT --to-destination 192.168.100.3:443\nPostDown = iptables -D FORWARD -i %i -j ACCEPT\nPostDown = iptables -D FORWARD -o %i -j ACCEPT\nPostDown = iptables -t nat -D POSTROUTING -o eth+ -j MASQUERADE\nPostDown = iptables -D FORWARD -i %i -o %i -j ACCEPT\nPostDown = iptables -t nat -D POSTROUTING -d 10.1.232.0\/24 -j MASQUERADE;\nPostDown = iptables -t nat -D PREROUTING -i eth+ -p tcp --dport 80 -j DNAT --to-destination 192.168.100.3:80\nPostDown = iptables -t nat -D PREROUTING -i eth+ -p tcp --dport 443 -j DNAT --to-destination 192.168.100.3:443\nPostDown = iptables -t nat -D PREROUTING -i eth+ -p udp --dport 443 -j DNAT --to-destination 192.168.100.3:443$ ls -R config\/<\/pre>\n<h2>Operation Verification<\/h2>\n<ol start=\"1\">\n<li>Check WireGuard connection\n<pre><code>docker exec -it &lt;wireguard container name&gt; wg show<\/code><\/pre>\n<\/li>\n<li>Verify if you can access the home server&#8217;s Web server from the VPS\n<pre><code>docker exec -it &lt;wireguard container name&gt; curl -I http:\/\/192.168.100.3<\/code><\/pre>\n<\/li>\n<li>Verify if you can access the Web server from the internet using the VPS domain\n<pre><code>curl -I https:\/\/your-vps-domain.com<\/code><\/pre>\n<\/li>\n<\/ol>\n<h2>Conclusion<\/h2>\n<p>With this configuration, we successfully exposed the Web server inside the apartment network by relaying through a VPS. Utilizing WireGuard made it possible to securely and flexibly forward traffic, enabling external access.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This guide explains how to expose a Web server (OpenLiteSpeed) installed within an apartment or multi-dwelling [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":379,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_locale":"en_US","_original_post":"https:\/\/donguri3.net\/?p=374","footnotes":""},"categories":[1170],"tags":[18,19,27,16,15,20,13,14,21,97,24,92,10,99,98,131],"class_list":["post-4900","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux-server-network","tag-docker","tag-docker-compose","tag-iptables","tag-lets-encrypt","tag-litespeed","tag-oci","tag-ols","tag-openlitespeed","tag-oracle-cloud-infrastructure","tag-ssl","tag-vpn","tag-wireguard","tag-server","tag-99","tag-98","tag-131","en-US"],"_links":{"self":[{"href":"https:\/\/donguri3.net\/wp-json\/wp\/v2\/posts\/4900","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/donguri3.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/donguri3.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/donguri3.net\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/donguri3.net\/wp-json\/wp\/v2\/comments?post=4900"}],"version-history":[{"count":1,"href":"https:\/\/donguri3.net\/wp-json\/wp\/v2\/posts\/4900\/revisions"}],"predecessor-version":[{"id":4903,"href":"https:\/\/donguri3.net\/wp-json\/wp\/v2\/posts\/4900\/revisions\/4903"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/donguri3.net\/wp-json\/wp\/v2\/media\/379"}],"wp:attachment":[{"href":"https:\/\/donguri3.net\/wp-json\/wp\/v2\/media?parent=4900"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/donguri3.net\/wp-json\/wp\/v2\/categories?post=4900"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/donguri3.net\/wp-json\/wp\/v2\/tags?post=4900"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}