- Create LXC
lxc.apparmor.profile: unconfined
lxc.cgroup.devices.allow: c 10:200 rwm
lxc.mount.auto: proc:rw sys:rw
lxc.mount.entry: /dev/net/tun dev/net/tun none bind,create=file
- install warp-cli https://developers.cloudflare.com/cloudflare-one/tutorials/warp-on-headless-linux/
- set NAT routing
root@rmr-egress-cf:~# iptables -t nat -A POSTROUTING -o CloudflareWARP -j MASQUERADE
root@rmr-egress-cf:~# iptables -A FORWARD -i eth0 -o CloudflareWARP -j ACCEPT
root@rmr-egress-cf:~# iptables -A FORWARD -i CloudflareWARP -o eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT
to make permanent
apt install -y iptables-persistent
netfilter-persistent save
- set routing in mikrotik (used as wan)