VyOS Quick Start - Build a NAT Gateway in 10 Minutes
This guide helps you quickly set up a basic VyOS configuration as a NAT gateway with two network interfaces.
Prerequisites
After installing VyOS, log in using the default credentials:
- Username:
vyos - Password:
vyos
Configuration Mode
To make changes to the configuration, you must enter configuration mode:
vyos@vyos:~$ configure
[edit]
vyos@vyos#Note that the command prompt has changed from $ to #, which indicates that you are in configuration mode.
The commit and save Commands
commit- applies configuration changessave- saves the configuration permanently
Important: Configuration changes will not take effect until you run the commit command.
Interface Configuration
WAN Interface (eth0)
Configure the external interface to obtain an IP address via DHCP:
set interfaces ethernet eth0 address dhcp
set interfaces ethernet eth0 description 'WAN'LAN Interface (eth1)
Configure the internal interface with a static IP address:
set interfaces ethernet eth1 address '192.168.0.1/24'
set interfaces ethernet eth1 description 'LAN'SSH Setup
Enable SSH for remote management:
set service ssh port 22DHCP and DNS Configuration
DHCP Server
Configure the DHCP server for the internal network:
set service dhcp-server shared-network-name LAN subnet 192.168.0.0/24 option default-router '192.168.0.1'
set service dhcp-server shared-network-name LAN subnet 192.168.0.0/24 option name-server '192.168.0.1'
set service dhcp-server shared-network-name LAN subnet 192.168.0.0/24 option domain-name 'internal-network'
set service dhcp-server shared-network-name LAN subnet 192.168.0.0/24 range 0 start '192.168.0.9'
set service dhcp-server shared-network-name LAN subnet 192.168.0.0/24 range 0 stop '192.168.0.254'
set service dhcp-server shared-network-name LAN subnet 192.168.0.0/24 subnet-id 1Parameters:
- default-router: Default gateway for clients
- name-server: DNS server for clients
- domain-name: Domain name
- range: Range of IP addresses to be assigned (192.168.0.9 - 192.168.0.254)
- lease: Address lease time (default 86400 seconds)
DNS forwarding
Configure DNS forwarding:
set service dns forwarding listen-address '192.168.0.1'
set service dns forwarding allow-from '192.168.0.0/24'NAT Configuration
Configure Source NAT to give the internal network internet access:
set nat source rule 100 outbound-interface name 'eth0'
set nat source rule 100 source address '192.168.0.0/24'
set nat source rule 100 translation address 'masquerade'Parameters:
- rule 100: Rule number
- outbound-interface: Outbound interface (WAN)
- source address: Source addresses (internal network)
- masquerade: IP masquerading (replacing the source address with the WAN interface address)
Firewall Configuration
VyOS 1.5.x uses nftables as the backend for the firewall.
Configuring Address Groups
Create an address group for the internal network:
set firewall group address-group LAN-NETWORKS address '192.168.0.0/24'Rules for Inbound Traffic (eth0 → router)
Create rules to protect the router itself:
set firewall ipv4 input filter default-action 'drop'
set firewall ipv4 input filter rule 10 action 'accept'
set firewall ipv4 input filter rule 10 state established
set firewall ipv4 input filter rule 10 state related
set firewall ipv4 input filter rule 20 action 'drop'
set firewall ipv4 input filter rule 20 state invalid
set firewall ipv4 input filter rule 30 action 'accept'
set firewall ipv4 input filter rule 30 protocol 'icmp'
set firewall ipv4 input filter rule 40 action 'accept'
set firewall ipv4 input filter rule 40 source group address-group 'LAN-NETWORKS'Rule logic:
- default-action drop: Block all traffic by default
- rule 10: Allow established/related connections
- rule 20: Drop invalid packets
- rule 30: Allow ICMP (ping)
- rule 40: Allow traffic from the internal network
Rules for Transit Traffic (eth0 → eth1)
Create rules for traffic passing through the router:
set firewall ipv4 forward filter default-action 'drop'
set firewall ipv4 forward filter rule 10 action 'accept'
set firewall ipv4 forward filter rule 10 state established
set firewall ipv4 forward filter rule 10 state related
set firewall ipv4 forward filter rule 20 action 'drop'
set firewall ipv4 forward filter rule 20 state invalid
set firewall ipv4 forward filter rule 30 action 'accept'
set firewall ipv4 forward filter rule 30 source group address-group 'LAN-NETWORKS'Applying the Configuration
Apply and save the changes:
commit
saveOnce these commands complete, the basic NAT gateway configuration is ready to use.
Hardening Security
Replacing the Default User
Create a new user with administrator privileges:
set system login user admin authentication plaintext-password 'secure_password'
set system login user admin authentication public-keys user@host key 'AAAAB3Nz....'
set system login user admin authentication public-keys user@host type 'ssh-rsa'Remove the default user:
delete system login user vyosDisabling Password Authentication
To improve security, it is recommended to use SSH key authentication only:
set service ssh disable-password-authenticationDo not forget to apply the changes:
commit
saveVerifying the Configuration
Check the state of the interfaces:
show interfacesCheck the routing table:
show ip routeCheck NAT:
show nat source rules
show nat source statisticsCheck the firewall rules:
show firewallView active DHCP leases:
show dhcp server leasesNext Steps
After configuring the basic setup, you can move on to more advanced tasks:
- Setting up a VPN (WireGuard, OpenVPN, IPsec)
- Configuring dynamic routing protocols (BGP, OSPF)
- Setting up QoS and traffic policies
- Configuring high availability (VRRP)
- Integrating with monitoring systems
For more details, see the Configuration and Administrator Guide sections.