summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--hostnix/creep/configuration.nix14
-rw-r--r--hostnix/creep/wifi-vpn.nix95
2 files changed, 104 insertions, 5 deletions
diff --git a/hostnix/creep/configuration.nix b/hostnix/creep/configuration.nix
index 86100af..67f7732 100644
--- a/hostnix/creep/configuration.nix
+++ b/hostnix/creep/configuration.nix
@@ -3,6 +3,7 @@
{
imports = [
./hardware-configuration.nix
+ ./wifi-vpn.nix
];
nix.settings.experimental-features = [ "nix-command" "flakes" ];
@@ -20,10 +21,13 @@
networking.hostName = "creep";
networking.domain = "mou.fo";
- networking.wireless.enable = true;
- networking.wireless.networks = {
- "Girls Gone Wireless".psk = "Paddlepops103!";
- "Cali's internet".psk = "calibanthetempest2019";
+ networking.wireless = {
+ enable = true;
+ interfaces = [ "wlan0" ];
+ networks = {
+ "Girls Gone Wireless".psk = "Paddlepops103!";
+ "Cali's internet".psk = "calibanthetempest2019";
+ };
};
time.timeZone = "Australia/Sydney";
@@ -64,7 +68,7 @@
-o ServerAliveInterval=60 -o ExitOnForwardFailure=yes \
-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no \
-i /etc/ssh/ssh_host_ed25519_key \
- -N -R 19422:localhost:22 joe@popfresh.mou.fo
+ -q -N -R 19422:localhost:22 joe@creepgw.mou.fo
'';
};
diff --git a/hostnix/creep/wifi-vpn.nix b/hostnix/creep/wifi-vpn.nix
new file mode 100644
index 0000000..8a790c4
--- /dev/null
+++ b/hostnix/creep/wifi-vpn.nix
@@ -0,0 +1,95 @@
+{ pkgs, ... }:
+
+{
+ boot.kernel.sysctl."net.ipv4.ip_forward" = 1;
+
+ networking.wg-quick.interfaces = {
+ wg0 = {
+ address = [ "172.28.89.2/24" ];
+ privateKeyFile = "/root/wg0.key";
+ # wg-quick normally adds routes for AllowedIPs to the default table.
+ # Specify a non-default table to instead use policy-based routing.
+ # Using netns may be an alternative.
+ table = "89";
+ # IP masquerade (SNAT) anything from the WiFi AP.
+ postUp = ''
+ ${pkgs.iptables}/bin/iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE
+ ${pkgs.iproute2}/bin/ip rule add iif wlp1s0u1u3 lookup 89
+ '';
+ preDown = ''
+ ${pkgs.iptables}/bin/iptables -t nat -D POSTROUTING -o wg0 -j MASQUERADE
+ ${pkgs.iproute2}/bin/ip rule del iif wlp1s0u1u3 lookup 89
+ '';
+ peers = [ {
+ publicKey = "iIRCcLGBvo0LBCysJKa5sbTs/Y4VR4PUDHMkoaU6sgo=";
+ allowedIPs = [ "0.0.0.0/0" ];
+ endpoint = "creepgw.mou.fo:51820";
+ persistentKeepalive = 25; # keep NAT rules alive
+ } ];
+ };
+ };
+
+ services.hostapd = {
+ enable = true;
+ radios.wlp1s0u1u3 = {
+ band = "5g";
+ # Wasn't able to get Auto Channel Selection working, so specify a band
+ # that should allow for High Throughput 40 MHz (HT40).
+ channel = 40;
+ countryCode = "AU";
+ # The network must have the same name as the radio.
+ networks.wlp1s0u1u3 = {
+ ssid = "The Up Over";
+ authentication = {
+ mode = "wpa3-sae-transition";
+ wpaPassword = "comingtoamerica";
+ saePasswords = [ { password = "comingtoamerica"; } ];
+ };
+ };
+ };
+ };
+
+ networking.interfaces.wlp1s0u1u3.ipv4.addresses = [ {
+ address = "172.16.175.1";
+ prefixLength = 24;
+ } ];
+
+ services.kea.dhcp4 = {
+ enable = true;
+ settings = {
+ interfaces-config = {
+ interfaces = [ "wlp1s0u1u3" ];
+ };
+ lease-database = {
+ type = "memfile";
+ persist = true;
+ name = "/var/lib/kea/dhcp4.leases";
+ };
+ subnet4 = [
+ {
+ id = 1;
+ subnet = "172.16.175.0/24";
+ pools = [ { pool = "172.16.175.100 - 172.16.175.240"; } ];
+ option-data = [ {
+ name = "routers";
+ data = "172.16.175.1";
+ } {
+ name = "domain-name-servers";
+ data = "1.1.1.1, 1.0.0.1";
+ } ];
+ }
+ ];
+ };
+ };
+ # Ensure interface is available to serve DHCP.
+ systemd.services.kea-dhcp4-server = {
+ requires = [ "network-addresses-wlp1s0u1u3.service" ];
+ };
+
+ # Generated entropy helps prevent WiFi AP from blocking.
+ services.haveged.enable = true;
+
+ # Reverse path forwarding has complications with multiple interfaces, like
+ # connectivity issues when WiFi and wired are on the same network.
+ networking.firewall.checkReversePath = false;
+}