summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--hostnix/elmo/configuration.nix1
-rw-r--r--hostnix/elmo/wireguard.nix32
2 files changed, 33 insertions, 0 deletions
diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix
index af4466d..7f5b197 100644
--- a/hostnix/elmo/configuration.nix
+++ b/hostnix/elmo/configuration.nix
@@ -15,6 +15,7 @@
./syncthing.nix
./system.nix
./usenet.nix
+ ./wireguard.nix
];
nix.settings.experimental-features = [ "nix-command" "flakes" ];
diff --git a/hostnix/elmo/wireguard.nix b/hostnix/elmo/wireguard.nix
new file mode 100644
index 0000000..7d56062
--- /dev/null
+++ b/hostnix/elmo/wireguard.nix
@@ -0,0 +1,32 @@
+{ pkgs, ... }:
+
+{
+ networking.nat = {
+ enable = true;
+ enableIPv6 = true;
+ externalInterface = "enp3s0f0";
+ internalInterfaces = [ "wg0" ];
+ };
+
+ networking.wg-quick.interfaces = {
+ wg0 = {
+ address = [ "172.28.92.1/24" "fd61:754f:ebd3:1c5c::1/64" ];
+ listenPort = 51820;
+ privateKeyFile = "/var/secrets/wg0.key";
+ postUp = ''
+ ${pkgs.iptables}/bin/iptables -t nat -A POSTROUTING -o enp3s0f0 -j MASQUERADE
+ ${pkgs.iptables}/bin/ip6tables -t nat -A POSTROUTING -o enp3s0f0 -j MASQUERADE
+ '';
+ preDown = ''
+ ${pkgs.iptables}/bin/iptables -t nat -D POSTROUTING -o enp3s0f0 -j MASQUERADE
+ ${pkgs.iptables}/bin/ip6tables -t nat -D POSTROUTING -o enp3s0f0 -j MASQUERADE
+ '';
+ peers = [ {
+ publicKey = "ZfJaZgG8e2neWJBWcN3cZsDd740Zq+sW/2pmBqSgbRI=";
+ allowedIPs = [ "172.28.92.2" "fd61:754f:ebd3:1c5c::2" ];
+ } ];
+ };
+ };
+
+ networking.firewall.allowedUDPPorts = [ 51820 ];
+}