diff options
Diffstat (limited to 'hostnix/creep/wifi-vpn.nix')
| -rw-r--r-- | hostnix/creep/wifi-vpn.nix | 101 |
1 files changed, 101 insertions, 0 deletions
diff --git a/hostnix/creep/wifi-vpn.nix b/hostnix/creep/wifi-vpn.nix new file mode 100644 index 0000000..ad94f4b --- /dev/null +++ b/hostnix/creep/wifi-vpn.nix @@ -0,0 +1,101 @@ +# TODO not working? + +{ pkgs, ... }: + +{ + boot.kernel.sysctl."net.ipv4.ip_forward" = 1; + + # Manual configuration on popfresh.mou.town: + # /etc/wireguard/wg0.conf + # # firewall-cmd --add-port=51820/udp + # # systemctl enable --now wg-quick@wg0 + networking.wg-quick.interfaces = { + wg0 = { + address = [ "172.28.89.2/24" ]; + privateKeyFile = "/root/wg0.key"; + # wg-quick normally adds routes for AllowedIPs to the default table. + # Specify a non-default table to instead use policy-based routing. + # Using netns may be an alternative. + table = "89"; + # IP masquerade (SNAT) anything from the WiFi AP. + postUp = '' + ${pkgs.iptables}/bin/iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE + ${pkgs.iproute2}/bin/ip rule add iif wlp1s0u1u3 lookup 89 + ''; + preDown = '' + ${pkgs.iptables}/bin/iptables -t nat -D POSTROUTING -o wg0 -j MASQUERADE + ${pkgs.iproute2}/bin/ip rule del iif wlp1s0u1u3 lookup 89 + ''; + peers = [ { + publicKey = "iIRCcLGBvo0LBCysJKa5sbTs/Y4VR4PUDHMkoaU6sgo="; + allowedIPs = [ "0.0.0.0/0" ]; + endpoint = "creepgw.mou.fo:51820"; + persistentKeepalive = 25; # keep NAT rules alive + } ]; + }; + }; + + services.hostapd = { + enable = true; + radios.wlp1s0u1u3 = { + band = "5g"; + # Wasn't able to get Auto Channel Selection working, so specify a band + # that should allow for High Throughput 40 MHz (HT40). + channel = 40; + countryCode = "AU"; + # The network must have the same name as the radio. + networks.wlp1s0u1u3 = { + ssid = "The Up Over"; + authentication = { + mode = "wpa3-sae-transition"; + wpaPassword = "comingtoamerica"; + saePasswords = [ { password = "comingtoamerica"; } ]; + }; + }; + }; + }; + + networking.interfaces.wlp1s0u1u3.ipv4.addresses = [ { + address = "172.16.175.1"; + prefixLength = 24; + } ]; + + services.kea.dhcp4 = { + enable = true; + settings = { + interfaces-config = { + interfaces = [ "wlp1s0u1u3" ]; + }; + lease-database = { + type = "memfile"; + persist = true; + name = "/var/lib/kea/dhcp4.leases"; + }; + subnet4 = [ + { + id = 1; + subnet = "172.16.175.0/24"; + pools = [ { pool = "172.16.175.100 - 172.16.175.240"; } ]; + option-data = [ { + name = "routers"; + data = "172.16.175.1"; + } { + name = "domain-name-servers"; + data = "1.1.1.1, 1.0.0.1"; + } ]; + } + ]; + }; + }; + # Ensure interface is available to serve DHCP. + systemd.services.kea-dhcp4-server = { + requires = [ "network-addresses-wlp1s0u1u3.service" ]; + }; + + # Generated entropy helps prevent WiFi AP from blocking. + services.haveged.enable = true; + + # Reverse path forwarding has complications with multiple interfaces, like + # connectivity issues when WiFi and wired are on the same network. + networking.firewall.checkReversePath = false; +} |
