From f676a60d8dc432952614e6dd4ab60e7f7a386389 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Mon, 16 Dec 2024 16:00:44 -0500 Subject: Wireguard --- hostnix/elmo/configuration.nix | 1 + hostnix/elmo/wireguard.nix | 32 ++++++++++++++++++++++++++++++++ 2 files changed, 33 insertions(+) create mode 100644 hostnix/elmo/wireguard.nix (limited to 'hostnix/elmo') diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix index af4466d..7f5b197 100644 --- a/hostnix/elmo/configuration.nix +++ b/hostnix/elmo/configuration.nix @@ -15,6 +15,7 @@ ./syncthing.nix ./system.nix ./usenet.nix + ./wireguard.nix ]; nix.settings.experimental-features = [ "nix-command" "flakes" ]; diff --git a/hostnix/elmo/wireguard.nix b/hostnix/elmo/wireguard.nix new file mode 100644 index 0000000..7d56062 --- /dev/null +++ b/hostnix/elmo/wireguard.nix @@ -0,0 +1,32 @@ +{ pkgs, ... }: + +{ + networking.nat = { + enable = true; + enableIPv6 = true; + externalInterface = "enp3s0f0"; + internalInterfaces = [ "wg0" ]; + }; + + networking.wg-quick.interfaces = { + wg0 = { + address = [ "172.28.92.1/24" "fd61:754f:ebd3:1c5c::1/64" ]; + listenPort = 51820; + privateKeyFile = "/var/secrets/wg0.key"; + postUp = '' + ${pkgs.iptables}/bin/iptables -t nat -A POSTROUTING -o enp3s0f0 -j MASQUERADE + ${pkgs.iptables}/bin/ip6tables -t nat -A POSTROUTING -o enp3s0f0 -j MASQUERADE + ''; + preDown = '' + ${pkgs.iptables}/bin/iptables -t nat -D POSTROUTING -o enp3s0f0 -j MASQUERADE + ${pkgs.iptables}/bin/ip6tables -t nat -D POSTROUTING -o enp3s0f0 -j MASQUERADE + ''; + peers = [ { + publicKey = "ZfJaZgG8e2neWJBWcN3cZsDd740Zq+sW/2pmBqSgbRI="; + allowedIPs = [ "172.28.92.2" "fd61:754f:ebd3:1c5c::2" ]; + } ]; + }; + }; + + networking.firewall.allowedUDPPorts = [ 51820 ]; +} -- cgit v1.3.1