{ pkgs, ... }: { boot.kernel.sysctl."net.ipv4.ip_forward" = 1; networking.wg-quick.interfaces = { wg0 = { address = [ "172.28.89.2/24" ]; privateKeyFile = "/root/wg0.key"; # wg-quick normally adds routes for AllowedIPs to the default table. # Specify a non-default table to instead use policy-based routing. # Using netns may be an alternative. table = "89"; # IP masquerade (SNAT) anything from the WiFi AP. postUp = '' ${pkgs.iptables}/bin/iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE ${pkgs.iproute2}/bin/ip rule add iif wlp1s0u1u3 lookup 89 ''; preDown = '' ${pkgs.iptables}/bin/iptables -t nat -D POSTROUTING -o wg0 -j MASQUERADE ${pkgs.iproute2}/bin/ip rule del iif wlp1s0u1u3 lookup 89 ''; peers = [ { publicKey = "iIRCcLGBvo0LBCysJKa5sbTs/Y4VR4PUDHMkoaU6sgo="; allowedIPs = [ "0.0.0.0/0" ]; endpoint = "creepgw.mou.fo:51820"; persistentKeepalive = 25; # keep NAT rules alive } ]; }; }; services.hostapd = { enable = true; radios.wlp1s0u1u3 = { band = "5g"; # Wasn't able to get Auto Channel Selection working, so specify a band # that should allow for High Throughput 40 MHz (HT40). channel = 40; countryCode = "AU"; # The network must have the same name as the radio. networks.wlp1s0u1u3 = { ssid = "The Up Over"; authentication = { mode = "wpa3-sae-transition"; wpaPassword = "comingtoamerica"; saePasswords = [ { password = "comingtoamerica"; } ]; }; }; }; }; networking.interfaces.wlp1s0u1u3.ipv4.addresses = [ { address = "172.16.175.1"; prefixLength = 24; } ]; services.kea.dhcp4 = { enable = true; settings = { interfaces-config = { interfaces = [ "wlp1s0u1u3" ]; }; lease-database = { type = "memfile"; persist = true; name = "/var/lib/kea/dhcp4.leases"; }; subnet4 = [ { id = 1; subnet = "172.16.175.0/24"; pools = [ { pool = "172.16.175.100 - 172.16.175.240"; } ]; option-data = [ { name = "routers"; data = "172.16.175.1"; } { name = "domain-name-servers"; data = "1.1.1.1, 1.0.0.1"; } ]; } ]; }; }; # Ensure interface is available to serve DHCP. systemd.services.kea-dhcp4-server = { requires = [ "network-addresses-wlp1s0u1u3.service" ]; }; # Generated entropy helps prevent WiFi AP from blocking. services.haveged.enable = true; # Reverse path forwarding has complications with multiple interfaces, like # connectivity issues when WiFi and wired are on the same network. networking.firewall.checkReversePath = false; }