blob: 8a790c4f5846a02135cbcf3c836a1bf5a47309c7 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
|
{ pkgs, ... }:
{
boot.kernel.sysctl."net.ipv4.ip_forward" = 1;
networking.wg-quick.interfaces = {
wg0 = {
address = [ "172.28.89.2/24" ];
privateKeyFile = "/root/wg0.key";
# wg-quick normally adds routes for AllowedIPs to the default table.
# Specify a non-default table to instead use policy-based routing.
# Using netns may be an alternative.
table = "89";
# IP masquerade (SNAT) anything from the WiFi AP.
postUp = ''
${pkgs.iptables}/bin/iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE
${pkgs.iproute2}/bin/ip rule add iif wlp1s0u1u3 lookup 89
'';
preDown = ''
${pkgs.iptables}/bin/iptables -t nat -D POSTROUTING -o wg0 -j MASQUERADE
${pkgs.iproute2}/bin/ip rule del iif wlp1s0u1u3 lookup 89
'';
peers = [ {
publicKey = "iIRCcLGBvo0LBCysJKa5sbTs/Y4VR4PUDHMkoaU6sgo=";
allowedIPs = [ "0.0.0.0/0" ];
endpoint = "creepgw.mou.fo:51820";
persistentKeepalive = 25; # keep NAT rules alive
} ];
};
};
services.hostapd = {
enable = true;
radios.wlp1s0u1u3 = {
band = "5g";
# Wasn't able to get Auto Channel Selection working, so specify a band
# that should allow for High Throughput 40 MHz (HT40).
channel = 40;
countryCode = "AU";
# The network must have the same name as the radio.
networks.wlp1s0u1u3 = {
ssid = "The Up Over";
authentication = {
mode = "wpa3-sae-transition";
wpaPassword = "comingtoamerica";
saePasswords = [ { password = "comingtoamerica"; } ];
};
};
};
};
networking.interfaces.wlp1s0u1u3.ipv4.addresses = [ {
address = "172.16.175.1";
prefixLength = 24;
} ];
services.kea.dhcp4 = {
enable = true;
settings = {
interfaces-config = {
interfaces = [ "wlp1s0u1u3" ];
};
lease-database = {
type = "memfile";
persist = true;
name = "/var/lib/kea/dhcp4.leases";
};
subnet4 = [
{
id = 1;
subnet = "172.16.175.0/24";
pools = [ { pool = "172.16.175.100 - 172.16.175.240"; } ];
option-data = [ {
name = "routers";
data = "172.16.175.1";
} {
name = "domain-name-servers";
data = "1.1.1.1, 1.0.0.1";
} ];
}
];
};
};
# Ensure interface is available to serve DHCP.
systemd.services.kea-dhcp4-server = {
requires = [ "network-addresses-wlp1s0u1u3.service" ];
};
# Generated entropy helps prevent WiFi AP from blocking.
services.haveged.enable = true;
# Reverse path forwarding has complications with multiple interfaces, like
# connectivity issues when WiFi and wired are on the same network.
networking.firewall.checkReversePath = false;
}
|