summaryrefslogtreecommitdiff
path: root/hostnix/creep/wifi-vpn.nix
blob: ad94f4bf24712da93c58ce02dee6d8f5ab26f385 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
# TODO not working?

{ pkgs, ... }:

{
  boot.kernel.sysctl."net.ipv4.ip_forward" = 1;

  # Manual configuration on popfresh.mou.town:
  # /etc/wireguard/wg0.conf
  # # firewall-cmd --add-port=51820/udp
  # # systemctl enable --now wg-quick@wg0
  networking.wg-quick.interfaces = {
    wg0 = {
      address = [ "172.28.89.2/24" ];
      privateKeyFile = "/root/wg0.key";
      # wg-quick normally adds routes for AllowedIPs to the default table.
      # Specify a non-default table to instead use policy-based routing.
      # Using netns may be an alternative.
      table = "89";
      # IP masquerade (SNAT) anything from the WiFi AP.
      postUp = ''
        ${pkgs.iptables}/bin/iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE
        ${pkgs.iproute2}/bin/ip rule add iif wlp1s0u1u3 lookup 89
      '';
      preDown = ''
        ${pkgs.iptables}/bin/iptables -t nat -D POSTROUTING -o wg0 -j MASQUERADE
        ${pkgs.iproute2}/bin/ip rule del iif wlp1s0u1u3 lookup 89
      '';
      peers = [ {
        publicKey = "iIRCcLGBvo0LBCysJKa5sbTs/Y4VR4PUDHMkoaU6sgo=";
        allowedIPs = [ "0.0.0.0/0" ];
        endpoint = "creepgw.mou.fo:51820";
        persistentKeepalive = 25;  # keep NAT rules alive
      } ];
    };
  };

  services.hostapd = {
    enable = true;
    radios.wlp1s0u1u3 = {
      band = "5g";
      # Wasn't able to get Auto Channel Selection working, so specify a band
      # that should allow for High Throughput 40 MHz (HT40).
      channel = 40;
      countryCode = "AU";
      # The network must have the same name as the radio.
      networks.wlp1s0u1u3 = {
        ssid = "The Up Over";
        authentication = {
          mode = "wpa3-sae-transition";
          wpaPassword = "comingtoamerica";
          saePasswords = [ { password = "comingtoamerica"; } ];
        };
      };
    };
  };

  networking.interfaces.wlp1s0u1u3.ipv4.addresses = [ {
    address = "172.16.175.1";
    prefixLength = 24;
  } ];

  services.kea.dhcp4 = {
    enable = true;
    settings = {
      interfaces-config = {
        interfaces = [ "wlp1s0u1u3" ];
      };
      lease-database = {
        type = "memfile";
        persist = true;
        name = "/var/lib/kea/dhcp4.leases";
      };
      subnet4 = [
        {
          id = 1;
          subnet = "172.16.175.0/24";
          pools = [ { pool = "172.16.175.100 - 172.16.175.240"; } ];
          option-data = [ {
            name = "routers";
            data = "172.16.175.1";
          } {
            name = "domain-name-servers";
            data = "1.1.1.1, 1.0.0.1";
          } ];
        }
      ];
    };
  };
  # Ensure interface is available to serve DHCP.
  systemd.services.kea-dhcp4-server = {
    requires = [ "network-addresses-wlp1s0u1u3.service" ];
  };

  # Generated entropy helps prevent WiFi AP from blocking.
  services.haveged.enable = true;

  # Reverse path forwarding has complications with multiple interfaces, like
  # connectivity issues when WiFi and wired are on the same network.
  networking.firewall.checkReversePath = false;
}