summaryrefslogtreecommitdiff
path: root/hostnix/elmo/wireguard.nix
blob: 7d56062cfc1b7666c46d6fb4d4da37a504eadc54 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
{ pkgs, ... }:

{
  networking.nat = {
    enable = true;
    enableIPv6 = true;
    externalInterface = "enp3s0f0";
    internalInterfaces = [ "wg0" ];
  };

  networking.wg-quick.interfaces = {
    wg0 = {
      address = [ "172.28.92.1/24" "fd61:754f:ebd3:1c5c::1/64" ];
      listenPort = 51820;
      privateKeyFile = "/var/secrets/wg0.key";
      postUp = ''
        ${pkgs.iptables}/bin/iptables -t nat -A POSTROUTING -o enp3s0f0 -j MASQUERADE
        ${pkgs.iptables}/bin/ip6tables -t nat -A POSTROUTING -o enp3s0f0 -j MASQUERADE
      '';
      preDown = ''
        ${pkgs.iptables}/bin/iptables -t nat -D POSTROUTING -o enp3s0f0 -j MASQUERADE
        ${pkgs.iptables}/bin/ip6tables -t nat -D POSTROUTING -o enp3s0f0 -j MASQUERADE
      '';
      peers = [ {
        publicKey = "ZfJaZgG8e2neWJBWcN3cZsDd740Zq+sW/2pmBqSgbRI=";
        allowedIPs = [ "172.28.92.2" "fd61:754f:ebd3:1c5c::2" ];
      } ];
    };
  };

  networking.firewall.allowedUDPPorts = [ 51820 ];
}