2024-03-28 16:35:03 +01:00
|
|
|
{
|
|
|
|
config,
|
2024-03-29 20:38:51 +01:00
|
|
|
lib,
|
2024-03-28 16:35:03 +01:00
|
|
|
secrets,
|
|
|
|
...
|
|
|
|
}: {
|
2024-02-24 19:36:29 +01:00
|
|
|
systemd.network = {
|
|
|
|
config = {
|
|
|
|
routeTables = {
|
2024-03-29 20:36:24 +01:00
|
|
|
"wg-sigma-public" = 42;
|
|
|
|
"wg-sigma-p2p" = 6881;
|
2024-02-24 19:36:29 +01:00
|
|
|
};
|
|
|
|
};
|
2024-02-28 00:49:48 +01:00
|
|
|
|
2024-02-24 19:36:29 +01:00
|
|
|
# The following establishes a wireguard tunnel to alpha and configures
|
|
|
|
# receiving traffic destined for 49.13.33.75. This allows us to have a
|
|
|
|
# public address even though we are behind NAT.
|
|
|
|
netdevs."50-wg-sigma-public" = {
|
|
|
|
netdevConfig = {
|
|
|
|
Name = "wg-sigma-public";
|
|
|
|
Kind = "wireguard";
|
|
|
|
};
|
|
|
|
wireguardConfig = {
|
2024-03-29 20:38:51 +01:00
|
|
|
PrivateKeyFile = config.age.secrets.wireguard-private-key-file-sigma.path;
|
2024-02-24 19:36:29 +01:00
|
|
|
};
|
|
|
|
wireguardPeers = [
|
|
|
|
{
|
|
|
|
wireguardPeerConfig = {
|
|
|
|
PublicKey = "AlphazUR/z+1DRCFSvxTeKPIJnyPQvYsDoSgESvqJhM=";
|
|
|
|
PresharedKeyFile = config.age.secrets.wireguard-preshared-key-file.path;
|
|
|
|
Endpoint = "alpha.caspervk.net:51820";
|
|
|
|
# Keep NAT mappings and stateful firewalls open at the ISP
|
|
|
|
PersistentKeepalive = 25;
|
|
|
|
# AllowedIPs is both an ACL for incoming traffic, as well as a
|
|
|
|
# routing table specifying to which peer outgoing traffic should be
|
|
|
|
# sent. We want to allow incoming traffic from any address on the
|
|
|
|
# internet (routed through alpha), but only replies to this should
|
|
|
|
# be routed back over wireguard. Unlike if we had used NAT, IP
|
|
|
|
# routes are stateless, so we have no notion of "replies". Instead,
|
|
|
|
# we add these routes to a specific routing table and configure a
|
|
|
|
# routing policy rule to only use it for packets being sent as the
|
|
|
|
# public IP.
|
2024-03-05 22:57:41 +01:00
|
|
|
AllowedIPs = ["0.0.0.0/0"];
|
2024-02-24 19:36:29 +01:00
|
|
|
RouteTable = "wg-sigma-public";
|
|
|
|
};
|
|
|
|
}
|
|
|
|
];
|
|
|
|
};
|
|
|
|
networks."wg-sigma-public" = {
|
|
|
|
name = "wg-sigma-public";
|
2024-03-05 22:57:41 +01:00
|
|
|
address = ["49.13.33.75/32"];
|
2024-02-24 19:36:29 +01:00
|
|
|
routingPolicyRules = [
|
|
|
|
{
|
2024-05-10 16:44:08 +02:00
|
|
|
# The postfix systemd service has
|
|
|
|
# RestrictNetworkInterfaces=wg-sigma-public, but that does not tell
|
|
|
|
# it to use the correct routing table.
|
2024-02-24 19:36:29 +01:00
|
|
|
routingPolicyRuleConfig = {
|
2024-05-10 16:44:08 +02:00
|
|
|
Priority = 10;
|
|
|
|
User = config.services.postfix.user;
|
2024-02-24 19:36:29 +01:00
|
|
|
Table = "wg-sigma-public";
|
|
|
|
};
|
|
|
|
}
|
2024-05-07 00:40:13 +02:00
|
|
|
{
|
|
|
|
# Allow hosts on the local network to contact us directly on the
|
|
|
|
# public address instead of routing the packet through Wireguard and
|
|
|
|
# back again.
|
|
|
|
routingPolicyRuleConfig = {
|
2024-05-10 16:44:08 +02:00
|
|
|
Priority = 500;
|
2024-05-07 00:40:13 +02:00
|
|
|
From = "49.13.33.75/32";
|
|
|
|
To = "192.168.0.0/24";
|
|
|
|
Table = "main";
|
|
|
|
};
|
|
|
|
}
|
2024-04-26 01:25:50 +02:00
|
|
|
{
|
2024-05-10 16:44:08 +02:00
|
|
|
# See the AllowedIPs comment above for why this is necessary
|
2024-04-26 01:25:50 +02:00
|
|
|
routingPolicyRuleConfig = {
|
2024-05-10 16:44:08 +02:00
|
|
|
Priority = 1000;
|
|
|
|
From = "49.13.33.75/32";
|
2024-04-26 01:25:50 +02:00
|
|
|
Table = "wg-sigma-public";
|
|
|
|
};
|
|
|
|
}
|
2024-02-24 19:36:29 +01:00
|
|
|
];
|
|
|
|
};
|
2024-02-28 00:49:48 +01:00
|
|
|
|
|
|
|
# The following establishes a wireguard tunnel to alpha and configures
|
2024-03-29 20:36:24 +01:00
|
|
|
# receiving traffic destined for the sigma-p2p address. This allows the
|
|
|
|
# server to have a public address and help others sail the high seas even
|
|
|
|
# though it is behind NAT.
|
2024-02-28 00:49:48 +01:00
|
|
|
netdevs."51-wg-sigma-p2p" = {
|
|
|
|
netdevConfig = {
|
|
|
|
Name = "wg-sigma-p2p";
|
|
|
|
Kind = "wireguard";
|
|
|
|
};
|
|
|
|
wireguardConfig = {
|
2024-03-29 20:38:51 +01:00
|
|
|
PrivateKeyFile = config.age.secrets.wireguard-private-key-file-sigma.path;
|
2024-02-28 00:49:48 +01:00
|
|
|
};
|
|
|
|
wireguardPeers = [
|
|
|
|
{
|
|
|
|
wireguardPeerConfig = {
|
|
|
|
PublicKey = "AlphazUR/z+1DRCFSvxTeKPIJnyPQvYsDoSgESvqJhM=";
|
|
|
|
PresharedKeyFile = config.age.secrets.wireguard-preshared-key-file.path;
|
|
|
|
Endpoint = "alpha.caspervk.net:51821";
|
|
|
|
PersistentKeepalive = 25;
|
2024-03-05 22:57:41 +01:00
|
|
|
AllowedIPs = ["0.0.0.0/0"];
|
2024-02-28 00:49:48 +01:00
|
|
|
RouteTable = "wg-sigma-p2p";
|
|
|
|
};
|
|
|
|
}
|
|
|
|
];
|
|
|
|
};
|
|
|
|
networks."wg-sigma-p2p" = {
|
|
|
|
name = "wg-sigma-p2p";
|
2024-05-10 18:50:22 +02:00
|
|
|
address = ["${secrets.hosts.sigma.sigma-p2p-ip-address}/32"];
|
2024-02-28 00:49:48 +01:00
|
|
|
routingPolicyRules = [
|
|
|
|
{
|
2024-05-10 16:44:08 +02:00
|
|
|
# The deluge systemd service has
|
|
|
|
# RestrictNetworkInterfaces=wg-sigma-p2p, but that does not tell it
|
|
|
|
# to use the correct routing table.
|
2024-02-28 00:49:48 +01:00
|
|
|
routingPolicyRuleConfig = {
|
2024-05-10 16:44:08 +02:00
|
|
|
Priority = 10;
|
|
|
|
User = config.services.deluge.user;
|
2024-02-28 00:49:48 +01:00
|
|
|
Table = "wg-sigma-p2p";
|
|
|
|
};
|
|
|
|
}
|
2024-03-29 20:38:51 +01:00
|
|
|
{
|
|
|
|
routingPolicyRuleConfig = {
|
2024-05-10 16:44:08 +02:00
|
|
|
Priority = 1000;
|
2024-05-10 18:50:22 +02:00
|
|
|
From = "${secrets.hosts.sigma.sigma-p2p-ip-address}/32";
|
2024-03-29 20:38:51 +01:00
|
|
|
Table = "wg-sigma-p2p";
|
|
|
|
};
|
|
|
|
}
|
2024-02-28 00:49:48 +01:00
|
|
|
];
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2024-03-29 20:38:51 +01:00
|
|
|
# Force explicit firewall configuration to ensure we allow the right services
|
|
|
|
# on the right interfaces.
|
|
|
|
networking.firewall = {
|
|
|
|
allowedTCPPorts = lib.mkForce [];
|
|
|
|
allowedUDPPorts = lib.mkForce [];
|
|
|
|
allowedTCPPortRanges = lib.mkForce [];
|
|
|
|
allowedUDPPortRanges = lib.mkForce [];
|
|
|
|
interfaces = {
|
|
|
|
"enp5s0" = {
|
2024-04-16 01:49:39 +02:00
|
|
|
allowedTCPPorts = [
|
2024-05-10 16:36:10 +02:00
|
|
|
1234 # ad hoc
|
|
|
|
1337 # ad hoc
|
2024-05-09 17:24:46 +02:00
|
|
|
139 # Samba
|
2024-05-10 20:34:38 +02:00
|
|
|
22000 # syncthing
|
2024-04-16 01:49:39 +02:00
|
|
|
22 # SSH
|
2024-04-26 01:25:50 +02:00
|
|
|
25 # Mail SMTP
|
2024-04-22 23:59:18 +02:00
|
|
|
443 # Caddy
|
2024-05-09 17:24:46 +02:00
|
|
|
445 # Samba
|
2024-04-26 01:25:50 +02:00
|
|
|
465 # Mail ESMTP
|
2024-05-10 16:36:10 +02:00
|
|
|
8000 # ad hoc
|
|
|
|
8080 # ad hoc
|
2024-04-26 01:25:50 +02:00
|
|
|
80 # Caddy
|
|
|
|
993 # Mail IMAPS
|
2024-04-16 01:49:39 +02:00
|
|
|
];
|
2024-05-10 16:36:10 +02:00
|
|
|
allowedUDPPorts = [
|
|
|
|
139 # Samba
|
2024-05-10 20:34:38 +02:00
|
|
|
21027 # syncthing
|
|
|
|
22000 # syncthing
|
2024-05-10 16:36:10 +02:00
|
|
|
445 # Samba
|
|
|
|
];
|
2024-03-29 20:38:51 +01:00
|
|
|
};
|
|
|
|
"wg-sigma-public" = {
|
2024-04-16 01:49:39 +02:00
|
|
|
allowedTCPPorts = [
|
2024-05-10 16:36:10 +02:00
|
|
|
1234 # ad hoc
|
|
|
|
1337 # ad hoc
|
2024-05-10 20:34:38 +02:00
|
|
|
22000 # syncthing
|
2024-04-16 01:49:39 +02:00
|
|
|
22 # SSH
|
2024-04-26 01:25:50 +02:00
|
|
|
25 # Mail SMTP
|
2024-04-16 01:49:39 +02:00
|
|
|
443 # Caddy
|
2024-04-26 01:25:50 +02:00
|
|
|
465 # Mail ESMTP
|
2024-05-10 16:36:10 +02:00
|
|
|
8000 # ad hoc
|
|
|
|
8080 # ad hoc
|
2024-04-26 01:25:50 +02:00
|
|
|
80 # Caddy
|
|
|
|
993 # Mail IMAPS
|
2024-04-16 01:49:39 +02:00
|
|
|
];
|
2024-05-10 20:34:38 +02:00
|
|
|
allowedUDPPorts = [
|
|
|
|
21027 # syncthing
|
|
|
|
22000 # syncthing
|
|
|
|
];
|
2024-03-29 20:38:51 +01:00
|
|
|
};
|
|
|
|
"wg-sigma-p2p" = {
|
2024-04-16 01:49:39 +02:00
|
|
|
allowedTCPPorts = [
|
2024-04-22 23:59:18 +02:00
|
|
|
60881 # Deluge
|
|
|
|
];
|
|
|
|
allowedUDPPorts = [
|
|
|
|
60881 # Deluge
|
2024-04-16 01:49:39 +02:00
|
|
|
];
|
2024-03-29 20:38:51 +01:00
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2024-02-24 19:36:29 +01:00
|
|
|
age.secrets.wireguard-preshared-key-file = {
|
2024-03-28 16:35:03 +01:00
|
|
|
file = "${secrets}/secrets/wireguard-preshared-key-file.age";
|
2024-05-09 17:26:55 +02:00
|
|
|
mode = "440";
|
2024-02-24 19:36:29 +01:00
|
|
|
owner = "root";
|
|
|
|
group = "systemd-network";
|
|
|
|
};
|
|
|
|
|
2024-03-29 20:38:51 +01:00
|
|
|
age.secrets.wireguard-private-key-file-sigma = {
|
|
|
|
file = "${secrets}/secrets/wireguard-private-key-file-sigma.age";
|
2024-05-09 17:26:55 +02:00
|
|
|
mode = "440";
|
2024-02-24 19:36:29 +01:00
|
|
|
owner = "root";
|
|
|
|
group = "systemd-network";
|
|
|
|
};
|
|
|
|
}
|