Files
nixos/hosts/genesis/networking.nix
T

138 lines
2.9 KiB
Nix
Raw Normal View History

2024-10-03 15:21:56 -05:00
{ pkgs, ... }:
2023-08-21 21:22:26 -05:00
let
lan = "ens18";
lanIP = "10.42.1.5";
iot = "ens19";
iotIP = "192.168.66.250";
routerIP = "10.42.1.2";
extraHosts = builtins.readFile ./net/hosts;
2023-09-05 11:06:35 -05:00
adblockUpdate = pkgs.writeShellScriptBin "adblockUpdate" (builtins.readFile ./adblockUpdate.sh);
proxyPort = 3128;
dnsPort = 53;
dhcpPort = 67;
dnsServers = [
"9.9.9.9" # Quad 9
"1.1.1.1" # Cloudflare
"1.0.0.1" # Cloudflare
"149.112.112.112" # Quad 9
];
in
{
greg.tailscale.enable = true;
2023-06-29 00:27:30 -05:00
# Really, why do I still have to force-disable this crap?
boot.kernel.sysctl = {
"net.ipv6.conf.${lan}.disable_ipv6" = true;
"net.ipv6.conf.${iot}.disable_ipv6" = true;
"net.ipv6.conf.lo.disable_ipv6" = true;
};
2023-08-21 21:22:26 -05:00
networking = {
enableIPv6 = false;
networkmanager.enable = pkgs.lib.mkForce false;
defaultGateway = routerIP;
nameservers = dnsServers;
interfaces = {
# This is our LAN port
"${lan}" = {
useDHCP = false;
2024-10-19 01:19:59 -05:00
ipv4.addresses = [
{
address = "${lanIP}";
prefixLength = 16;
}
];
};
2023-06-29 00:27:30 -05:00
"${iot}" = {
useDHCP = false;
2024-10-19 01:19:59 -05:00
ipv4.addresses = [
{
address = "${iotIP}";
prefixLength = 24;
}
];
};
};
firewall = {
enable = false;
allowedUDPPorts = [
dhcpPort
dnsPort
];
allowedTCPPorts = [
dnsPort
proxyPort
80
];
};
nftables.enable = false;
};
2023-06-29 00:27:30 -05:00
environment.etc."hosts.d/local".text = extraHosts;
2023-06-29 00:27:30 -05:00
services = {
#########
# Blind service proxy behind the walls of the VPN
########
_3proxy = {
enable = true;
2024-10-19 01:19:59 -05:00
services = [
{
type = "socks";
auth = [ "strong" ];
bindPort = proxyPort;
acl = [
{
rule = "allow";
users = [ "greg" ];
}
];
}
];
#usersFile = "/run/agenix/3proxy";
denyPrivate = false;
};
2023-09-05 11:06:35 -05:00
kea.dhcp4 = (
import ./networking/dhcp.nix {
inherit
iot
lan
lanIP
routerIP
;
}
);
#########
# dnsmasq config
########
dnsmasq = {
enable = true;
settings = {
domain = "thehellings.lan";
expand-hosts = true;
log-queries = true;
no-hosts = true; # Do not read /etc/hosts, which makes genesis resolve to 127.0.0.2
addn-hosts = "/etc/adblock_hosts";
hostsdir = "/etc/hosts.d/";
server = dnsServers;
};
};
2023-09-05 11:06:35 -05:00
# Update adblock list
cron = {
enable = true;
2024-10-19 01:19:59 -05:00
systemCronJobs = [ "* * * * * root ${adblockUpdate} 2>&1 > /var/log/adblock.log" ];
};
}; # End of services configuration
2023-06-29 00:27:30 -05:00
environment.systemPackages = with pkgs; [
bind
curl # Used by dnsmasq fetching
sqlite
];
2023-06-29 00:27:30 -05:00
}