Genesis buttoned up
Removed lots of overlays that are redundant now Added copier to home tools Added static DHCP leases to dnsmasq Improved router Added ability to read Jinja2 template files
This commit is contained in:
@@ -15,7 +15,7 @@
|
||||
];
|
||||
|
||||
greg.home = true;
|
||||
greg.gnome.enable = true;
|
||||
greg.gnome.enable = false;
|
||||
|
||||
# Bootloader.
|
||||
boot.loader = {
|
||||
|
||||
+36
-10
@@ -4,17 +4,17 @@ let
|
||||
extraHosts = builtins.concatStringsSep "\n" [
|
||||
# Local hosts
|
||||
"10.42.0.1 switch"
|
||||
"10.42.1.1 router"
|
||||
"10.42.1.2 2maccabees 2maccabees.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan jellyfin jellyfin.thehellings.lan"
|
||||
"10.42.1.1 router genesis genesis.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan jellyfin jellyfin.thehellings.lan"
|
||||
#"10.42.1.2 2maccabees 2maccabees.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan jellyfin jellyfin.thehellings.lan"
|
||||
"10.42.1.3 printer"
|
||||
"10.42.1.4 chronicles nas"
|
||||
"10.42.1.12 tv"
|
||||
|
||||
# Tailscale hosts
|
||||
"100.90.74.19 jude.me.ts"
|
||||
"100.99.244.92 dns.me.ts 2maccabees.me.ts smart.me.ts jellyfin.me.ts"
|
||||
"100.119.228.115 chronicles.me.ts nas.me.ts"
|
||||
"100.115.57.8 linode.me.ts"
|
||||
"100.90.74.19 jude.shire-zebra.ts.net"
|
||||
"100.99.244.92 dns.shire-zebra.ts.net 2maccabees.shire-zebra.ts.net smart.shire-zebra.ts.net jellyfin.shire-zebra.ts.net"
|
||||
"100.119.228.115 chronicles.shire-zebra.ts.net nas.shire-zebra.ts.net"
|
||||
"100.115.57.8 linode.shire-zebra.ts.net"
|
||||
|
||||
# Dev hosts
|
||||
"10.42.101.1 icdm.lan wiki.icdm.lan *.icdm.lan"
|
||||
@@ -33,13 +33,13 @@ in
|
||||
domain = "thehellings.lan";
|
||||
dhcp-range = [
|
||||
# "${lanDevice},10.42.0.1,10.42.1.255,255.255.0.0,static"
|
||||
"${lanDevice},10.42.2.1,10.42.2.255,255.255.0.0,12h"
|
||||
"${lanDevice},10.43.2.1,10.43.2.255,255.255.0.0,12h"
|
||||
"vlan66@${lanDevice},192.168.66.3,192.168.66.150,255.255.255.0,12h"
|
||||
"vlan67@${lanDevice},192.168.67.3,192.168.67.150,12h"
|
||||
];
|
||||
dhcp-option = [
|
||||
"${lanDevice},option:router,10.42.1.1"
|
||||
"${lanDevice},option:dns-server,10.42.1.2,1.1.1.1"
|
||||
"${lanDevice},option:router,10.43.1.1"
|
||||
"${lanDevice},option:dns-server,10.43.1.2,1.1.1.1"
|
||||
"${lanDevice},option:domain-search,thehellings.lan"
|
||||
|
||||
"vlan66@${lanDevice},option:router,192.168.66.1"
|
||||
@@ -48,6 +48,33 @@ in
|
||||
"vlan67@${lanDevice},option:router,192.168.67.1"
|
||||
"vlan67@${lanDevice},option:dns-server,192.168.67.2"
|
||||
];
|
||||
dhcp-host = [
|
||||
# Static IPs for things in the IOT range
|
||||
"98:da:c4:77:7f:4d,192.168.66.102"
|
||||
"28:87:ba:0e:ca:da,192.168.66.74" # KS200M switch
|
||||
"8c:49:62:aa:58:60,192.168.66.108" # Roku, HiHandsome
|
||||
"28:87:ba:0e:c9:fd,192.168.66.75"
|
||||
"4c:a1:61:05:cd:52,192.168.66.61"
|
||||
"8c:85:80:1c:f9:d1,192.168.66.104"
|
||||
"48:d6:d5:5d:81:21,192.168.66.65" # Google Home
|
||||
"ac:84:c6:5e:4b:28,192.168.66.100"
|
||||
"d8:0d:17:19:60:62,192.168.66.112"
|
||||
"0c:80:63:41:6c:5d,192.168.66.98" # HS200 switch
|
||||
"0c:80:63:41:74:73,192.168.66.106"
|
||||
"0c:80:63:41:6e:0f,192.168.66.90"
|
||||
"98:da:c4:20:f3:64,192.168.66.6"
|
||||
"98:da:c4:21:1b:2e,192.168.66.85"
|
||||
"98:da:c4:20:ea:db,192.168.66.107" # HS220 switch
|
||||
"f0:03:8c:b3:b0:f6,192.168.66.55" # Roomba
|
||||
"98:da:c4:77:80:18,192.168.66.84"
|
||||
"98:da:c4:77:82:7b,192.168.66.105"
|
||||
"e4:f0:42:61:fa:b5,192.168.66.149" # Google Home-mini
|
||||
"b4:b0:24:9a:14:0e,192.168.66.131"
|
||||
"6c:29:90:3e:e2:02,192.168.66.66" # wiz
|
||||
"54:af:97:83:ed:33,192.168.66.80"
|
||||
"54:af:97:c2:0f:a1,192.168.66.76"
|
||||
"b4:b0:24:9a:12:53,192.168.66.130" # KL125
|
||||
];
|
||||
expand-hosts = true;
|
||||
log-dhcp = true;
|
||||
log-queries = true;
|
||||
@@ -72,7 +99,6 @@ in
|
||||
|
||||
# Allow traffic through
|
||||
networking.firewall = {
|
||||
enable = true;
|
||||
allowedTCPPorts = [ 53 ];
|
||||
allowedUDPPorts = [ 53 67 ];
|
||||
};
|
||||
|
||||
@@ -78,7 +78,6 @@ in
|
||||
# Ensure that both ports are up and running. We keep 8123 directly open because we are on the LAN and sometimes want to connect
|
||||
# directly for troubleshooting Nginx configuration
|
||||
networking.firewall = {
|
||||
enable = true;
|
||||
allowedTCPPorts = [ 80 443 8091 8123 ];
|
||||
};
|
||||
|
||||
|
||||
@@ -1,10 +1,22 @@
|
||||
{ ... }:
|
||||
|
||||
{
|
||||
{ pkgs, config, ... }:
|
||||
let
|
||||
lan = "enp1s0";
|
||||
wan = "enp2s0";
|
||||
iot = "vlan66";
|
||||
in {
|
||||
greg.tailscale.enable = true;
|
||||
|
||||
# Really, why do I still have to force-disable this crap?
|
||||
boot.kernel.sysctl = {
|
||||
"net.ipv6.conf.${lan}.disable_ipv6" = true;
|
||||
"net.ipv6.conf.${wan}.disable_ipv6" = true;
|
||||
"net.ipv6.conf.${iot}.disable_ipv6" = true;
|
||||
"net.ipv6.conf.lo.disable_ipv6" = true;
|
||||
};
|
||||
|
||||
networking = {
|
||||
enableIPv6 = false;
|
||||
networkmanager.enable = pkgs.lib.mkForce false;
|
||||
#defaultGateway = "10.42.1.1";
|
||||
# 100.100.100.100 is the tailscale DNS
|
||||
nameservers = [
|
||||
@@ -14,37 +26,52 @@
|
||||
];
|
||||
interfaces = {
|
||||
# This is our WAN port
|
||||
enp2s0 = {
|
||||
"${wan}" = {
|
||||
useDHCP = true;
|
||||
name = "wan";
|
||||
};
|
||||
|
||||
# This is our LAN port
|
||||
enp1s0.ipv4.addresses = [ {
|
||||
address = "10.43.1.1";
|
||||
prefixLength = 16;
|
||||
} ];
|
||||
"${lan}" = {
|
||||
ipv4.addresses = [ {
|
||||
address = "10.42.1.1";
|
||||
prefixLength = 16;
|
||||
} ];
|
||||
useDHCP = false;
|
||||
};
|
||||
wlan0.useDHCP = false;
|
||||
|
||||
vlan66.ipv4.addresses = [ {
|
||||
address = "192.168.66.2";
|
||||
prefixLength = 24;
|
||||
} ];
|
||||
"${iot}" = {
|
||||
useDHCP = false;
|
||||
ipv4.addresses = [ {
|
||||
address = "192.168.66.2";
|
||||
prefixLength = 24;
|
||||
} ];
|
||||
};
|
||||
};
|
||||
|
||||
vlans = {
|
||||
vlan66 = {
|
||||
"${iot}" = {
|
||||
id = 66;
|
||||
interface = "enp2s0";
|
||||
interface = lan;
|
||||
};
|
||||
};
|
||||
|
||||
firewall.enable = false;
|
||||
# Router portion here
|
||||
nftables = let
|
||||
myvars = {
|
||||
lanInterfaces = [ lan ];
|
||||
wanInterface = wan;
|
||||
limitedLan = [ iot ];
|
||||
tcpPorts = config.networking.firewall.allowedTCPPorts;
|
||||
udpPorts = config.networking.firewall.allowedUDPPorts;
|
||||
};
|
||||
in {
|
||||
enable = true;
|
||||
rulesetFile = pkgs.template "router.nft" myvars ./nftables.nft;
|
||||
};
|
||||
};
|
||||
|
||||
# Open ports in the firewall.
|
||||
# networking.firewall.allowedTCPPorts = [ ... ];
|
||||
# networking.firewall.allowedUDPPorts = [ ... ];
|
||||
# Or disable the firewall altogether.
|
||||
# networking.firewall.enable = false;
|
||||
|
||||
fileSystems."/media" = {
|
||||
device = "10.42.1.4:/volume1/video/";
|
||||
|
||||
@@ -0,0 +1,47 @@
|
||||
#!/usr/bin/env nft -f
|
||||
|
||||
table ip filter {
|
||||
chain output {
|
||||
type filter hook output priority 100; policy accept;
|
||||
}
|
||||
|
||||
chain input {
|
||||
type filter hook input priority 0; policy drop;
|
||||
|
||||
iifname lo accept
|
||||
|
||||
# Open the specific ports that we allow
|
||||
{% for port in tcpPorts %}
|
||||
iifname { {{ lanInterfaces | join(", ") }}, "tailscale0" } tcp dport {{ port }} accept
|
||||
{% endfor %}
|
||||
{% for port in udpPorts %}
|
||||
iifname { {{ lanInterfaces | join(", ") }}, "tailscale0" } udp dport {{ port }} accept
|
||||
{% endfor %}
|
||||
|
||||
iifname { {{ lanInterfaces | join(", ") }} } accept comment "Allows LAN traffic and outgoing"
|
||||
iifname { {{ wanInterface }} } ct state { established, related } accept comment "Allows existing connections"
|
||||
iifname { {{ wanInterface }} } icmp type { echo-request, destination-unreachable, time-exceeded } counter accept comment "Allow some ICMP traffic"
|
||||
iifname { {{ wanInterface }} } counter drop comment "Drop other incoming traffic, and count how much"
|
||||
}
|
||||
chain forward {
|
||||
type filter hook forward priority 0; policy drop;
|
||||
iifname { {{ (lanInterfaces + limitedLan) | join(", ") }} } oifname { {{ wanInterface }} } accept comment "Forward LAN to WAN"
|
||||
iifname { {{ wanInterface }} } oifname { {{ (lanInterfaces + limitedLan) | join(", ") }} } ct state established, related accept comment "Allow incoming established traffic"
|
||||
}
|
||||
}
|
||||
|
||||
table ip nat {
|
||||
chain postrouting {
|
||||
type nat hook postrouting priority 100; policy accept;
|
||||
oifname { {{ wanInterface }} } masquerade
|
||||
}
|
||||
}
|
||||
|
||||
table ip6 filter {
|
||||
chain input {
|
||||
type filter hook input priority 0; policy drop;
|
||||
}
|
||||
chain forward {
|
||||
type filter hook forward priority 0; policy drop;
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user