summaryrefslogtreecommitdiff
path: root/hosts/omega-relay/firewall.nix
blob: c90a903e8934c7318496bd0cd470c4ddd8b88369 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
{ config, lib, pkgs, ... }:
let
  wgHomePort = 16888;
  baseTCP = [
    20
    22
    25
    80
    143
    443
    993
    465
  ];
  baseUDP = [
    wgHomePort # Wireguard
  ];
  baseTCPRanges = [
  ];

  baseUDPRanges = [
  ];

  secureTCP = [
    # config.wilkuu.services.mysql.port
  ];

  secureUDP = [
  ];

  secureTCPRanges = [
  ];

  secureUDPRanges = [
  ];
in
{
  sops.secrets = let 
	secrets = [
	  "wg/home/privateKey" 
	  "wg/home/chrono/PSK" 
	  "wg/home/chrono/PK" 
	  "wg/home/chrono/endpoint" 
	];  
  in lib.genAttrs secrets (name: {
	sopsFile = ../../secrets/${config.networking.hostName}/wireguard.yaml;
	key = lib.removePrefix "wg/" name; 
  });

  networking.wireguard = {
	enable = true; 
	useNetworkd = true; 
	interfaces = {
	  wg-home = {
	    ips = ["192.168.80.100/24"]; 
	    extraOptions = {
		DNS = "192.168.88.1"; 
	    };
	    privateKeyFile = config.sops.secrets."wg/home/privateKey".path; 
	    listenPort = wgHomePort;
	    dynamicEndpointRefreshSeconds = 45;
	    
	    peers = [
	      {
	        allowedIPs = ["192.168.88.0/24" "192.168.80.0/24"]; 
		presharedKeyFile = config.sops.secrets."wg/home/chrono/PSK".path;
		publicKey  = "rP5lJY6ea7BKX40edzqNMJbhfLkSlSwG1FipEufeflk="; 
	    	# endpoint       = "45.138.54.155:16556";
	    	endpoint       = "wilkuu.duckdns.org:16556";
		name = "wg-home-chronosphere"; 

	      } 
	    ]; 
	  }; 
	};
  }; 
  systemd.network.networks."40-wg-home".dns = ["192.168.88.1"];
  systemd.network.enable = true;
  systemd.network.networks."10-uplink" = {
    matchConfig.Name = "ens18";
    # TODO: Cloudinit
    address = ["45.136.141.133/26" "2a12:bec0:650:128::133/64"];   
    gateway = ["45.136.141.129"    "2a12:bec0:650:128::"];
    dns     = ["1.1.1.1"           "2606:4700:4700:0000:0000:0000:0000:1002"];
    linkConfig.RequiredForOnline="yes";
  };
  systemd.network.networks."99-fallback" = {
    matchConfig.Type = "ether";
    networkConfig.DHCP = "ipv4";
    linkConfig.RequiredForOnline="routable";
  };

  networking.useDHCP = false;
  networking.useNetworkd = true;
  networking.nftables.enable = true;
  networking.firewall = {
    enable = true;
    checkReversePath = false;
    allowedTCPPorts = baseTCP;
    allowedUDPPorts = baseUDP;
    allowedUDPPortRanges = baseUDPRanges;
    allowedTCPPortRanges = baseTCPRanges;
    interfaces = {
      "wg-home" = {
        allowedTCPPorts = secureTCP;
        allowedUDPPorts = secureUDP;
        allowedUDPPortRanges = secureUDPRanges;
        allowedTCPPortRanges = secureTCPRanges;
      };
    };
    trustedInterfaces = [
      "docker0"
      "br-*"
      "veth*"
      "vnet*"
      "virbr*"
      "lo"
    ];

  };
}