summaryrefslogtreecommitdiff
path: root/hosts/tacitus/network.nix
blob: ee24ad0322d2e7d15fe14fa1d71b4ab15ed71158 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
{ config, lib, ... }:
let
  baseTCP = [
    20
    22
    25
    80
    443
    config.services.grafana.port
    config.services.prometheus.port
  ] ++ lib.mapAttrsToList (_: opt: opt.port) (
    lib.filterAttrs (
      _: e:
      let
        evaluated = builtins.tryEval e;
      in
      evaluated.success && e ? enable && e.enable
    ) config.services.prometheus.exporters
  );

  baseUDP = [
  ];
  baseTCPRanges = [ ];
  baseUDPRanges = [ ];
in
{
  systemd.network = {
    enable = true;
    networks."10-uplink" = {
      matchConfig.Type = "ether";
      networkConfig = {
        DHCP = "ipv4";
        IPv6AcceptRA = "yes";
      };
      linkConfig = {
        RequiredForOnline = "yes";
      };
      ipv6AcceptRAConfig = {
        UseDNS = "yes";
        UseDomains = "yes";
      };
      dns = [
        "192.168.88.1"
        "1.1.1.1"
        "2606:4700:4700:0000:0000:0000:0000:1002"
      ];
    };
  };
  networking = {
    useNetworkd = true;
    nftables.enable = true;
    useDHCP = true;
    firewall = {
      # check  enable = true;
      checkReversePath = false;
      allowedTCPPorts = baseTCP;
      allowedUDPPorts = baseUDP;
      allowedUDPPortRanges = baseUDPRanges;
      allowedTCPPortRanges = baseTCPRanges;
      # TODO: Figure out how to do FW that allows only on the internal ip range
      #interfaces = {
      #  "wg-home" = {
      #   allowedTCPPorts = secureTCP;
      #   allowedUDPPorts = secureUDP;
      #   allowedUDPPortRanges = secureUDPRanges;
      #   allowedTCPPortRanges = secureTCPRanges;
      # };
      #};
    };
  };

}