summaryrefslogtreecommitdiff
path: root/hosts/skadhi/networking
diff options
context:
space:
mode:
Diffstat (limited to 'hosts/skadhi/networking')
-rw-r--r--hosts/skadhi/networking/default.nix38
-rw-r--r--hosts/skadhi/networking/ruleset.nft237
2 files changed, 275 insertions, 0 deletions
diff --git a/hosts/skadhi/networking/default.nix b/hosts/skadhi/networking/default.nix
new file mode 100644
index 00000000..4d6edd97
--- /dev/null
+++ b/hosts/skadhi/networking/default.nix
@@ -0,0 +1,38 @@
1{ flake, config, ... }:
2{
3 imports = with flake.nixosModules.systemProfiles; [
4 networkmanager
5 ];
6
7 config = {
8 environment.persistence."/persistent".directories = [
9 "/etc/NetworkManager/system-connections"
10 ];
11
12 networking = {
13 domain = "yggdrasil";
14 search = [ "yggdrasil" ];
15 hosts = {
16 "127.0.0.1" = [ "${config.networking.hostName}.yggdrasil" config.networking.hostName ];
17 "::1" = [ "${config.networking.hostName}.yggdrasil" config.networking.hostName ];
18 };
19
20 firewall.enable = false;
21 nftables = {
22 enable = true;
23 rulesetFile = ./ruleset.nft;
24 };
25
26 useDHCP = false;
27 useNetworkd = true;
28 };
29
30 environment.etc."NetworkManager/dnsmasq.d/yggdrasil.conf" = {
31 text = ''
32 server=/yggdrasil/2a03:4000:52:ada:1:1::@yggdrasil
33 server=/141.10.in-addr.arpa/2a03:4000:52:ada:1:1::@yggdrasil
34 server=/1.0.0.0.a.d.a.0.2.5.0.0.0.0.0.4.3.0.a.2.ip6.arpa/2a03:4000:52:ada:1:1::@yggdrasil
35 '';
36 };
37 };
38}
diff --git a/hosts/skadhi/networking/ruleset.nft b/hosts/skadhi/networking/ruleset.nft
new file mode 100644
index 00000000..94e21b10
--- /dev/null
+++ b/hosts/skadhi/networking/ruleset.nft
@@ -0,0 +1,237 @@
1define icmp_protos = { ipv6-icmp, icmp, igmp }
2
3table arp filter {
4 limit lim_arp {
5 rate over 50 mbytes/second burst 50 mbytes
6 }
7
8 counter arp-rx {}
9 counter arp-tx {}
10
11 counter arp-ratelimit-rx {}
12 counter arp-ratelimit-tx {}
13
14 chain input {
15 type filter hook input priority filter
16 policy accept
17
18 limit name lim_arp counter name arp-ratelimit-rx drop
19
20 counter name arp-rx
21 }
22
23 chain output {
24 type filter hook output priority filter
25 policy accept
26
27 limit name lim_arp counter name arp-ratelimit-tx drop
28
29 counter name arp-tx
30 }
31}
32
33table inet filter {
34 limit lim_reject {
35 rate over 1000/second burst 1000 packets
36 }
37
38 limit lim_icmp {
39 rate over 50 mbytes/second burst 50 mbytes
40 }
41
42 counter invalid-fw {}
43
44 counter fw-lo {}
45
46 counter reject-ratelimit-fw {}
47 counter reject-fw {}
48 counter reject-tcp-fw {}
49 counter reject-icmp-fw {}
50
51
52 counter invalid-rx {}
53 counter rx-lo {}
54 counter invalid-local4-rx {}
55 counter invalid-local6-rx {}
56
57 counter icmp-ratelimit-rx {}
58 counter icmp-rx {}
59
60 counter ssh-rx {}
61 counter mosh-rx {}
62 counter wg-rx {}
63 counter yggdrasil-gre-rx {}
64 counter miniserve-rx {}
65 counter ausweisapp2-rx {}
66
67 counter established-rx {}
68
69 counter reject-ratelimit-rx {}
70 counter reject-rx {}
71 counter reject-tcp-rx {}
72 counter reject-icmp-rx {}
73
74
75 counter tx-lo {}
76
77 counter icmp-ratelimit-tx {}
78 counter icmp-tx {}
79
80 counter ssh-tx {}
81 counter mosh-tx {}
82 counter wg-tx {}
83 counter yggdrasil-gre-tx {}
84 counter miniserve-tx {}
85
86 counter tx {}
87
88 counter fw-libvirt {}
89 counter libvirt-dhcp {}
90 counter libvirt-dns {}
91
92
93 chain forward_tmp {}
94 chain forward {
95 type filter hook forward priority filter
96 policy drop
97
98
99 ct state invalid log level debug prefix "drop invalid forward: " counter name invalid-fw drop
100
101
102 iifname lo counter name fw-lo accept
103
104 jump forward_tmp
105
106 iifname virbr0 oifname != {lo, wgrz, yggdrasil-wg-4, yggdrasil-wg-6, yggdrasil, ip6tnl, ip6gre, yggre-surtr-6, yggre-surtr-4, yggre-vidhar-4} counter name fw-libvirt accept
107 oifname virbr0 ct state {established, related} counter name fw-libvirt accept
108
109
110 limit name lim_reject log level debug prefix "drop forward: " counter name reject-ratelimit-fw drop
111 log level debug prefix "reject forward: " counter name reject-fw
112 meta l4proto tcp ct state new counter name reject-tcp-fw reject with tcp reset
113 ct state new counter name reject-icmp-fw reject
114 }
115
116 ct helper ftp-standard {
117 type "ftp" protocol tcp
118 }
119 chain input_pr_tmp {
120 # tcp dport 2121 ct helper set "ftp-standard"
121 }
122 chain input_pr {
123 type filter hook prerouting priority 0
124
125 jump input_pr_tmp
126 }
127
128 chain input_tmp {
129 # tcp dport 2121 accept
130 }
131 chain input {
132 type filter hook input priority filter
133 policy drop
134
135
136 ct state invalid log level debug prefix "drop invalid input: " counter name invalid-rx drop
137
138
139 iifname lo counter name rx-lo accept
140 iif != lo ip daddr 127.0.0.1/8 counter name invalid-local4-rx reject
141 iif != lo ip6 daddr ::1/128 counter name invalid-local6-rx reject
142
143 meta l4proto $icmp_protos limit name lim_icmp counter name icmp-ratelimit-rx drop
144 meta l4proto $icmp_protos counter name icmp-rx accept
145
146 jump input_tmp
147
148 tcp dport 22 counter name ssh-rx accept
149 udp dport 60000-61000 counter name mosh-rx accept
150
151 tcp dport 8080 counter name miniserve-rx accept
152 udp dport 24727 counter name ausweisapp2-rx accept
153
154 udp dport 51820-51822 counter name wg-rx accept
155 iifname "yggdrasil-wg-*" meta l4proto gre counter name yggdrasil-gre-rx accept
156
157 iifname virbr0 udp dport 67 counter name libvirt-dhcp accept
158 iifname virbr0 udp dport 547 counter name libvirt-dhcp accept
159 iifname virbr0 udp dport 53 counter name libvirt-dns accept
160 iifname virbr0 tcp dport 53 counter name libvirt-dns accept
161
162 iifname wgrz ip saddr 10.200.116.1 meta l4proto gre counter accept
163
164 ct state {established, related} counter name established-rx accept
165
166
167 limit name lim_reject log level debug prefix "drop input: " counter name reject-ratelimit-rx drop
168 log level debug prefix "reject input: " counter name reject-rx
169 meta l4proto tcp ct state new counter name reject-tcp-rx reject with tcp reset
170 ct state new counter name reject-icmp-rx reject
171 }
172
173 chain output {
174 type filter hook output priority filter
175 policy accept
176
177
178 oifname lo counter name tx-lo accept
179
180 meta l4proto $icmp_protos limit name lim_icmp counter name icmp-ratelimit-tx drop
181 meta l4proto $icmp_protos counter name icmp-tx accept
182
183
184 tcp sport 22 counter name ssh-tx
185 udp sport 60000-61000 counter name mosh-tx
186
187 udp sport 51820-51822 counter name wg-tx
188 iifname "yggdrasil-wg-*" meta l4proto gre counter name yggdrasil-gre-tx
189
190 tcp sport 8080 counter name miniserve-tx accept
191
192 oifname virbr0 udp sport 67 counter name libvirt-dhcp accept
193 oifname virbr0 udp sport 547 counter name libvirt-dhcp accept
194 oifname virbr0 udp sport 53 counter name libvirt-dns accept
195 oifname virbr0 tcp sport 53 counter name libvirt-dns accept
196
197
198 counter name tx
199 }
200}
201
202table ip nat {
203 counter libvirt-nat {}
204
205 chain postrouting_tmp {}
206 chain postrouting {
207 type nat hook postrouting priority srcnat
208 policy accept
209
210 iifname virbr0 oifname != virbr0 counter name libvirt-nat masquerade
211 jump postrouting_tmp
212 }
213}
214
215table ip6 nat {
216 counter libvirt-nat {}
217
218 chain postrouting {
219 type nat hook postrouting priority srcnat
220 policy accept
221
222 iifname virbr0 oifname != virbr0 counter name libvirt-nat masquerade
223 }
224}
225
226table ip mss_clamp {
227 counter libvirt-mss-clamp {}
228
229 chain postrouting_tmp {}
230 chain postrouting {
231 type filter hook postrouting priority mangle
232 policy accept
233
234 iifname virbr0 oifname != virbr0 tcp flags & (syn|rst) == syn counter name libvirt-mss-clamp tcp option maxseg size set rt mtu
235 jump postrouting_tmp
236 }
237}