Compare commits
No commits in common. "b6caebc4ef08c4ad609540b7d9b3b1520baf8c31" and "337f5824f0d4b2f404faa4b6b55cf171ef3f79a6" have entirely different histories.
b6caebc4ef
...
337f5824f0
@ -10,17 +10,11 @@
|
|||||||
"net.ipv6.conf.all.forwarding" = true;
|
"net.ipv6.conf.all.forwarding" = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
networking.firewall.allowedTCPPorts = [
|
# Open Firewall for BGP
|
||||||
# Open Firewall for BGP
|
networking.firewall.allowedTCPPorts = [ 179 ];
|
||||||
179
|
# Open Fireall for OSPF
|
||||||
];
|
|
||||||
|
|
||||||
networking.firewall.extraCommands = ''
|
networking.firewall.extraCommands = ''
|
||||||
# Open fireall for OSPF
|
ip6tables -A INPUT -p ospfigp -j ACCEPT
|
||||||
ip6tables -A INPUT -p ospfigp -j ACCEPT
|
iptables -A INPUT -p ospfigp -j ACCEPT
|
||||||
iptables -A INPUT -p ospfigp -j ACCEPT
|
|
||||||
# Open firewall for GRE
|
|
||||||
ip6tables -A INPUT -p gre -j ACCEPT
|
|
||||||
iptables -A INPUT -p gre -j ACCEPT
|
|
||||||
'';
|
'';
|
||||||
}
|
}
|
||||||
|
@ -84,17 +84,6 @@
|
|||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
clerie.gre-tunnel = {
|
|
||||||
enable = true;
|
|
||||||
ipv4 = {
|
|
||||||
gre-gatekeeper = {
|
|
||||||
remote = "10.152.101.1";
|
|
||||||
local = (lib.head config.networking.interfaces.lo.ipv4.addresses).address;
|
|
||||||
address = "169.254.201.2/24";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
services.bird2.enable = true;
|
services.bird2.enable = true;
|
||||||
services.bird2.config = ''
|
services.bird2.config = ''
|
||||||
router id ${ (lib.head config.networking.interfaces.lo.ipv4.addresses).address };
|
router id ${ (lib.head config.networking.interfaces.lo.ipv4.addresses).address };
|
||||||
|
@ -136,17 +136,6 @@
|
|||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
clerie.gre-tunnel = {
|
|
||||||
enable = true;
|
|
||||||
ipv4 = {
|
|
||||||
gre-carbon = {
|
|
||||||
remote = "10.152.104.1";
|
|
||||||
local = (lib.head config.networking.interfaces.lo.ipv4.addresses).address;
|
|
||||||
address = "169.254.201.1/24";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
services.bird2.enable = true;
|
services.bird2.enable = true;
|
||||||
services.bird2.config = ''
|
services.bird2.config = ''
|
||||||
router id ${ (lib.head config.networking.interfaces.lo.ipv4.addresses).address };
|
router id ${ (lib.head config.networking.interfaces.lo.ipv4.addresses).address };
|
||||||
|
@ -5,7 +5,6 @@
|
|||||||
./policyrouting
|
./policyrouting
|
||||||
./anycast_healthchecker
|
./anycast_healthchecker
|
||||||
./gitea
|
./gitea
|
||||||
./gre-tunnel
|
|
||||||
./nginx-port-forward
|
./nginx-port-forward
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
@ -1,11 +1,11 @@
|
|||||||
{ config, lib, pkgs, ... }:
|
{ config, lib, ... }:
|
||||||
|
|
||||||
with lib;
|
with lib;
|
||||||
|
|
||||||
let
|
let
|
||||||
cfg = config.clerie.gre-tunnel;
|
cfg = config.clerie.gre-tunnel;
|
||||||
|
|
||||||
generateInterfaceUnit = isIPv6: (name: tunnel:
|
generateInterfaceUnit = isIPv6: name: tunnel:
|
||||||
nameValuePair "gre-tunnel-${name}" {
|
nameValuePair "gre-tunnel-${name}" {
|
||||||
description = "GRE Tunnel - ${name}";
|
description = "GRE Tunnel - ${name}";
|
||||||
requires = [ "network-online.target" ];
|
requires = [ "network-online.target" ];
|
||||||
@ -32,36 +32,30 @@ let
|
|||||||
ip tunnel del ${name}
|
ip tunnel del ${name}
|
||||||
${tunnel.postShutdown}
|
${tunnel.postShutdown}
|
||||||
'';
|
'';
|
||||||
});
|
};
|
||||||
|
|
||||||
checkOpts = { config, ... }@moduleAttrs: {
|
checkOpts = { config, ... }@moduleAttrs: {
|
||||||
options = {
|
options = {
|
||||||
remote = mkOption {
|
remote = mkOption {
|
||||||
type = types.str;
|
type = types.str;
|
||||||
description = "Address of reciever.";
|
|
||||||
};
|
};
|
||||||
local = mkOption {
|
local = mkOption {
|
||||||
type = types.str;
|
type = types.str;
|
||||||
description = "Address our packets originate from.";
|
|
||||||
};
|
};
|
||||||
address = mkOption {
|
address = mkOption {
|
||||||
type = types.str;
|
type = types.str;
|
||||||
description = "Our address in this tunnel.";
|
|
||||||
};
|
};
|
||||||
preSetup = mkOption {
|
preSetup = mkOption {
|
||||||
type = types.str;
|
type = types.str;
|
||||||
default = "";
|
default = "";
|
||||||
description = "Commands called at the start of the interface setup.";
|
|
||||||
};
|
};
|
||||||
postSetup = mkOption {
|
postSetup = mkOption {
|
||||||
type = types.str;
|
type = types.str;
|
||||||
default = "";
|
default = "";
|
||||||
description = "Commands called at the end of the interface setup.";
|
|
||||||
};
|
};
|
||||||
postShutdown = mkOption {
|
postShutdown = mkOption {
|
||||||
type = types.str;
|
type = types.str;
|
||||||
default = "";
|
default = "";
|
||||||
description = "Commands called after shutting down the interface.";
|
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
@ -83,7 +77,7 @@ in {
|
|||||||
|
|
||||||
config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
systemd.services =
|
systemd.services =
|
||||||
(mapAttrs' (generateInterfaceUnit false) cfg.ipv4)
|
(mapAttrsToList (generateInterfaceUnit false) cfg.ipv4)
|
||||||
// (mapAttrs' (generateInterfaceUnit true) cfg.ipv6);
|
++ (mapAttrsToList (generateInterfaceUnit true) cfg.ipv6);
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
Loading…
Reference in New Issue
Block a user