diff --git a/nixos/hosts/framework-server/default.nix b/nixos/hosts/framework-server/default.nix index 4c204c8f..381239d2 100644 --- a/nixos/hosts/framework-server/default.nix +++ b/nixos/hosts/framework-server/default.nix @@ -53,10 +53,4 @@ boot.kernel.sysctl = { "net.ipv4.ip_forward" = true; }; - environment.systemPackages = with pkgs; [ iproute2 ]; - # Forward mail port 25 to sysctl.io / linode - networking.firewall.extraCommands = '' - ip route add table 25 0.0.0.0/0 dev wireguard0 - ip route add table 25 default via 10.100.0.2 - ''; } diff --git a/nixos/hosts/osaka-linode-01/firewall.nix b/nixos/hosts/osaka-linode-01/firewall.nix index 938024bc..b9f8a468 100644 --- a/nixos/hosts/osaka-linode-01/firewall.nix +++ b/nixos/hosts/osaka-linode-01/firewall.nix @@ -23,79 +23,76 @@ networking.firewall.extraCommands = '' iptables -A FORWARD -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT - iptables -t nat -A POSTROUTING -o eth0 -s 10.100.0.2/32 ! -d 10.100.0.2/32 -j MASQUERADE - iptables -A FORWARD -s 10.100.0.2/32 -j ACCEPT - iptables -A FORWARD -d 10.100.0.2/32 -j ACCEPT - iptables -A FORWARD -s ! 10.100.0.2/32 -j DROP + iptables -t nat -A POSTROUTING -s 10.100.0.2 -j SNAT --to `:%s/\= # TCP PORTS ################################################################################################## # PORT 80 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 80 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 80 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 80 -j MASQUERADE # PORT 443 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 443 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 443 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 443 -j MASQUERADE # PORT 25 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 25 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 25 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 25 -j MASQUERADE # PORT 465 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 465 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 465 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 465 -j MASQUERADE # PORT 587 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 587 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 587 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 587 -j MASQUERADE # PORT 143 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 143 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 143 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 143 -j MASQUERADE # PORT 993 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 993 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 993 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 993 -j MASQUERADE # PORT 4190 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 4190 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 4190 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 4190 -j MASQUERADE # PORT 42420 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 42420 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 42420 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 42420 -j MASQUERADE # PORT 25565 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 25565 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 25565 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 25565 -j MASQUERADE # PORT 1443 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 1443 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 1443 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 1443 -j MASQUERADE # PORT 4443 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 4443 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 4443 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 4443 -j MASQUERADE # PORT 5222 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 5222 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 5222 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 5222 -j MASQUERADE # PORT 5347 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 5347 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 5347 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 5347 -j MASQUERADE # PORT 5280 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 5280 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p tcp --dport 5280 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 5280 -j MASQUERADE # UDP PORTS ################################################################################################## # PORT 10000 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p udp --dport 10000 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p udp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p udp --dport 10000 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p udp --dport 10000 -j MASQUERADE # PORT 3478 - iptables -t nat -A PREROUTING -d 172.234.84.222 -p udp --dport 3478 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p udp -s 10.100.0.2 -j SNAT --to 10.100.0.2 + iptables -t nat -A PREROUTING -p udp --dport 3478 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p udp --dport 3478 -j MASQUERADE ''; } \ No newline at end of file