4 ms·
I appreciate your comment here, and the parent comment. I've been using OPNSense[0] as my router for the past several months. So far, I am quite happy with it,
by 1MachineElf 4y ago
I appreciate your comment here, and the parent comment.
I've been using OPNSense[0] as my router for the past several months. So far, I am quite happy with it, but I've also thought that NixOS would be the next step.
My OPNSense router has 30+ VLANs and many layered firewall rules (my take on "zEr0 tRuSt") and so the task of converting it all to NixOS seems a little daunting.
I appreciate the utility of OPNSense's web GUI when configuring and troubleshooting my router config. It would be awesome if something like that could be integrated with NixOS. Additionally, something like nsh[1] to provide a traditional router/switch style CLI would be a dream come true.
[0] https://opnsense.org/ https://opnsense.org/
[1] https://www.nmedia.net/nsh/ https://www.nmedia.net/nsh/
- hamandcheese 4y agoNixOS is great for a basic home router (I use it for my home router) but it’s networking config is still pretty rudimentary, and some things I would expect to work just don’t - i.e. port forwarding only works from outside your network, not inside. I haven’t done much with vlans yet so I can’t comment on that.
- SuperSandro2000 4y agoI would highly recommend to use systemd-networkd based networking which should be able to do almost everything if configured correct.
- hamandcheese 4y agoIs there a nix config wrapper for systemd-networkd? NixOS still does everything I need it too, but the parent comment sounded like they had a bit more complex of a setup.
- janfrode 4y agoNot sure what you mean by config wrapper, but yes, systems-networkd is quite nice. Here's my home router setup with vlan1 for uplink to ISP, a bunch of other vlans for internal networks, and IPv6 prefix delegation to internal networks, and of course fireguard. All configured using systemd-networkd: { pkgs, lib, ... }:{ networking = { useNetworkd = true; useDHCP = false; enableIPv6 = true; }; networking.wireguard.interfaces = { wireguard = { ips = [ "172.20.60.1/24" ]; listenPort = 61891; privateKeyFile = "/etc/nixos/secrets/wireguard-privateKey"; peers = [ { publicKey = "897mRPejuv9yVnmTvcUL7ckQkIiM0wnSgHmgR15Evyw="; allowedIPs = [ "172.20.60.10/32" ]; presharedKeyFile = "/etc/nixos/secrets/wireguard-presharedkey"; } ... systemd.network.networks = { "10-eno1" = { matchConfig.Name = "eno1"; networkConfig.LinkLocalAddressing = "no"; networkConfig.DHCP = "no"; extraConfig = '' VLAN=wan VLAN=vlan99 VLAN=vlan30 VLAN=vlan20 VLAN=vlan1 VLAN=podnet LLDP=no EmitLLDP=no IPv6AcceptRA=no IPv6SendRA=no ''; }; "11-vlan1" = { matchConfig.Name = "vlan1"; linkConfig.RequiredForOnline = false; networkConfig.DHCP = "no"; networkConfig.Address = "192.168.1.1/24"; networkConfig.Domains = "tanso.net"; networkConfig.ConfigureWithoutCarrier = "yes"; }; "11-podnet" = { matchConfig.Name = "podnet"; linkConfig.RequiredForOnline = false; networkConfig.DHCP = "no"; networkConfig.Address = "172.20.2.1/24"; networkConfig.Domains = "tanso.net"; networkConfig.ConfigureWithoutCarrier = "yes"; }; "11-vlan20" = { matchConfig.Name = "vlan20"; networkConfig.DHCP = "no"; networkConfig.Address = "172.20.20.1/24"; networkConfig.Domains = "tanso.net"; networkConfig.ConfigureWithoutCarrier = "yes"; extraConfig = '' IPv6SendRA=yes DHCPv6PrefixDelegation=yes ''; }; .... systemd.network.netdevs = { "11-vlan1" = { netdevConfig = { Name = "vlan1"; Kind = "vlan"; }; vlanConfig.Id = 1; }; "11-podnet" = { netdevConfig = { Name = "podnet"; Kind = "vlan"; }; vlanConfig.Id = 2; }; "11-vlan20" = { netdevConfig = { Name = "vlan20"; Kind = "vlan"; }; vlanConfig.Id = 20; }; "11-vlan30" = { netdevConfig = { Name = "vlan30"; Kind = "vlan"; }; vlanConfig.Id = 30; };
- SuperSandro2000 4y ago> Is there a nix config wrapper for systemd-networkd? The options under systemd.network almost map 1:1 to systemd-networkd ones.
- madjam002 4y agoThis has more to do with iptables/nftables I think. I solved this by adding my port forwarding rules to the prerouting chain and the output chain. You can use a jump to consolidate the rules, like so - https://gist.github.com/madjam002/d30f6000adf0761e92623f7de2129152 https://gist.github.com/madjam002/d30f6000adf0761e92623f7de2... As other commentators have said, switching to systemd networkd has allowed for more advanced network configurations than I ever managed with pfSense. IPv6 works pretty much out of the box with my ISP which uses DHCP prefix delegation, I can assign /64's to different VLAN networks, and more recently I set up network prefix translation (I think that's what it's called) for my lab kubernetes cluster so each pod gets a unique IPv6 address in the RFC 4193 range which maps to my actual ISP provided IPv6 prefix, so if I change ISP the IPs in the cluster would remain the same. Being able to expose Kubernetes services directly to the internet with unique IPv6 addresses is pretty nice :)
- TheKitchenSinc 4y agoPort forwarding not working from inside the gateway sounds like it’s not doing hairpin NAT by default. I’m running a NixOS home router pair, not currently doing any port forwarding but now I’ll have to check that tonight, if nothing else people might appreciate an option for it.