summaryrefslogtreecommitdiff
path: root/hosts/toaster/network/mullvad.nix
diff options
context:
space:
mode:
authorGrisha Shipunov2025-01-11 03:55:19 +0100
committerGrisha Shipunov2025-01-11 03:55:19 +0100
commit62e2519639faa250f43f9e80e69906a59d07a44e (patch)
tree08d662d7674904d566d2dd7ccf85affb9ddd7cd9 /hosts/toaster/network/mullvad.nix
parent595d4935de99cc2ff10be9eaddac498c7c38489f (diff)
delete legacy stuff and reformat
Diffstat (limited to 'hosts/toaster/network/mullvad.nix')
-rw-r--r--hosts/toaster/network/mullvad.nix99
1 files changed, 57 insertions, 42 deletions
diff --git a/hosts/toaster/network/mullvad.nix b/hosts/toaster/network/mullvad.nix
index 8ad71b7..a3bfaec 100644
--- a/hosts/toaster/network/mullvad.nix
+++ b/hosts/toaster/network/mullvad.nix
@@ -1,10 +1,14 @@
-{ config, lib, ... }: {
+{ config, lib, ... }:
+{
systemd.network =
let
- pubkey = "BChJDLOwZu9Q1oH0UcrxcHP6xxHhyRbjrBUsE0e07Vk=";
+ pubkey = "BChJDLOwZu9Q1oH0UcrxcHP6xxHhyRbjrBUsE0e07Vk=";
endpoint = "169.150.196.15";
port = "51820";
- addr = [ "10.74.16.48/32" "fc00:bbbb:bbbb:bb01::b:102f/128" ];
+ addr = [
+ "10.74.16.48/32"
+ "fc00:bbbb:bbbb:bb01::b:102f/128"
+ ];
in
{
netdevs."10-wg-mullvad" = {
@@ -21,7 +25,10 @@
{
PublicKey = pubkey;
Endpoint = "${endpoint}:${port}";
- AllowedIPs = [ "0.0.0.0/0" "::0/0" ];
+ AllowedIPs = [
+ "0.0.0.0/0"
+ "::0/0"
+ ];
}
];
};
@@ -33,44 +40,52 @@
DNSDefaultRoute = true;
Domains = [ "~." ];
};
- routes = map
- (gate: {
- Gateway = gate;
- Table = 1000;
- }) [
- "0.0.0.0"
- "::"
- ];
+ routes =
+ map
+ (gate: {
+ Gateway = gate;
+ Table = 1000;
+ })
+ [
+ "0.0.0.0"
+ "::"
+ ];
- routingPolicyRules = [ {
- Family = "both";
- FirewallMark = 34952; # 0x8888
- InvertRule = true;
- Table = "1000";
- Priority = 100;
- }
- {
- Family = "both";
- SuppressPrefixLength = 0;
- Table = "main";
- Priority = 90;
- } ] ++ map (net: {
- # only route global addresses over VPN
- Priority = 80;
- To = net;
- }) [
- # Mullvad endpoint
- "${endpoint}/32"
- # "10.0.0.0/8"
- "10.13.37.0/24"
- # 0xa-mgmt
- "10.89.87.0/24"
- # "172.16.0.0/12"
- "172.16.0.0/12"
- # "182.168.0.0/16"
- "182.168.0.0/16"
- # "fc00::/7"
- ];
+ routingPolicyRules =
+ [
+ {
+ Family = "both";
+ FirewallMark = 34952; # 0x8888
+ InvertRule = true;
+ Table = "1000";
+ Priority = 100;
+ }
+ {
+ Family = "both";
+ SuppressPrefixLength = 0;
+ Table = "main";
+ Priority = 90;
+ }
+ ]
+ ++ map
+ (net: {
+ # only route global addresses over VPN
+ Priority = 80;
+ To = net;
+ })
+ [
+ # Mullvad endpoint
+ "${endpoint}/32"
+ # "10.0.0.0/8"
+ "10.13.37.0/24"
+ # 0xa-mgmt
+ "10.89.87.0/24"
+ # "172.16.0.0/12"
+ "172.16.0.0/12"
+ # "182.168.0.0/16"
+ "182.168.0.0/16"
+ # "fc00::/7"
+ ];
+ };
};
- };
}