From e8352a8ac80fff6cfa3a0f2a8bd7b1d85b3a3093 Mon Sep 17 00:00:00 2001 From: Phil Pluckthun Date: Sun, 15 Mar 2026 17:20:37 +0000 Subject: [PATCH] Add ppp router config --- machines/ramune/configuration.nix | 8 +-- modules/router/encrypt/pppoe-options.age | 5 ++ modules/router/network.nix | 83 ++++++++++++++++++++++-- secrets.nix | 2 + 4 files changed, 90 insertions(+), 8 deletions(-) create mode 100644 modules/router/encrypt/pppoe-options.age diff --git a/machines/ramune/configuration.nix b/machines/ramune/configuration.nix index cacd9fd..c26dd5d 100644 --- a/machines/ramune/configuration.nix +++ b/machines/ramune/configuration.nix @@ -16,6 +16,10 @@ enable = true; ipv6 = true; upnp.enable = true; + ppp = { + enable = true; + mtu = 1500; + }; interfaces = { external = { name = "extern0"; @@ -40,10 +44,6 @@ automation = { enable = true; mqtt.enable = true; - zigbee = { - enable = true; - serialPort = "/dev/serial/by-id/usb-ITead_Sonoff_Zigbee_3.0_USB_Dongle_Plus_fcea8ceb8612ec11ab4e23c7bd930c07-if00-port0"; - }; homebridge.enable = true; }; server = { diff --git a/modules/router/encrypt/pppoe-options.age b/modules/router/encrypt/pppoe-options.age new file mode 100644 index 0000000..a13fbf1 --- /dev/null +++ b/modules/router/encrypt/pppoe-options.age @@ -0,0 +1,5 @@ +age-encryption.org/v1 +-> ssh-ed25519 QwbpPw O0VMlg5Kz330g8eYHFFLoCdZT9j7/9NlxNrdkWmvHAI +D9vFm/fpPtXdURgflHBTgHPRPsUO5JnVYWkoNRhex1U +--- NdYkkGJK0MYa6qy2MkuHZQ/UD0RkDww3ghvO2olTwyU +$��5f�� ~�"�!���8�;O���]��)0���{E�*�5C�D�fC/���j_?�ǢG,��\�2q^V��n����� \ No newline at end of file diff --git a/modules/router/network.nix b/modules/router/network.nix index 5acb7af..ed83f5f 100644 --- a/modules/router/network.nix +++ b/modules/router/network.nix @@ -1,4 +1,4 @@ -{ lib, config, ... } @ inputs: +{ lib, pkgs, config, ... } @ inputs: with lib; let @@ -41,6 +41,22 @@ let }; }; + pppType = types.submodule { + options = { + enable = mkOption { + default = false; + example = true; + description = "Whether to enable PPPoE"; + type = types.bool; + }; + mtu = mkOption { + default = null; + type = types.nullOr types.int; + }; + }; + }; + + ppp = cfg.ppp; extern = cfg.interfaces.external; intern = cfg.interfaces.internal; in { @@ -76,20 +92,37 @@ in { type = types.listOf leaseType; description = "List of reserved IP address leases"; }; + ppp = mkOption { + default = { }; + type = pppType; + }; }; config = let links = { "10-${extern.name}" = { matchConfig.PermanentMACAddress = extern.macAddress; - linkConfig = { + linkConfig = if ppp.enable then { + Description = "PPPoE Network Interface"; + Name = "wan"; + MACAddress = extern.adoptMacAddress; + MTUBytes = mkIf (ppp.mtu != null) (toString (ppp.mtu + 8)); + } else { Description = "External Network Interface"; Name = extern.name; MACAddress = extern.adoptMacAddress; MTUBytes = "1500"; }; }; - } // (optionalAttrs (intern != null) { + } // (optionalAttrs ppp.enable { + "10-ppp" = { + matchConfig.Type = "ppp"; + linkConfig = { + Description = "External Network Interface"; + Name = extern.name; + }; + }; + }) // (optionalAttrs (intern != null) { "11-${intern.name}" = { matchConfig.PermanentMACAddress = intern.macAddress; linkConfig = { @@ -132,10 +165,15 @@ in { "10-${extern.name}" = { name = extern.name; networkConfig = { - DHCP = if cfg.ipv6 then "yes" else "ipv4"; + DHCP = if ppp.enable + then if cfg.ipv6 then "ipv6" else "no" + else if cfg.ipv6 then "yes" else "ipv4"; IPv4Forwarding = true; IPv6Forwarding = true; IPv6AcceptRA = mkIf cfg.ipv6 true; + LinkLocalAddressing = mkIf cfg.ipv6 "ipv6"; + KeepConfiguration = mkIf ppp.enable "static"; + DefaultRouteOnDevice = mkIf ppp.enable true; }; cakeConfig = { Parent = "root"; @@ -147,6 +185,7 @@ in { }; dhcpV6Config = mkIf cfg.ipv6 { WithoutRA = "solicit"; + UseNTP = true; UseDNS = false; UseDomains = false; UseAddress = false; @@ -155,14 +194,20 @@ in { }; dhcpPrefixDelegationConfig = mkIf cfg.ipv6 { UplinkInterface = ":self"; + SubnetId = 0; Announce = false; }; ipv6AcceptRAConfig = mkIf cfg.ipv6 { UseDNS = false; UseDomains = false; + UseMTU = false; + UseOnLinkPrefix = false; DHCPv6Client = "always"; Token = mkIf (extern.adoptMacAddress != null) "static:::${extern.adoptMacAddress}"; }; + routes = optionals ppp.enable [ + { Gateway = "::"; } + ]; }; } // (optionalAttrs (intern != null) { "11-${intern.name}" = { @@ -200,9 +245,39 @@ in { Announce = true; }; }; + }) // (optionalAttrs ppp.enable { + "10-ppp" = { + name = "wan"; + networkConfig.ConfigureWithoutCarrier = true; + }; }); }; + services.pppd = mkIf ppp.enable { + enable = true; + peers.extern.config = '' + plugin pppoe.so wan + ifname ${extern.name} + noipdefault + defaultroute + replacedefaultroute + persist + maxfail 0 + holdoff 5 + lcp-echo-adaptive + default-asyncmap + noaccomp + file ${config.age.secrets.pppoe-options.path} + ${optionalString cfg.ipv6 "+ipv6"} + ${optionalString (ppp.mtu != null) "mtu ${toString ppp.mtu}"} + ${optionalString (ppp.mtu != null) "mru ${toString ppp.mtu}"} + ''; + }; + + age.secrets.pppoe-options = mkIf ppp.enable { + file = ./encrypt/pppoe-options.age; + }; + services.resolved = { enable = true; settings.Resolve = mkMerge [ diff --git a/secrets.nix b/secrets.nix index cc91df3..f08468e 100644 --- a/secrets.nix +++ b/secrets.nix @@ -11,6 +11,8 @@ in "./modules/server/encrypt/tangled-knot-ssh.age".publicKeys = keys; "./modules/server/encrypt/gitconfig.age".publicKeys = keys; + "./modules/router/encrypt/pppoe-options.age".publicKeys = keys; + "./home/fonts/encrypt/DankMono-Regular.otf.age".publicKeys = keys; "./home/fonts/encrypt/DankMono-Bold.otf.age".publicKeys = keys; "./home/fonts/encrypt/DankMono-Italic.otf.age".publicKeys = keys; -- 2.51.2