Compare commits

..

1 commit

Author SHA1 Message Date
d21cf03776
feat: use seperate routing table for wg
Signed-off-by: Lander Van den Bulcke <landervandenbulcke@gmail.com>
2025-09-10 21:49:59 +02:00

View file

@ -18,47 +18,11 @@
80 80
443 443
]; ];
allowedUDPPorts = [
51820
];
}; };
networking.iproute2.enable = true; systemd.network.networks."30-wan".address = [
systemd.network.config = { "2a01:4f8:c013:7fc0::/64"
routeTables = { ];
vpn = 133;
};
addRouteTablesToIPRoute2 = true;
};
systemd.network.networks."30-wan" = {
address = [
"2a01:4f8:c013:7fc0::/64"
];
routingPolicyRules = [
{
From = "10.64.244.95/32";
Table = "vpn";
}
{
From = "fc00:bbbb:bbbb:bb01::1:f45e/128";
Table = "vpn";
}
{
User = config.users.users.vpn.uid;
Table = "vpn";
Family = "both";
}
];
};
users.groups.vpn = { };
users.users.vpn = {
isSystemUser = true;
group = "vpn";
uid = 51280;
};
networking.wireguard = { networking.wireguard = {
enable = true; enable = true;