systemrescue_as_a_router
Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| systemrescue_as_a_router [2026/06/20 16:38] – created steve | systemrescue_as_a_router [2026/06/23 17:28] (current) – steve | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ==== System Rescue as a router ==== | ==== System Rescue as a router ==== | ||
| - | Use curl to get this script to a freshly booted machine running SystemRescue [[https:// | + | Use curl to get this script to a freshly booted machine running SystemRescue [[https:// |
| + | |||
| + | ^^%%curl -sL " | ||
| <code bash srr.sh> | <code bash srr.sh> | ||
| - | ## 1. Clean Dnsmasq Configuration | + | #!/usr/bin/env bash |
| - | # | + | # This sets up pretty much any hardware |
| - | # directives. It is restricted | + | # emergency router. If it reboots, everything needs to be reloaded. |
| - | # interface: | + | # If this is booted from Ventoy, add this script in a 3rd partition. |
| - | mv / | + | # The variables below are the only things that should need changing; |
| - | export enX1=enX1 | + | |
| - | export enX0=enX0 | + | |
| + | export ExtIF=" | ||
| + | export IntIF=" | ||
| + | export Sub=" | ||
| + | export CIDR="/ | ||
| + | export | ||
| + | export IntNet=" | ||
| + | export IntLow=" | ||
| + | export | ||
| + | export Dur=" | ||
| + | export DNS1=" | ||
| + | export DNS2=" | ||
| + | export Dom=" | ||
| + | |||
| + | # Replace the contents of your / | ||
| + | mv / | ||
| cat << EndOfFile > / | cat << EndOfFile > / | ||
| # --- NETWORK INTERFACE --- | # --- NETWORK INTERFACE --- | ||
| # Bind only to the internal interface for security | # Bind only to the internal interface for security | ||
| - | interface=${enX1} | + | interface=${IntIF} |
| bind-interfaces | bind-interfaces | ||
| Line 21: | Line 37: | ||
| domain-needed | domain-needed | ||
| bogus-priv | bogus-priv | ||
| - | domain=local.lan | + | domain=${Dom} |
| expand-hosts | expand-hosts | ||
| # --- UPSTREAM DNS FORWARDERS --- | # --- UPSTREAM DNS FORWARDERS --- | ||
| - | server=1.1.1.1 | + | server=${DNS1} |
| - | server=8.8.8.8 | + | server=${DNS2} |
| # --- DHCP SETTINGS --- | # --- DHCP SETTINGS --- | ||
| - | # Lease range tailored to your 192.168.31.0/ | + | # Lease range for ${IntNet} |
| - | dhcp-range=192.168.31.50,192.168.31.250,12h | + | dhcp-range=${IntLow},${IntHi},${Dur} |
| - | # Explicitly pass this server' | + | # Explicitly pass this VMs internal IP as the gateway |
| - | dhcp-option=option: | + | dhcp-option=option: |
| - | # Announce this server | + | # Announce this VM as the authoritative DHCP source |
| dhcp-authoritative | dhcp-authoritative | ||
| EndOfFile | EndOfFile | ||
| - | ## 2. Network Interface Alignment | + | # Before starting the services, ensure your internal interface (${IntIF}) |
| - | ## Before starting the services, ensure your internal interface (${enX1}) | + | # is configured and up |
| - | ip addr add 192.168.31.1/ | + | ip addr add ${IntIP}${CIDR} |
| - | ip link set ${enX1} up | + | ip link set ${IntIF} up |
| - | ## 3. Bash Script to Flush Rules, Enable Routing, and NAT | + | # Run this to completely wipe the firewall, enable system-level |
| - | # Run this script | + | # packet forwarding, and route internal client traffic out to the |
| - | # | + | # internet through ${ExtIF}. |
| - | # | + | # Enable IPv4 packet forwarding in the Linux kernel |
| - | # 1. Enable IPv4 packet forwarding in the Linux kernel | + | |
| sysctl -w net.ipv4.ip_forward=1 | sysctl -w net.ipv4.ip_forward=1 | ||
| echo " | echo " | ||
| - | # 2. Set default policies to ACCEPT everything temporarily | + | # Set default policies to ACCEPT everything temporarily |
| iptables -P INPUT ACCEPT | iptables -P INPUT ACCEPT | ||
| iptables -P FORWARD ACCEPT | iptables -P FORWARD ACCEPT | ||
| iptables -P OUTPUT ACCEPT | iptables -P OUTPUT ACCEPT | ||
| - | # 3. Flush all rules from all tables (Filter, NAT, Mangle) | + | # Flush all rules from all tables (Filter, NAT, Mangle) |
| iptables -F | iptables -F | ||
| iptables -t nat -F | iptables -t nat -F | ||
| iptables -t mangle -F | iptables -t mangle -F | ||
| - | # 4. Delete all custom user-defined chains | + | # Delete all custom user-defined chains |
| iptables -X | iptables -X | ||
| iptables -t nat -X | iptables -t nat -X | ||
| iptables -t mangle -X | iptables -t mangle -X | ||
| - | # 5. Reset all packet and byte counters back to zero | + | # Reset all packet and byte counters back to zero |
| iptables -Z | iptables -Z | ||
| - | # 6. Configure NAT / Masquerade out of the external interface | + | # Configure NAT / Masquerade out of the external interface |
| - | iptables -t nat -A POSTROUTING -o ${enX0} -j MASQUERADE | + | iptables -t nat -A POSTROUTING -o ${ExtIF} -j MASQUERADE |
| - | # 7. Forward traffic from internal network out to the internet | + | # Forward traffic from internal network out to the internet |
| - | iptables -A FORWARD -i ${enX1} -o ${enX0} -j ACCEPT | + | iptables -A FORWARD -i ${IntIF} -o ${ExtIF} -j ACCEPT |
| - | iptables -A FORWARD -i ${enX0} -o ${enX1} -m state --state RELATED, | + | iptables -A FORWARD -i ${ExtIF} -o ${IntIF} -m state --state RELATED, |
| - | ## Restarting the Clean Infrastructure | ||
| # Wipe out any runtime artifacts from old setups and fire up the new router configuration | # Wipe out any runtime artifacts from old setups and fire up the new router configuration | ||
| # Clear any stuck active leases | # Clear any stuck active leases | ||
| Line 89: | Line 103: | ||
| systemctl restart dnsmasq | systemctl restart dnsmasq | ||
| </ | </ | ||
| + | {{ : | ||
systemrescue_as_a_router.1781973488.txt.gz · Last modified: by steve
