User Tools

Site Tools


systemrescue_as_a_router

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
systemrescue_as_a_router [2026/06/20 17:59] stevesystemrescue_as_a_router [2026/06/23 17:28] (current) steve
Line 12: Line 12:
 # The variables below are the only things that should need changing; # The variables below are the only things that should need changing;
  
-export ExtIF="enX0"                     # External Interface +export ExtIF="enX0"             # External Interface, connected to Internet 
-export IntIF="enX1"                     # Internal Interface +export IntIF="enX1"             # Internal Interface, connected to PCs 
-export Sub="11"                         # Subnet number +export Sub="192.168.11"         # Subnet number 
-export CIDR="/24"                       # Subnet mask +export CIDR="/24"               # Subnet mask 
-export IntIP="192.168.${Sub}.1"         # Internal interface address +export  IntIP="${Sub}.1"        # Internal interface address 
-export IntNet="192.168.${Sub}.0${CIDR}" # Internal Network +export IntNet="${Sub}.0${CIDR}" # Internal Network 
-export IntLow="192.168.${Sub}.50"       # Low IP lease +export IntLow="${Sub}.50"       # Low IP lease 
-export  IntHi="192.168.${Sub}.199"      # High IP lease +export  IntHi="${Sub}.199"      # High IP lease 
-export Dur="1h"                         # Lease duration +export Dur="1h"                 # Lease duration 
-export DNS1="8.8.8.8"                   # First DNS server +export DNS1="8.8.8.8"           # First DNS server 
-export DNS2="1.1.1.1"                   # Second DNS server +export DNS2="1.1.1.1"           # Second DNS server 
-export Dom="cyli.org"+export Dom="cyli.org"           # Our domain
  
-# 1. Clean Dnsmasq Configuration 
 #    Replace the contents of your /etc/dnsmasq.conf file with the following  #    Replace the contents of your /etc/dnsmasq.conf file with the following 
- 
 mv /etc/dnsmasq.conf /etc/dnsmasq.orig mv /etc/dnsmasq.conf /etc/dnsmasq.orig
  
Line 47: Line 45:
  
 # --- DHCP SETTINGS --- # --- DHCP SETTINGS ---
-# Lease range tailored to your ${IntNet} subnet+# Lease range for ${IntNet}
 dhcp-range=${IntLow},${IntHi},${Dur} dhcp-range=${IntLow},${IntHi},${Dur}
  
-# Explicitly pass this server'internal IP as the gateway+# Explicitly pass this VMs internal IP as the gateway
 dhcp-option=option:router,${IntIP} dhcp-option=option:router,${IntIP}
  
-# Announce this server as the authoritative DHCP source+# Announce this VM as the authoritative DHCP source
 dhcp-authoritative dhcp-authoritative
 EndOfFile EndOfFile
  
-# 2. Network Interface Alignment 
 #    Before starting the services, ensure your internal interface (${IntIF})  #    Before starting the services, ensure your internal interface (${IntIF}) 
 +#    is configured and up
 ip addr add ${IntIP}${CIDR} dev ${IntIF} ip addr add ${IntIP}${CIDR} dev ${IntIF}
 ip link set ${IntIF} up ip link set ${IntIF} up
  
-# 3. Bash Script to Flush Rules, Enable Routing, and NAT +#    Run this to completely wipe the firewall, enable system-level 
-#    Run this script to completely wipe the firewall, enable system-level +
 #    packet forwarding, and route internal client traffic out to the  #    packet forwarding, and route internal client traffic out to the 
 #    internet through ${ExtIF}. #    internet through ${ExtIF}.
-    1. Enable IPv4 packet forwarding in the Linux kernel+     Enable IPv4 packet forwarding in the Linux kernel
 sysctl -w net.ipv4.ip_forward=1 sysctl -w net.ipv4.ip_forward=1
 echo "net.ipv4.ip_forward=1" | tee -a /etc/sysctl.conf echo "net.ipv4.ip_forward=1" | tee -a /etc/sysctl.conf
  
-    2. Set default policies to ACCEPT everything temporarily+     Set default policies to ACCEPT everything temporarily
 iptables -P INPUT ACCEPT iptables -P INPUT ACCEPT
 iptables -P FORWARD ACCEPT iptables -P FORWARD ACCEPT
 iptables -P OUTPUT ACCEPT iptables -P OUTPUT ACCEPT
  
-    3. Flush all rules from all tables (Filter, NAT, Mangle)+     Flush all rules from all tables (Filter, NAT, Mangle)
 iptables -F iptables -F
 iptables -t nat -F iptables -t nat -F
 iptables -t mangle -F iptables -t mangle -F
  
-    4. Delete all custom user-defined chains+     Delete all custom user-defined chains
 iptables -X iptables -X
 iptables -t nat -X iptables -t nat -X
 iptables -t mangle -X iptables -t mangle -X
  
-    5. Reset all packet and byte counters back to zero+     Reset all packet and byte counters back to zero
 iptables -Z iptables -Z
  
-    6. Configure NAT / Masquerade out of the external interface+     Configure NAT / Masquerade out of the external interface
 iptables -t nat -A POSTROUTING -o ${ExtIF} -j MASQUERADE iptables -t nat -A POSTROUTING -o ${ExtIF} -j MASQUERADE
  
-    7. Forward traffic from internal network out to the internet+     Forward traffic from internal network out to the internet
 iptables -A FORWARD -i ${IntIF} -o ${ExtIF} -j ACCEPT iptables -A FORWARD -i ${IntIF} -o ${ExtIF} -j ACCEPT
 iptables -A FORWARD -i ${ExtIF} -o ${IntIF} -m state --state RELATED,ESTABLISHED -j ACCEPT iptables -A FORWARD -i ${ExtIF} -o ${IntIF} -m state --state RELATED,ESTABLISHED -j ACCEPT
  
  
-## Restarting the Clean Infrastructure 
 #  Wipe out any runtime artifacts from old setups and fire up the new router configuration #  Wipe out any runtime artifacts from old setups and fire up the new router configuration
 #  Clear any stuck active leases #  Clear any stuck active leases
systemrescue_as_a_router.1781978396.txt.gz · Last modified: by steve