systemrescue_as_a_router
This is an old revision of the document!
System Rescue as a router
Use curl to get this script to a freshly booted machine running SystemRescue https://www.system-rescue.org/ and use it as an emergency backup router.
- srr.sh
## 1. Clean Dnsmasq Configuration # Replace the contents of your /etc/dnsmasq.conf file with the following # directives. It is restricted to bind and listen only on your internal # interface: mv /etc/dnsmasq.conf /etc/dnsmasq.orig export enX1=enX1 # Internal Interface export enX0=enX0 # External Interface cat << EndOfFile > /etc/dnsmasq.conf # --- NETWORK INTERFACE --- # Bind only to the internal interface for security interface=${enX1} bind-interfaces # --- DNS SETTINGS --- domain-needed bogus-priv domain=local.lan expand-hosts # --- UPSTREAM DNS FORWARDERS --- server=1.1.1.1 server=8.8.8.8 # --- DHCP SETTINGS --- # Lease range tailored to your 192.168.31.0/24 subnet dhcp-range=192.168.31.50,192.168.31.250,12h # Explicitly pass this server's internal IP as the gateway dhcp-option=option:router,192.168.31.1 # Announce this server as the authoritative DHCP source dhcp-authoritative EndOfFile ## 2. Network Interface Alignment ## Before starting the services, ensure your internal interface (${enX1}) ip addr add 192.168.31.1/24 dev ${enX1} ip link set ${enX1} up ## 3. Bash Script to Flush Rules, Enable Routing, and NAT # Run this script to completely wipe the firewall, enable system-level # packet forwarding, and route internal client traffic out to the # internet through ${enX0}. # 1. Enable IPv4 packet forwarding in the Linux kernel sysctl -w net.ipv4.ip_forward=1 echo "net.ipv4.ip_forward=1" | tee -a /etc/sysctl.conf # 2. Set default policies to ACCEPT everything temporarily iptables -P INPUT ACCEPT iptables -P FORWARD ACCEPT iptables -P OUTPUT ACCEPT # 3. Flush all rules from all tables (Filter, NAT, Mangle) iptables -F iptables -t nat -F iptables -t mangle -F # 4. Delete all custom user-defined chains iptables -X iptables -t nat -X iptables -t mangle -X # 5. Reset all packet and byte counters back to zero iptables -Z # 6. Configure NAT / Masquerade out of the external interface iptables -t nat -A POSTROUTING -o ${enX0} -j MASQUERADE # 7. Forward traffic from internal network out to the internet iptables -A FORWARD -i ${enX1} -o ${enX0} -j ACCEPT iptables -A FORWARD -i ${enX0} -o ${enX1} -m state --state RELATED,ESTABLISHED -j ACCEPT ## Restarting the Clean Infrastructure # Wipe out any runtime artifacts from old setups and fire up the new router configuration # Clear any stuck active leases rm -f /var/lib/misc/dnsmasq.leases # Kill rogue dnsmasq processes killall dnsmasq 2>/dev/null # Restart your freshly configured system service systemctl restart dnsmasq
systemrescue_as_a_router.1781973488.txt.gz · Last modified: by steve
