User Tools

Site Tools


systemrescue_as_a_router

This is an old revision of the document!


System Rescue as a router

Use curl to get this script to a freshly booted machine running SystemRescue https://www.system-rescue.org/ and use it as an emergency backup router.

srr.sh
## 1. Clean Dnsmasq Configuration
#     Replace the contents of your /etc/dnsmasq.conf file with the following 
#     directives. It is restricted to bind and listen only on your internal 
#     interface:
 
mv /etc/dnsmasq.conf /etc/dnsmasq.orig
export enX1=enX1   # Internal Interface
export enX0=enX0   # External Interface
 
 
cat << EndOfFile > /etc/dnsmasq.conf
# --- NETWORK INTERFACE ---
# Bind only to the internal interface for security
interface=${enX1}
bind-interfaces
 
# --- DNS SETTINGS ---
domain-needed
bogus-priv
domain=local.lan
expand-hosts
 
# --- UPSTREAM DNS FORWARDERS ---
server=1.1.1.1
server=8.8.8.8
 
# --- DHCP SETTINGS ---
# Lease range tailored to your 192.168.31.0/24 subnet
dhcp-range=192.168.31.50,192.168.31.250,12h
 
# Explicitly pass this server's internal IP as the gateway
dhcp-option=option:router,192.168.31.1
 
# Announce this server as the authoritative DHCP source
dhcp-authoritative
EndOfFile
 
## 2. Network Interface Alignment
## Before starting the services, ensure your internal interface (${enX1}) 
ip addr add 192.168.31.1/24 dev ${enX1}
ip link set ${enX1} up
 
## 3. Bash Script to Flush Rules, Enable Routing, and NAT
#     Run this script to completely wipe the firewall, enable system-level 
#     packet forwarding, and route internal client traffic out to the 
#     internet through ${enX0}.
#     1. Enable IPv4 packet forwarding in the Linux kernel
sysctl -w net.ipv4.ip_forward=1
echo "net.ipv4.ip_forward=1" | tee -a /etc/sysctl.conf
 
#     2. Set default policies to ACCEPT everything temporarily
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT
 
#     3. Flush all rules from all tables (Filter, NAT, Mangle)
iptables -F
iptables -t nat -F
iptables -t mangle -F
 
#     4. Delete all custom user-defined chains
iptables -X
iptables -t nat -X
iptables -t mangle -X
 
#     5. Reset all packet and byte counters back to zero
iptables -Z
 
#     6. Configure NAT / Masquerade out of the external interface
iptables -t nat -A POSTROUTING -o ${enX0} -j MASQUERADE
 
#     7. Forward traffic from internal network out to the internet
iptables -A FORWARD -i ${enX1} -o ${enX0} -j ACCEPT
iptables -A FORWARD -i ${enX0} -o ${enX1} -m state --state RELATED,ESTABLISHED -j ACCEPT
 
 
## Restarting the Clean Infrastructure
#  Wipe out any runtime artifacts from old setups and fire up the new router configuration
#  Clear any stuck active leases
rm -f /var/lib/misc/dnsmasq.leases
 
#  Kill rogue dnsmasq processes
killall dnsmasq 2>/dev/null
 
#  Restart your freshly configured system service
systemctl restart dnsmasq
systemrescue_as_a_router.1781973488.txt.gz · Last modified: by steve