router: let allowWan VLANs out through the staging uplink
With stagingPort set, the box itself had internet over the staging DHCP
uplink but LAN/Wi-Fi clients had none: forward and masquerade were scoped
to ppp0 only. Worse, pppd's `defaultroute` refuses to install its route
while the staging DHCP default route (metric 1024) exists ("not replacing
existing default route"), so even a live PPPoE session was never used.
- firewall: forward-allow + masquerade allowWan VLANs -> stagingPort in a
separate `router-staging-nat` postrouting chain (networking.nat only
takes one external interface). Same allowWan set as nixos-nat.
- pppoe: `defaultroute-metric 0`, so pppd only checks for a metric-0
default route, installs ppp0 as the preferred exit and removes it on
hangup, leaving the staging route as the fallback.
This commit is contained in:
@@ -256,13 +256,15 @@ in
|
||||
example = "enp3s0";
|
||||
description = ''
|
||||
Temporary DHCPv4-client uplink into the existing LAN while the box
|
||||
runs alongside the router it replaces: gives it internet + mesh
|
||||
before the WAN port is cabled (PPPoE simply retries until then). The
|
||||
port is in no VLAN zone; the firewall admits only SSH on it. Do NOT
|
||||
connect the trunk ports to the production switch while staging —
|
||||
Kea on the mgmt tag would fight the old router's DHCP in one
|
||||
broadcast domain. Set to null at cutover (and usually hand the port
|
||||
back to `trunkPorts`).
|
||||
runs alongside the router it replaces: gives it (and, NATed, the
|
||||
allowWan VLANs) internet + mesh before the WAN port is cabled; once
|
||||
the PPPoE session is up its default route wins, and the staging
|
||||
route only carries traffic again if the session drops (PPPoE simply
|
||||
retries until then). The port is in no VLAN zone; inbound, the
|
||||
firewall admits only SSH on it. Do NOT connect the trunk ports to
|
||||
the production switch while staging — Kea on the mgmt tag would
|
||||
fight the old router's DHCP in one broadcast domain. Set to null at
|
||||
cutover (and usually hand the port back to `trunkPorts`).
|
||||
'';
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user