fastd.conf 2.7 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495
  1. #
  2. # {{ site }} / {{ network }} FASTd configuration (Salt managed)
  3. #
  4. log to syslog level info;
  5. interface "{{ site }}_{{ network }}";
  6. {%- if 'aes' in grains.cpu_flags and grains.oscodename not in [ "stretch" ] %}
  7. method "aes128-gcm";
  8. {%- else %}
  9. #method "aes128-gcm"; # - Not supported by CPU on this machine
  10. {%- endif %}
  11. method "salsa2012+umac";
  12. {#- Calculating FASTd port depending on network_type #}
  13. {%- set port = -1 %}
  14. {%- if network_type == 'nodes' %}
  15. {%- set port = 10000 + site_no|int %}
  16. {%- elif network_type == 'intergw' %}
  17. {%- set port = 11000 + site_no|int %}
  18. {%- endif %}
  19. {%- if network in ['nodes4', 'intergw'] %}
  20. bind 0.0.0.0:{{ port }} interface "vrf_external";
  21. {%- endif %}
  22. {%- if network in ['nodes6', 'intergw'] %}
  23. bind [::]:{{ port }} interface "vrf_external";
  24. {%- endif %}
  25. # Mark packets to make sure they are associated to VRF vrf_external.
  26. # Specifying the interface and setsockopt() isn't enough for fastd.
  27. packet mark 0x1023;
  28. secret "{{ secret }}";
  29. mtu 1406;
  30. status socket "/var/run/fastd.{{ site }}_{{ network }}.sock";
  31. on up "
  32. ip link set $INTERFACE down
  33. ip link set address {{ mac_address }} dev $INTERFACE
  34. ip link set $INTERFACE up
  35. batctl -m {{ bat_iface }} if add $INTERFACE
  36. ";
  37. on down "
  38. batctl -m {{ bat_iface }} if del $INTERFACE
  39. ";
  40. {%- if network_type == 'nodes' %}
  41. #on establish async "/usr/local/bin/ff_log_vpnpeer establish";
  42. #on disestablish async "/usr/local/bin/ff_log_vpnpeer disestablish";
  43. # Nur registrierte Peers -- ALT --
  44. #include peers from "/etc/freifunk/peers";
  45. on verify "/etc/fastd/verify-peer.sh $PEER_KEY $PEER_ADDRESS";
  46. {%- if peer_limit %}
  47. peer limit {{ peer_limit }};
  48. {%- endif %}
  49. {%- elif network_type == 'intergw' %}
  50. #
  51. # Set up Inter-Gw-VPN link to all nodes of this site
  52. {%- set node_is_gw = True if grains.id.startswith('gw') else False %}
  53. {%- for peer, peer_config in salt['pillar.get']('nodes').items ()|sort if peer != grains.id %}
  54. {%- if site not in peer_config.get ('sites', {}) %}{% continue %}{% endif %}
  55. {%- if 'fastd' not in peer_config %}{% continue %}{% endif %}
  56. {#- non gw nodes are only allowed to connect to gw peers #}
  57. {%- set peer_is_gw = True if peer.startswith('gw') else False %}
  58. {%- if not node_is_gw and not peer_is_gw %}{% continue %}{% endif %}
  59. # Peer config for {{ peer }}
  60. peer "{{ peer }}" {
  61. key "{{ peer_config.get('fastd', {}).get('intergw_pubkey') }}";
  62. {%- if peer_is_gw %}
  63. {%- set ips = salt['ffho_net.get_node_iface_ips'](peer_config, 'vrf_external') %}
  64. {#- set peer IPv4 address #}
  65. {%- for ipv4 in ips['v4'] %}
  66. remote {{ ipv4 }}:{{ port }};
  67. {%- endfor %}
  68. {#- set peer IPv6 address #}
  69. {%- for ipv6 in ips['v6'] %}
  70. remote [{{ ipv6 }}]:{{ port }};
  71. {%- endfor %}
  72. {%- endif %}
  73. }
  74. {%- endfor %}
  75. {%- endif %}