Showing posts with label DNS. Show all posts
Showing posts with label DNS. Show all posts

Wednesday, February 21, 2024

How to Set Up a Tunneled Wi-Fi Hotspot on Raspberry Pi OS Bookworm with WireGuard and NetworkManager

This guide updates our earlier tutorial for Debian 12 Bookworm on Raspberry Pi. In this architecture, the Raspberry Pi connects to upstream internet via Ethernet (eth0), establishes an encrypted WireGuard VPN tunnel (wg0), and broadcasts a secure Wi-Fi access point on wlan0. All client traffic connected to the hotspot is policy-routed strictly through the WireGuard tunnel.

Modern Bookworm Architecture: NetworkManager replaces dhcpcd and leverages the built-in dnsmasq-base plugin for DHCP and DNS caching, eliminating the need for standalone services like isc-dhcp-server.

1. Create the Wi-Fi Hotspot Profile in NetworkManager

Create a hotspot connection in the Raspberry Pi desktop Network GUI or via nmcli. Set the hotspot subnet to 10.0.1.1/24, enable auto-connect, and set MTU to 1420.

To enforce robust WPA2-only (RSN/AES) authentication and disable legacy WPA1:

nmcli con modify "Wi-Fi Hot" 802-11-wireless-security.proto rsn

2. Configure Policy Routing Table

Create a dedicated routing table for hotspot clients (subnet 10.0.1.0/24):

echo "200 INET2" | sudo tee -a /etc/iproute2/rt_tables

3. WireGuard Configuration (/etc/wireguard/wg0.conf)

Configure WireGuard with policy rules and MSS clamping to ensure seamless MTU handling through the tunnel:

[Interface]
PrivateKey = YOUR_PRIVATE_KEY
Address = 10.10.0.6/24
PostUp = iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE; ip rule add from 10.0.1.0/24 table INET2 priority 100; ip route add default dev wg0 table INET2; ip route add 8.8.8.8/32 dev wg0; ip route add 8.8.4.4/32 dev wg0; iptables -t mangle -A FORWARD -o wg0 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu; iptables -t mangle -A FORWARD -i wg0 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu; ip route flush cache
PreDown = iptables -t nat -D POSTROUTING -o wg0 -j MASQUERADE; ip rule del from 10.0.1.0/24 table INET2 priority 100; ip route del default dev wg0 table INET2; ip route del 8.8.8.8/32 dev wg0; ip route del 8.8.4.4/32 dev wg0; iptables -t mangle -D FORWARD -o wg0 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu; iptables -t mangle -D FORWARD -i wg0 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu; ip route flush cache
Table = off
MTU = 1280

[Peer]
PublicKey = SERVER_PUBLIC_KEY
AllowedIPs = 0.0.0.0/0
Endpoint = YOUR_VPN_SERVER_IP:PORT
PersistentKeepalive = 25

4. Enable Kernel IPv4 Forwarding

Enable packet forwarding in /etc/sysctl.conf:

sudo sysctl -w net.ipv4.ip_forward=1
echo "net.ipv4.ip_forward=1" | sudo tee -a /etc/sysctl.conf

5. DNS Configuration for DHCP Clients

Configure NetworkManager's shared dnsmasq instance to supply public DNS servers to hotspot clients:

sudo mkdir -p /etc/NetworkManager/dnsmasq-shared.d/
echo "dhcp-option=option:dns-server,8.8.8.8,8.8.4.4" | sudo tee /etc/NetworkManager/dnsmasq-shared.d/dns.conf

6. Monitoring and Verification

Check active DHCP leases granted to Wi-Fi clients:

cat /var/lib/NetworkManager/dnsmasq-wlan0.leases

Verify dnsmasq runtime process parameters:

ps aux | grep dnsmasq

Friday, March 17, 2017

How to Build a Dynamic PowerDNS Pipe Backend in Python

The PowerDNS Pipe Backend allows developers to attach custom external scripts (written in Python, Perl, Bash, or Go) to resolve DNS queries dynamically over standard I/O streams. This approach is ideal for dynamically serving CNAME aliases, geo-routing records, or integrating DNS responses with external APIs without rebuilding PowerDNS.

Environment: PowerDNS 3.x / 4.x • pdns-backend-pipe • Python IPC

1. Installing PowerDNS Pipe Backend (CentOS / RHEL)

yum install pdns pdns-backend-pipe -y

Configure /etc/pdns/pdns.conf to launch the pipe backend alongside standard zone providers:

launch=bind,pipe
pipe-command=/etc/pdns/pdns-backend.py

2. The Python Backend Script (/etc/pdns/pdns-backend.py)

The script communicates with PowerDNS via tab-delimited protocol over stdin/stdout. Note the -u flag on Python to ensure unbuffered I/O:

#!/usr/bin/python -u
from sys import stdin, stdout

# Handshake initialization
data = stdin.readline()
stdout.write("OK	My Dynamic Python Backend
")
stdout.flush()

TARGET_CNAME = 'cname-target.example.com'

while True:
    line = stdin.readline()
    if not line:
        break
    data = line.strip()
    kind, qname, qclass, qtype, qid, ip = data.split('	')
    
    if kind == 'Q' and qname not in TARGET_CNAME:
        # Provide SOA record for authoritative delegation
        soa_resp = f"DATA	{qname}	{qclass}	SOA	86400	-1	support.{qname} ns1.example.org 2026010100 1800 3600 604800 3600
"
        stdout.write(soa_resp)
        
        # Respond to ANY or CNAME queries
        if qtype in ('ANY', 'CNAME'):
            cname_resp = f"DATA	{qname}	{qclass}	CNAME	86400	{qid}	{TARGET_CNAME}
"
            stdout.write(cname_resp)
            
    stdout.write("END
")
    stdout.flush()

Make the script executable and restart PowerDNS:

chmod +x /etc/pdns/pdns-backend.py
systemctl restart pdns

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...