homebrew – Jacob N Calvert https://jacobncalvert.com/blog-archive Sat, 10 Feb 2018 18:36:47 +0000 en-US hourly 1 https://wordpress.org/?v=6.0.17 https://jacobncalvert.com/blog-archive/wp-content/uploads/2018/02/cropped-icon-32x32.png homebrew – Jacob N Calvert https://jacobncalvert.com/blog-archive 32 32 Build Your Own Router – Part 2 https://jacobncalvert.com/blog-archive/2017/04/19/build-your-own-router-part-2/ https://jacobncalvert.com/blog-archive/2017/04/19/build-your-own-router-part-2/#respond Thu, 20 Apr 2017 01:26:58 +0000 http://jacobncalvert.com/?p=70 BYOR part deux Hello all! I’m back again with part two of the Build Your Own Router Series! In this post, we’re going to do the following: Talk about our proposed network architecture Set up our interfaces Set up a DHCP server and define our subnets Define some subnet ranges for our devices Set up some DHCP reservations Set up a DNS cache server Set up some basic iptables rules and forwarding What you must have before this point You…

The post Build Your Own Router – Part 2 appeared first on Jacob N Calvert.

]]>
BYOR part deux Hello all!
I’m back again with part two of the Build Your Own Router Series!
In this post, we’re going to do the following:

  • Talk about our proposed network architecture
  • Set up our interfaces
  • Set up a DHCP server and define our subnets
  • Define some subnet ranges for our devices
  • Set up some DHCP reservations
  • Set up a DNS cache server
  • Set up some basic iptables rules and forwarding

What you must have before this point

You need a Linux machine with two NICs, updated and ready to go.(I’ll be using 64bit Debian Jesse)

The Network Architecture

Most likely, unless you have a particularly different setup, you have a modem connected to a combo router/wireless access point, or perhaps a modem+router+WAP all-in-one unit. See the images below for a diagram of this:

Typical All-In-One Home LAN

Typical All-In-One Home LAN

Our Home LAN

Typical Modem+Router/WAP/Switch Home LAN

The units in the red boxes usually handle the following things and not much more:

  • Routing
  • DHCP
  • DNS
  • Firewall

It’s likely a small system-on-a-chip (SoC) and is configured with a web GUI. The architecture we are proposing is a little different. We want to replace that router part (the part inside the red box) with our Linux machine. We’ll let the Linux kernel do our packet switching, and let a few services handle DHCP, DNS, and the Firewall.

Note: this will require that you have a separate modem with an Ethernet interface.

Our IP network will have the following properties:

Property Value or Description
Subnet 192.168.0.0/22
Linux machine LAN IP 192.168.0.1
DHCP Pool 192.168.1.0/24

Let’s set up the interfaces

First, let’s see our two NICs and find out what the system calls them:

machine:/# ls /sys/class/net
	eth0  eth1  lo
machine:/#

So we now know our interfaces are named eth0 and eth1. Let’s designate eth0 as the WAN or Internet side of our machine, and designate eth1 as the LAN side of the interface.
Edit the /etc/network/interfaces to set up our WAN side to get and IP address from the ISP and our LAN side to have a static IP on our subnet.
The file should look similar to:

	source /etc/network/interfaces.d/*

	# The loopback network interface
	auto lo
	iface lo inet loopback

	# The WAN network interface
	allow-hotplug eth0
	iface eth0 inet dhcp

	# The LAN network interface
	allow-hotplug eth1
	iface eth1 inet static
		address 192.168.0.1
		netmask 255.255.252.0


Once you save this file and restart the network service, you should be able to see your interfaces using the tool ifconfig.
Now, plug in the WAN side to your router and let’s get on the internet!

Setting up DHCP

Since we want our Linux machine to hand out IP addresses on our LAN side, we need to install a DHCP server. Use your package manager to install isc-dhcp-server:

	apt-get install isc-dhcp-server

Now we need to tell the DHCP server what to do. Edit the DHCP configuration file (likely in /etc/dhcp/dhcpd.conf)

	option domain-name-servers              172.16.0.1;
	option routers                          172.16.0.1;
	default-lease-time                      600;
	max-lease-time                          7200;
	ddns-update-style none;

	subnet 192.168.0.0 netmask 255.255.252.0
	{
		option broadcast-address 192.168.3.255;
		allow unknown-clients;	
		pool {
			    range 192.168.1.0 192.168.1.255;

		}
	



	}

This will instruct the DHCP server to hand out addresses on the LAN in the range 192.168.1.0/24.
Restart the DHCP service to have these changes take effect. You should now be able to plug your laptop into the LAN port on your Linux machine and get an IP address via DHCP.
Now that we have some addresses assigned for DHCP use, let’s assign some DHCP reservations. Editing the same config file, add this:

host my-laptop {
		hardware ethernet aa:bb:cc:dd:ee:ff;
        fixed-address 192.168.2.0;
}

The ‘hardware ethernet’ line should contain the MAC address of your laptop, and the ‘fixed-address’ line should be the address you want to give that machine each time it requests one. Another restart will cause these new changes to take effect.

DNS Cache server

This is the easy part!

	apt-get install bind9

Done! That’s all for a basic configuration.

Forwarding and Firewall

Now we have a machine which can hand out IP addresses, but it can’t actually forward any traffic yet! First thing’s first, let’s enable forwarding.
Edit /etc/sysctl.conf and change the line regarding IPv4 forwarding to

net.ipv4.ip_forward = 1

Then, to make these changes active, issue a ‘sysctl -p’
Now we can forward traffic, let’s create some iptables rules to keep us straight. Two things to note here,

  1. iptables rules must be re-enabled after each reboot
  2. iptables can be dangerous! always backup your configuration

Because iptables are not persistent between reboots, we’ll use a script! Let’s first create a file in /etc/network/ called ‘iptables-rules’. In this script, place the following iptables rules:

*nat
:PREROUTING ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]


-A POSTROUTING -o eth0 -j MASQUERADE

COMMIT

*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]



# accept all loopback
-A INPUT -s 127.0.0.0/8 -d 127.0.0.0/8 -i lo -j ACCEPT

# accept all pings
-A INPUT -p icmp -j ACCEPT

# accept all established connections
-A INPUT -m state --state ESTABLISHED -j ACCEPT

# enable traceroute rejections to get sent out
-A INPUT -p udp -m udp --dport 33434:33523 -j REJECT --reject-with icmp-port-unreachable

# DNS from LAN
-A INPUT -i eth1 -p tcp --dport 53 -j ACCEPT
-A INPUT -i eth1 -p udp --dport 53 -j ACCEPT

# SSH from LAN
-A INPUT -i eth1 -p tcp --dport 22 -j ACCEPT

# DHCP from LAN
-A INPUT -i eth1 -p udp --dport 67:68 -j ACCEPT


# forward packets along established/related connections
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

# forward from LAN to WAN 
-A FORWARD -i eth1 -o eth0 -j ACCEPT
-A FORWARD -i eth1 -o tun0 -j ACCEPT

# drop all other forwarded traffic
-A FORWARD -j DROP


# drop all other inbound traffic
-A INPUT -j DROP


COMMIT

The comments for each section describe what that particular rule accomplishes. Now, let’s make the script which will restore these rules on startup. Create an executable file in /etc/network/if-pre-up.d called iptables-restore-rules. In that file, insert this:

#!/bin/sh
iptables-restore < /etc/network/iptables-rules

The location of this script, ensures that it will be executed *prior to* the network interfaces coming up, therefore protecting us from the internet!

Wrap up

Now we have a basic Linux router which can serve IP addresses, route packets between interfaces, and has a basic level of firewalling from the internet. In the next post, we’ll do some more iptables stuff, and talk about OpenVPN and how we can use policy based routing to route some traffic through a VPN and some around it.
As always, thanks for reading!

The post Build Your Own Router – Part 2 appeared first on Jacob N Calvert.

]]>
https://jacobncalvert.com/blog-archive/2017/04/19/build-your-own-router-part-2/feed/ 0
Build Your Own Router – Part 1 https://jacobncalvert.com/blog-archive/2017/04/10/build-your-own-router-part-1/ https://jacobncalvert.com/blog-archive/2017/04/10/build-your-own-router-part-1/#respond Tue, 11 Apr 2017 04:27:17 +0000 http://jacobncalvert.com/?p=76 Hi all, Since many folks these days are talking about VPNs and improving their online security, I thought I’d write a series on my approach to this. In this series, I want to cover the following: Why would you build a router to improve your privacy? What are the basic skills needed for building your own router? What hardware is needed? What software is needed? What does all this effort buy me? I’ll address these questions and more as I…

The post Build Your Own Router – Part 1 appeared first on Jacob N Calvert.

]]>
Hi all,
Since many folks these days are talking about VPNs and improving their online security, I thought I’d write a series on my approach to this. In this series, I want to cover the following:

  • Why would you build a router to improve your privacy?
  • What are the basic skills needed for building your own router?
  • What hardware is needed?
  • What software is needed?
  • What does all this effort buy me?

I’ll address these questions and more as I walk through my approach to this ever-increasing issue of degrading privacy online.
So let’s get to it!

I see HTTPS on all the popular websites… that’s not private?

Well, sort of. Once your machine has established an HTTPS connection to say Facebook’s servers, the data between the two of you is encrypted. But, that Domain Name Server (DNS) request your computer made to find out Facebook’s IP address was not encrypted at all. The same goes for your bank, your pharmacy, your children’s school website, and more.
So, we want to improve our privacy by making our traffic less visible. How do we do that? A VPN of course!
Many people, especially those who work from home frequently, are already familiar with VPNs. You fire up your businesses VPN client, log in, and *BOOM*, it looks like you’re sitting in your office! There’s your shared network drives, the PLM tools work and so on. This technology can also be used to enhance your web privacy.
Let me explain.
You have a VPN provider, who has 500+ servers all around the world. When you connect to this VPN service, your traffic looks like it comes from one of those servers instead of your home ISP connection. Thousands of other users have traffic exiting from that node as well. Your traffic all mixed in with other traffic — it’d be really hard to track you based on that. Plus, you have the added benefit of being able to change exit nodes practically any time (that is, if your VPN provider allows.)

So great! I just need to run a VPN on my laptop when I want to more secure!

Well, sort of, again. We have one hole, and there may be more that I’m unaware of, which can leak your private IP address to the world when using a web browser. Check out the page here about WebRTC leaking your IP address. Even when you’re actively running a VPN client on your local machine, the protocol can ask, “Hey what’s your IP address?” and your machine will willingly hand it out. Mozilla Firefox will let you disable this feature altogether, but Chrome will not. There are tweaks you can make and plugins you can get, but we have a better solution!
Enter our hero: VPN at the router!! 
Rather than running your VPN client at the machine, running it at the router makes your machine completely oblivious to the fact that a tunnel is running at all.

So I need to buy a router that supports VPN clients?

Well, you could! But they could be expensive and it’s more fun (and educational!) to build it ourselves!
By home-making a router, we can accomplish many things, the least of which is the actual routing of our home network. Not only can we have stricter control over what (and who) comes in and out of our network, but we can also offer other services like local DNS caching, more DHCP options (like NetBoot or PXE), and last but certainly not least, a VPN client.

So now we know why we would like to build our own router, but what skills will I need?

At the very least, the person building their own router needs to understand the basics of the following items:

Not on the list but absolutely essential to this endeavor is a strong background in Linux (at the helm of the CLI). All the networking and services will be configured in and hosted on a Linux distro of your choosing.
I think this is enough for one post! Check back soon for part two! I’ll come back and link it here, and it will be up on the blog page!
Thanks for reading!

The post Build Your Own Router – Part 1 appeared first on Jacob N Calvert.

]]>
https://jacobncalvert.com/blog-archive/2017/04/10/build-your-own-router-part-1/feed/ 0