2016-06-12 17:48:15 +00:00
|
|
|
{ config, pkgs, ... }:
|
|
|
|
let
|
2016-06-23 14:57:19 +00:00
|
|
|
tinc-siem-ip = "10.8.10.1";
|
|
|
|
|
2016-06-13 14:22:51 +00:00
|
|
|
ip = "64.137.234.215";
|
2016-07-11 18:46:09 +00:00
|
|
|
alt-ip = "64.137.234.210"; # honeydrive honeyd
|
|
|
|
extra-ip1 = "64.137.234.114"; # floating tinc.siem
|
|
|
|
extra-ip2 = "64.137.234.232"; # honeydrive
|
2016-06-13 14:22:51 +00:00
|
|
|
gw = "64.137.234.1";
|
2016-06-12 17:48:15 +00:00
|
|
|
in {
|
|
|
|
imports = [
|
2017-07-15 17:01:02 +00:00
|
|
|
<stockholm/makefu>
|
|
|
|
<stockholm/makefu/2configs/save-diskspace.nix>
|
|
|
|
<stockholm/makefu/2configs/hw/CAC.nix>
|
|
|
|
<stockholm/makefu/2configs/fs/CAC-CentOS-7-64bit.nix>
|
|
|
|
<stockholm/makefu/2configs/tinc/retiolum.nix>
|
2016-06-12 17:48:15 +00:00
|
|
|
];
|
|
|
|
|
2016-06-13 14:22:51 +00:00
|
|
|
|
2016-06-12 17:48:15 +00:00
|
|
|
krebs = {
|
|
|
|
enable = true;
|
|
|
|
build.host = config.krebs.hosts.shoney;
|
2016-06-23 14:57:19 +00:00
|
|
|
tinc_graphs = {
|
|
|
|
enable = true;
|
|
|
|
network = "siem";
|
|
|
|
hostsPath = "/etc/tinc/siem/hosts";
|
|
|
|
nginx = {
|
|
|
|
enable = true;
|
|
|
|
# TODO: remove hard-coded hostname
|
2016-12-25 01:56:56 +00:00
|
|
|
anonymous-domain = "localhost.localdomain";
|
|
|
|
anonymous.extraConfig = "return 403;";
|
2016-06-23 14:57:19 +00:00
|
|
|
complete = {
|
2017-04-17 11:13:35 +00:00
|
|
|
serverAliases = [ "graph.siem" ];
|
2016-12-25 01:56:56 +00:00
|
|
|
extraConfig = ''
|
|
|
|
if ( $server_addr = "${ip}" ) {
|
|
|
|
return 403;
|
|
|
|
}
|
|
|
|
'';
|
2016-06-23 14:57:19 +00:00
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
2016-06-12 17:48:15 +00:00
|
|
|
};
|
2016-07-11 18:46:09 +00:00
|
|
|
makefu.forward-journal = {
|
|
|
|
enable = true;
|
|
|
|
src = "10.8.10.1";
|
|
|
|
dst = "10.8.10.6";
|
|
|
|
};
|
2016-06-23 14:57:19 +00:00
|
|
|
networking = {
|
2018-08-28 22:57:57 +00:00
|
|
|
interfaces.enp2s1.ipv4.addresses = [
|
2016-06-23 14:57:19 +00:00
|
|
|
{ address = ip; prefixLength = 24; }
|
2016-07-11 18:46:09 +00:00
|
|
|
# { address = alt-ip; prefixLength = 24; }
|
2016-06-23 14:57:19 +00:00
|
|
|
];
|
2016-06-13 23:33:41 +00:00
|
|
|
|
2016-06-23 14:57:19 +00:00
|
|
|
defaultGateway = gw;
|
|
|
|
nameservers = [ "8.8.8.8" ];
|
|
|
|
firewall = {
|
|
|
|
trustedInterfaces = [ "tinc.siem" ];
|
|
|
|
allowedUDPPorts = [ 655 1655 ];
|
|
|
|
allowedTCPPorts = [ 655 1655 ];
|
|
|
|
};
|
|
|
|
};
|
2016-06-12 17:48:15 +00:00
|
|
|
}
|