diff --git a/modules/build-types/tailscale-router.nix b/modules/build-types/tailscale-router.nix index 5140a06..764ef38 100644 --- a/modules/build-types/tailscale-router.nix +++ b/modules/build-types/tailscale-router.nix @@ -16,17 +16,29 @@ # Must also be approved in the Tailscale admin console (Machines → Edit route settings). services.tailscale.extraUpFlags = [ "--advertise-routes=${vars.lanCidr}" ]; - # Forwarded subnet-router traffic arrives on tailscale0 already - # tailscale-authenticated -- the firewall's normal per-port allow-list - # would otherwise drop it. Standard NixOS/Tailscale subnet-router guidance. - networking.firewall.trustedInterfaces = [ "tailscale0" ]; + networking = { + # SNAT traffic from LAN machines going out through Tailscale so the remote + # peer sees it sourced from this router's Tailscale IP (100.x.x.x) rather + # than a raw LAN IP. Without this, Tailscale drops the forwarded packets + # because the source is not a recognised Tailscale address. + # + # networking.nat.externalInterface alone does not insert a MASQUERADE rule + # (it only does so when internalInterfaces is also set). We use + # extraCommands to add the rule into the nixos-nat-post chain that + # networking.nat.enable creates, and extraStopCommands to clean it up. + nat.enable = true; - # SNAT traffic from LAN machines going out through Tailscale so the remote - # peer sees it sourced from this router's Tailscale IP (100.x.x.x) rather - # than a raw LAN IP. Without this, Tailscale drops the forwarded packets - # because the source is not a recognised Tailscale address. - networking.nat = { - enable = true; - externalInterface = "tailscale0"; + firewall = { + # Forwarded subnet-router traffic arrives on tailscale0 already + # tailscale-authenticated -- the firewall's normal per-port allow-list + # would otherwise drop it. Standard NixOS/Tailscale subnet-router guidance. + trustedInterfaces = [ "tailscale0" ]; + extraCommands = '' + iptables -t nat -A nixos-nat-post -s ${vars.lanCidr} -o tailscale0 -j MASQUERADE + ''; + extraStopCommands = '' + iptables -t nat -D nixos-nat-post -s ${vars.lanCidr} -o tailscale0 -j MASQUERADE 2>/dev/null || true + ''; + }; }; }