Debian 13 as a dual WAN router
5 hours ago
- Replaced a dual WAN Cisco router with an N100 mini PC running Debian 13, using six gigabit ports and an NVMe disk.
- Configured Ziggo (cable) via DHCP on enp1s0, and KPN (fiber) via VLAN 6 and PPPoE on enp2s0, with increased MTU to support baby jumbo frames.
- Set up dnsmasq for LAN DHCP and DNS, forwarding to Cloudflare and Google to remain independent of provider DNS.
- Implemented nftables firewall and NAT for both WAN interfaces, with SSH rate limiting and MSS clamping for PPPoE.
- Created per‑line routing tables (ziggo and kpn) with dynamic hooks (dhcpcd exit‑hook and ppp ip‑up/down scripts) to maintain source‑based routing.
- Made KPN the primary line with a lower route metric (100) than Ziggo (1002); automatic fallback when ppp0 disappears.
- Developed a failover script (wan‑failover) that pings three targets from each line’s address and switches the default route after three failed checks, with a recovery condition of six consecutive good checks.
- Fixed DNS resolution on the router by pointing /etc/resolv.conf to 127.0.0.1 (dnsmasq) and disabling dhcpcd and pppd from overwriting it.
- Prevented link‑local default route on Ziggo by adding `noipv4ll` to dhcpcd.conf, and used a dynamic DNS cron job with TransIP API to update the A record based on the active line.
- Discussed future work: IPv6 via prefix delegation, unplug tests, and load balancing.