A Debian 13 system on an N100 mini PC replaces a Cisco dual‑WAN router, using three of six gigabit ports: enp1s0 to Ziggo (DHCP), enp2s0 to KPN (VLAN 6 + PPPoE) and enp5s0 for the LAN. The network is managed with ifupdown files per interface; dhcpcd is the Ziggo DHCP client. KPN requires ppp and vlan packages, PPPoE on enp2s0.6 and MTU tuning (port 1512, VLAN 1508, PPPoE 1500) to support baby jumbo frames. pppd is configured to persist and keepalive but not to steal the default route. dnsmasq provides LAN DHCP/DNS forwarding to Cloudflare/Google, while nftables handles filtering and NAT for both WANs (masquerade on both outputs), TCP MSS clamping for PPPoE safety, and an SSH accept rule; removing ufw first can break existing SSH allowances, so nftables rules must be in place before purging ufw.
Each WAN uses its own routing table and source‑based rules so traffic sourced from a provider leaves via that provider; table names are placed in /etc/iproute2/rt_tables.d and are populated by hooks (dhcpcd.exit-hook for Ziggo, /etc/ppp/ip-up.d and ip-down.d for KPN). KPN was made primary via route metrics (ppp0 metric 100 vs Ziggo 1002). Practical testing and fixes include adding a temporary route to test ppp0 with traceroute, deleting conntrack entries when NATed connections break on failover, and ensuring the router’s resolv.conf isn’t tied to Ziggo’s DNS.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.