summaryrefslogtreecommitdiff
path: root/hosts/vidhar/default.nix
diff options
context:
space:
mode:
authorGregor Kleen <gkleen@yggdrasil.li>2021-11-15 23:44:09 +0059
committerGregor Kleen <gkleen@yggdrasil.li>2021-11-15 23:44:09 +0059
commit0856a288b6fc1ff61c847f20495366a48577ed80 (patch)
treefe0028edbfdf8b5b0690acc3bb723d9e40a7559b /hosts/vidhar/default.nix
parent30c4e879ed6dd8fd690882aac442d9ddfc9234ec (diff)
downloadnixos-0856a288b6fc1ff61c847f20495366a48577ed80.tar
nixos-0856a288b6fc1ff61c847f20495366a48577ed80.tar.gz
nixos-0856a288b6fc1ff61c847f20495366a48577ed80.tar.bz2
nixos-0856a288b6fc1ff61c847f20495366a48577ed80.tar.xz
nixos-0856a288b6fc1ff61c847f20495366a48577ed80.zip
vidhar: ...
Diffstat (limited to 'hosts/vidhar/default.nix')
-rw-r--r--hosts/vidhar/default.nix6
1 files changed, 3 insertions, 3 deletions
diff --git a/hosts/vidhar/default.nix b/hosts/vidhar/default.nix
index 844dd5a1..a13398db 100644
--- a/hosts/vidhar/default.nix
+++ b/hosts/vidhar/default.nix
@@ -95,7 +95,7 @@
95 ip46tables -F nixos-fw-forward 2> /dev/null || true 95 ip46tables -F nixos-fw-forward 2> /dev/null || true
96 ip46tables -X nixos-fw-forward 2> /dev/null || true 96 ip46tables -X nixos-fw-forward 2> /dev/null || true
97 97
98 ip46tables -N nixos-fw-forward 98 ip46tables -N nixos-fw-forward 2>/dev/null || true
99 ip46tables -A nixos-fw-forward -i eno1 -j ACCEPT 99 ip46tables -A nixos-fw-forward -i eno1 -j ACCEPT
100 ip46tables -A nixos-fw-forward -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT 100 ip46tables -A nixos-fw-forward -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
101 ip6tables -A nixos-fw-forward -p icmpv6 --icmpv6-type redirect -j nixos-fw-log-refuse 101 ip6tables -A nixos-fw-forward -p icmpv6 --icmpv6-type redirect -j nixos-fw-log-refuse
@@ -110,7 +110,7 @@
110 ip46tables -t nat -F nixos-fw-postrouting 2>/dev/null || true 110 ip46tables -t nat -F nixos-fw-postrouting 2>/dev/null || true
111 ip46tables -t nat -X nixos-fw-postrouting 2>/dev/null || true 111 ip46tables -t nat -X nixos-fw-postrouting 2>/dev/null || true
112 112
113 ip46tables -t nat -N nixos-fw-postrouting 113 ip46tables -t nat -N nixos-fw-postrouting 2>/dev/null || true
114 iptables -t nat -A nixos-fw-postrouting -o dsl -j MASQUERADE 114 iptables -t nat -A nixos-fw-postrouting -o dsl -j MASQUERADE
115 115
116 ip46tables -t nat -A POSTROUTING -j nixos-fw-postrouting 116 ip46tables -t nat -A POSTROUTING -j nixos-fw-postrouting
@@ -119,7 +119,7 @@
119 ip46tables -t mangle -F nixos-fw-postrouting 2>/dev/null || true 119 ip46tables -t mangle -F nixos-fw-postrouting 2>/dev/null || true
120 ip46tables -t mangle -X nixos-fw-postrouting 2>/dev/null || true 120 ip46tables -t mangle -X nixos-fw-postrouting 2>/dev/null || true
121 121
122 ip46tables -t mangle -N nixos-fw-postrouting 122 ip46tables -t mangle -N nixos-fw-postrouting 2>/dev/null || true
123 ip46tables -A nixos-fw-postrouting -t mangle -o dsl -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu 123 ip46tables -A nixos-fw-postrouting -t mangle -o dsl -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
124 124
125 ip46tables -t mangle -A POSTROUTING -j nixos-fw-postrouting 125 ip46tables -t mangle -A POSTROUTING -j nixos-fw-postrouting