diff options
author | Gregor Kleen <gkleen@yggdrasil.li> | 2021-11-15 23:44:09 +0059 |
---|---|---|
committer | Gregor Kleen <gkleen@yggdrasil.li> | 2021-11-15 23:44:09 +0059 |
commit | 0856a288b6fc1ff61c847f20495366a48577ed80 (patch) | |
tree | fe0028edbfdf8b5b0690acc3bb723d9e40a7559b /hosts/vidhar | |
parent | 30c4e879ed6dd8fd690882aac442d9ddfc9234ec (diff) | |
download | nixos-0856a288b6fc1ff61c847f20495366a48577ed80.tar nixos-0856a288b6fc1ff61c847f20495366a48577ed80.tar.gz nixos-0856a288b6fc1ff61c847f20495366a48577ed80.tar.bz2 nixos-0856a288b6fc1ff61c847f20495366a48577ed80.tar.xz nixos-0856a288b6fc1ff61c847f20495366a48577ed80.zip |
vidhar: ...
Diffstat (limited to 'hosts/vidhar')
-rw-r--r-- | hosts/vidhar/default.nix | 6 |
1 files changed, 3 insertions, 3 deletions
diff --git a/hosts/vidhar/default.nix b/hosts/vidhar/default.nix index 844dd5a1..a13398db 100644 --- a/hosts/vidhar/default.nix +++ b/hosts/vidhar/default.nix | |||
@@ -95,7 +95,7 @@ | |||
95 | ip46tables -F nixos-fw-forward 2> /dev/null || true | 95 | ip46tables -F nixos-fw-forward 2> /dev/null || true |
96 | ip46tables -X nixos-fw-forward 2> /dev/null || true | 96 | ip46tables -X nixos-fw-forward 2> /dev/null || true |
97 | 97 | ||
98 | ip46tables -N nixos-fw-forward | 98 | ip46tables -N nixos-fw-forward 2>/dev/null || true |
99 | ip46tables -A nixos-fw-forward -i eno1 -j ACCEPT | 99 | ip46tables -A nixos-fw-forward -i eno1 -j ACCEPT |
100 | ip46tables -A nixos-fw-forward -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT | 100 | ip46tables -A nixos-fw-forward -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT |
101 | ip6tables -A nixos-fw-forward -p icmpv6 --icmpv6-type redirect -j nixos-fw-log-refuse | 101 | ip6tables -A nixos-fw-forward -p icmpv6 --icmpv6-type redirect -j nixos-fw-log-refuse |
@@ -110,7 +110,7 @@ | |||
110 | ip46tables -t nat -F nixos-fw-postrouting 2>/dev/null || true | 110 | ip46tables -t nat -F nixos-fw-postrouting 2>/dev/null || true |
111 | ip46tables -t nat -X nixos-fw-postrouting 2>/dev/null || true | 111 | ip46tables -t nat -X nixos-fw-postrouting 2>/dev/null || true |
112 | 112 | ||
113 | ip46tables -t nat -N nixos-fw-postrouting | 113 | ip46tables -t nat -N nixos-fw-postrouting 2>/dev/null || true |
114 | iptables -t nat -A nixos-fw-postrouting -o dsl -j MASQUERADE | 114 | iptables -t nat -A nixos-fw-postrouting -o dsl -j MASQUERADE |
115 | 115 | ||
116 | ip46tables -t nat -A POSTROUTING -j nixos-fw-postrouting | 116 | ip46tables -t nat -A POSTROUTING -j nixos-fw-postrouting |
@@ -119,7 +119,7 @@ | |||
119 | ip46tables -t mangle -F nixos-fw-postrouting 2>/dev/null || true | 119 | ip46tables -t mangle -F nixos-fw-postrouting 2>/dev/null || true |
120 | ip46tables -t mangle -X nixos-fw-postrouting 2>/dev/null || true | 120 | ip46tables -t mangle -X nixos-fw-postrouting 2>/dev/null || true |
121 | 121 | ||
122 | ip46tables -t mangle -N nixos-fw-postrouting | 122 | ip46tables -t mangle -N nixos-fw-postrouting 2>/dev/null || true |
123 | ip46tables -A nixos-fw-postrouting -t mangle -o dsl -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu | 123 | ip46tables -A nixos-fw-postrouting -t mangle -o dsl -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu |
124 | 124 | ||
125 | ip46tables -t mangle -A POSTROUTING -j nixos-fw-postrouting | 125 | ip46tables -t mangle -A POSTROUTING -j nixos-fw-postrouting |