From cbe13936a152eaab0e421c9dd1d19787e2ed7f16 Mon Sep 17 00:00:00 2001 From: Gregor Kleen Date: Sat, 9 Oct 2021 11:25:49 +0200 Subject: yggdrasil-wg: ... --- modules/yggdrasil-wg/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/modules/yggdrasil-wg/default.nix b/modules/yggdrasil-wg/default.nix index e81fee84..d0d6e522 100644 --- a/modules/yggdrasil-wg/default.nix +++ b/modules/yggdrasil-wg/default.nix @@ -91,6 +91,7 @@ in { networking.hosts = mkIf inNetwork (listToAttrs (concatMap ({name, value}: map (ip: nameValuePair (stripSubnet ip) ["${name}.yggdrasil"]) value) (mapAttrsToList nameValuePair hostIPs))); + systemd.services.firewall.path = optionals isRouter [pkgs.procps]; networking.firewall = mkIf isRouter { extraCommands = '' iptables -A FORWARD -i yggdrasil -o yggdrasil -j nixos-fw-accept -- cgit v1.2.3