diff options
| author | Jakub Stachurski <j.stachurski@student.utwente.nl> | 2025-08-17 11:25:33 +0200 |
|---|---|---|
| committer | Jakub Stachurski <j.stachurski@student.utwente.nl> | 2025-08-17 11:25:33 +0200 |
| commit | 1be972048dd58218cd689ecb5cac562eb398b751 (patch) | |
| tree | 203f19ee01ad5fe28f2868e8c1451f9538e4ab12 /hosts/apocalypse/firewall.nix | |
| parent | 3cd59d4670711e34a50adea912c3b0894883e490 (diff) | |
refreshed config
Diffstat (limited to 'hosts/apocalypse/firewall.nix')
| -rw-r--r-- | hosts/apocalypse/firewall.nix | 50 |
1 files changed, 50 insertions, 0 deletions
diff --git a/hosts/apocalypse/firewall.nix b/hosts/apocalypse/firewall.nix new file mode 100644 index 0000000..5c73966 --- /dev/null +++ b/hosts/apocalypse/firewall.nix @@ -0,0 +1,50 @@ +{pkgs, config, ...}: +let + baseTCP = [ + 22000 # Syncthng + ]; + baseUDP = [ + 22000 # Syncthing + 22027 # Syncthing + 16555 # Wireguard + ]; + baseTCPRanges = [ + { from = 1714; to = 1764; } # KDE-CONNECT + ]; + baseUDPRanges = [ + { from = 1714; to = 1764; } # KDE-CONNECT + ]; + + secureTCP = [ + 22 80 433 5900 # SSH HTTP VNC + ]; + + secureUDP = [ + 5900 + ]; + + secureTCPRanges = [ + + ]; + secureUDPRanges = [ + + ]; +in +{ + networking.firewall = { + enable = false; + allowedTCPPorts = baseTCP; + allowedUDPPorts = baseUDP; + allowedUDPPortRanges = baseUDPRanges; + allowedTCPPortRanges = baseTCPRanges; + interfaces = { + "nix-laptop" = { + allowedTCPPorts = secureTCP; + allowedUDPPorts = secureUDP; + allowedUDPPortRanges = secureUDPRanges; + allowedTCPPortRanges = secureTCPRanges; + }; + }; + }; +} + |
