summaryrefslogtreecommitdiff
path: root/nixos/hosts/apocalypse/firewall.nix
diff options
context:
space:
mode:
authorJakub Stachurski <j.stachurski@student.utwente.nl>2025-08-17 11:25:33 +0200
committerJakub Stachurski <j.stachurski@student.utwente.nl>2025-08-17 11:25:33 +0200
commit1be972048dd58218cd689ecb5cac562eb398b751 (patch)
tree203f19ee01ad5fe28f2868e8c1451f9538e4ab12 /nixos/hosts/apocalypse/firewall.nix
parent3cd59d4670711e34a50adea912c3b0894883e490 (diff)
refreshed config
Diffstat (limited to 'nixos/hosts/apocalypse/firewall.nix')
-rw-r--r--nixos/hosts/apocalypse/firewall.nix50
1 files changed, 0 insertions, 50 deletions
diff --git a/nixos/hosts/apocalypse/firewall.nix b/nixos/hosts/apocalypse/firewall.nix
deleted file mode 100644
index 5c73966..0000000
--- a/nixos/hosts/apocalypse/firewall.nix
+++ /dev/null
@@ -1,50 +0,0 @@
-{pkgs, config, ...}:
-let
- baseTCP = [
- 22000 # Syncthng
- ];
- baseUDP = [
- 22000 # Syncthing
- 22027 # Syncthing
- 16555 # Wireguard
- ];
- baseTCPRanges = [
- { from = 1714; to = 1764; } # KDE-CONNECT
- ];
- baseUDPRanges = [
- { from = 1714; to = 1764; } # KDE-CONNECT
- ];
-
- secureTCP = [
- 22 80 433 5900 # SSH HTTP VNC
- ];
-
- secureUDP = [
- 5900
- ];
-
- secureTCPRanges = [
-
- ];
- secureUDPRanges = [
-
- ];
-in
-{
- networking.firewall = {
- enable = false;
- allowedTCPPorts = baseTCP;
- allowedUDPPorts = baseUDP;
- allowedUDPPortRanges = baseUDPRanges;
- allowedTCPPortRanges = baseTCPRanges;
- interfaces = {
- "nix-laptop" = {
- allowedTCPPorts = secureTCP;
- allowedUDPPorts = secureUDP;
- allowedUDPPortRanges = secureUDPRanges;
- allowedTCPPortRanges = secureTCPRanges;
- };
- };
- };
-}
-