summaryrefslogtreecommitdiff
path: root/hosts/apocalypse/firewall.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hosts/apocalypse/firewall.nix')
-rw-r--r--hosts/apocalypse/firewall.nix29
1 files changed, 17 insertions, 12 deletions
diff --git a/hosts/apocalypse/firewall.nix b/hosts/apocalypse/firewall.nix
index f45d4f7..4bc4b32 100644
--- a/hosts/apocalypse/firewall.nix
+++ b/hosts/apocalypse/firewall.nix
@@ -3,6 +3,7 @@ let
baseTCP = [
22000 # Syncthng
5352 # Zeroconf for spotifyd
+ 22 # ssh
];
baseUDP = [
22000 # Syncthing
@@ -24,7 +25,6 @@ let
];
secureTCP = [
- 22
80
433
5900 # SSH HTTP VNC
@@ -42,23 +42,28 @@ let
];
in
{
- environment.etc.hosts.mode = "0644";
- networking.nftables.enable = true;
- networking.firewall = {
- enable = false;
- checkReversePath = false;
- allowedTCPPorts = baseTCP;
- allowedUDPPorts = baseUDP;
- allowedUDPPortRanges = baseUDPRanges;
- allowedTCPPortRanges = baseTCPRanges;
- interfaces = {
- "nix-laptop" = {
+ wilkuu.firewall = {
+ enable = true;
+ defaultLayer = "external";
+ layers = {
+ internal = {
allowedTCPPorts = secureTCP;
allowedUDPPorts = secureUDP;
allowedUDPPortRanges = secureUDPRanges;
allowedTCPPortRanges = secureTCPRanges;
};
+ external = {
+ allowedTCPPorts = baseTCP;
+ allowedUDPPorts = baseUDP;
+ allowedUDPPortRanges = baseUDPRanges;
+ allowedTCPPortRanges = baseTCPRanges;
+ };
};
+ };
+ environment.etc.hosts.mode = "0644";
+ networking.nftables.enable = true;
+ networking.firewall = {
+ enable = true;
trustedInterfaces = [
"docker0"
"br-*"