From 1be972048dd58218cd689ecb5cac562eb398b751 Mon Sep 17 00:00:00 2001 From: Jakub Stachurski Date: Sun, 17 Aug 2025 11:25:33 +0200 Subject: refreshed config --- hosts/apocalypse/firewall.nix | 50 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 hosts/apocalypse/firewall.nix (limited to 'hosts/apocalypse/firewall.nix') diff --git a/hosts/apocalypse/firewall.nix b/hosts/apocalypse/firewall.nix new file mode 100644 index 0000000..5c73966 --- /dev/null +++ b/hosts/apocalypse/firewall.nix @@ -0,0 +1,50 @@ +{pkgs, config, ...}: +let + baseTCP = [ + 22000 # Syncthng + ]; + baseUDP = [ + 22000 # Syncthing + 22027 # Syncthing + 16555 # Wireguard + ]; + baseTCPRanges = [ + { from = 1714; to = 1764; } # KDE-CONNECT + ]; + baseUDPRanges = [ + { from = 1714; to = 1764; } # KDE-CONNECT + ]; + + secureTCP = [ + 22 80 433 5900 # SSH HTTP VNC + ]; + + secureUDP = [ + 5900 + ]; + + secureTCPRanges = [ + + ]; + secureUDPRanges = [ + + ]; +in +{ + networking.firewall = { + enable = false; + allowedTCPPorts = baseTCP; + allowedUDPPorts = baseUDP; + allowedUDPPortRanges = baseUDPRanges; + allowedTCPPortRanges = baseTCPRanges; + interfaces = { + "nix-laptop" = { + allowedTCPPorts = secureTCP; + allowedUDPPorts = secureUDP; + allowedUDPPortRanges = secureUDPRanges; + allowedTCPPortRanges = secureTCPRanges; + }; + }; + }; +} + -- cgit v1.3.1