nix/system/Firewall.nix

21 lines
481 B
Nix
Raw Normal View History

{ lib, ... }:
2024-12-08 22:25:43 +03:00
{
networking.firewall = {
enable = true;
2024-12-08 22:25:43 +03:00
# NOTE: Configure manually with `extraCommands`.
allowedTCPPortRanges = lib.mkForce [ ];
allowedTCPPorts = lib.mkForce [ ];
allowedUDPPortRanges = lib.mkForce [ ];
allowedUDPPorts = lib.mkForce [ ];
2024-12-08 22:25:43 +03:00
allowPing = true;
rejectPackets = false; # Drop.
2024-12-08 22:25:43 +03:00
logRefusedConnections = false;
logRefusedPackets = false;
logRefusedUnicastsOnly = true;
logReversePathDrops = false;
};
}