Firewall
This commit is contained in:
parent
02712e1aa1
commit
960729f6e5
@ -2,8 +2,8 @@
|
|||||||
let
|
let
|
||||||
weechat-matrix = pkgs.weechatScripts.weechat-matrix.overrideAttrs (_: {
|
weechat-matrix = pkgs.weechatScripts.weechat-matrix.overrideAttrs (_: {
|
||||||
src = pkgs.fetchzip {
|
src = pkgs.fetchzip {
|
||||||
url = "https://github.com/balsoft/weechat-matrix/archive/feat/enable-replies.tar.gz";
|
url = "https://github.com/myii/weechat-matrix/archive/feat/enable-replies.tar.gz";
|
||||||
sha256 = "sha256-GdUu/dfFy8bcEF2plon9/c+9zh9nqfAqKQd8cuUT4PE=";
|
sha256 = "sha256-KeTfSdwVosouJwz0aZARKdxNERmFWl96Dl1ps0kbBy4=";
|
||||||
};
|
};
|
||||||
});
|
});
|
||||||
weechat = pkgs.weechat.override {
|
weechat = pkgs.weechat.override {
|
||||||
|
@ -1,17 +1,19 @@
|
|||||||
{ pkgs, lib, config, ... }: {
|
{ pkgs, lib, config, ... }:
|
||||||
|
let
|
||||||
|
localRanges = [
|
||||||
|
{ from = 1714; to = 1764; } # KDE connect
|
||||||
|
{ from = 6600; to = 6600; } # Mopidy
|
||||||
|
];
|
||||||
|
in {
|
||||||
networking = {
|
networking = {
|
||||||
networkmanager.enable = true;
|
networkmanager.enable = true;
|
||||||
firewall = {
|
firewall = {
|
||||||
enable = true;
|
enable = true;
|
||||||
allowedTCPPorts = [ 13748 13722 5000 22 80 443 ];
|
allowedTCPPorts = [ 13748 13722 5000 22 80 443 ];
|
||||||
interfaces.wlan0.allowedTCPPortRanges = [{
|
interfaces.wlan0.allowedTCPPortRanges = localRanges;
|
||||||
from = 1714;
|
interfaces.wlan0.allowedUDPPortRanges = localRanges;
|
||||||
to = 1764;
|
interfaces.eth0.allowedUDPPortRanges = localRanges;
|
||||||
}];
|
interfaces.eth0.allowedTCPPortRanges = localRanges;
|
||||||
interfaces.wlan0.allowedUDPPortRanges = [{
|
|
||||||
from = 1714;
|
|
||||||
to = 1764;
|
|
||||||
}];
|
|
||||||
};
|
};
|
||||||
resolvconf.extraConfig = ''
|
resolvconf.extraConfig = ''
|
||||||
local_nameservers=""
|
local_nameservers=""
|
||||||
|
Loading…
Reference in New Issue
Block a user