aboutsummaryrefslogtreecommitdiffstats
path: root/hosts
diff options
context:
space:
mode:
authorMark Nipper <nipsy@bitgnome.net>2024-06-13 01:23:27 -0700
committerMark Nipper <nipsy@bitgnome.net>2024-06-13 01:23:27 -0700
commit955088a064ae9838f37cf8a318c951849ee4d9a4 (patch)
tree4f5f19b5819811281891e4347efbe138b5f74ad7 /hosts
parent40fc29352e9699d66ec63cda4dd98881bc281938 (diff)
downloadnix-955088a064ae9838f37cf8a318c951849ee4d9a4.tar
nix-955088a064ae9838f37cf8a318c951849ee4d9a4.tar.gz
nix-955088a064ae9838f37cf8a318c951849ee4d9a4.tar.bz2
nix-955088a064ae9838f37cf8a318c951849ee4d9a4.tar.lz
nix-955088a064ae9838f37cf8a318c951849ee4d9a4.tar.xz
nix-955088a064ae9838f37cf8a318c951849ee4d9a4.tar.zst
nix-955088a064ae9838f37cf8a318c951849ee4d9a4.zip
Add additional service firewall rules
Diffstat (limited to 'hosts')
-rw-r--r--hosts/darkstar/default.nix8
-rw-r--r--hosts/darkstar/services.nix9
2 files changed, 17 insertions, 0 deletions
diff --git a/hosts/darkstar/default.nix b/hosts/darkstar/default.nix
index 73f66fa..eb5aa11 100644
--- a/hosts/darkstar/default.nix
+++ b/hosts/darkstar/default.nix
@@ -42,6 +42,14 @@
hostName = "darkstar";
defaultGateway = "192.168.1.1";
domain = "bitgnome.net";
+ firewall = {
+ allowedTCPPorts = [
+ 53 # domain
+ ];
+ allowedUDPPorts = [
+ 53 # domain
+ ];
+ };
interfaces = {
enp116s0 = {
ipv4.addresses = [
diff --git a/hosts/darkstar/services.nix b/hosts/darkstar/services.nix
index 90face3..323080c 100644
--- a/hosts/darkstar/services.nix
+++ b/hosts/darkstar/services.nix
@@ -1,4 +1,13 @@
{
+ networking.nftables.tables.ntp = {
+ content = ''
+ define int_if = enp116s0
+ iifname $int_if udp dport ntp accept # 123
+ '';
+ enable = true;
+ family = inet;
+ };
+
services.chrony = {
enable = true;
extraConfig = ''