networking updates

This commit is contained in:
Rouven Seifert 2023-12-12 17:44:28 +01:00
parent 9f6221d8b1
commit cf9dedf17a
Signed by: rouven.seifert
GPG key ID: B95E8FE6B11C4D09
4 changed files with 15 additions and 0 deletions

View file

@ -2,6 +2,10 @@
{
services.fail2ban = {
enable = true;
ignoreIP = [
"141.30.0.0/16"
"141.76.0.0/16"
];
bantime = "10m";
bantime-increment = {
enable = true;

View file

@ -17,6 +17,11 @@
domain = "rfive.de";
useNetworkd = true;
enableIPv6 = true;
firewall = {
extraInputRules = ''
ip saddr 192.168.0.0/16 tcp dport 19531 accept comment "Allow journald gateway access from local networks"
'';
};
};
services.resolved = {
dnssec = "true";

View file

@ -6,6 +6,11 @@
useNetworkd = true;
enableIPv6 = true;
nftables.enable = true;
firewall = {
extraInputRules = ''
ip saddr 192.168.0.0/16 tcp dport 19531 accept comment "Allow journald gateway access from local networks"
'';
};
};
services.lldpd.enable = true;
services.resolved = {

View file

@ -6,6 +6,7 @@
./gpg.nix
./vim.nix
./nix.nix
./systemd.nix
./tmux.nix
./yazi.nix
./zsh.nix