+13
-13
nixos/modules/services/networking/firewall.nix
+13
-13
nixos/modules/services/networking/firewall.nix
······-ip46tables -t raw -A nixos-fw-rpfilter -m rpfilter --validmark ${optionalString (cfg.checkReversePath == "loose") "--loose"} -j RETURN+ip46tables -t mangle -A nixos-fw-rpfilter -m rpfilter --validmark ${optionalString (cfg.checkReversePath == "loose") "--loose"} -j RETURN-iptables -t raw -A nixos-fw-rpfilter -s 0.0.0.0 -d 255.255.255.255 -p udp --sport 68 --dport 67 -j RETURN+iptables -t mangle -A nixos-fw-rpfilter -s 0.0.0.0 -d 255.255.255.255 -p udp --sport 68 --dport 67 -j RETURN+ip46tables -t mangle -A nixos-fw-rpfilter -j LOG --log-level info --log-prefix "rpfilter drop: "···
-3
nixos/modules/services/networking/wg-quick.nix
-3
nixos/modules/services/networking/wg-quick.nix
···boot.extraModulePackages = optional (versionOlder kernel.kernel.version "5.6") kernel.wireguard;-# This is forced to false for now because the default "--validmark" rpfilter we apply on reverse path filtering