Commit Graph

57 Commits (7456be85db41b32e0f3e2e7bd4371d4d4bd15816)

Author SHA1 Message Date
Alyssa Ross 1176525f87 treewide: remove obsolete kernel version checks 2 years ago
Louis Bettens 625412d2bc nixos/firewall: remove dead code 2 years ago
Pierre Bourdon 833bcbc844
nixos/firewall: make 'networking.firewall.package' example less confusing 2 years ago
pennae 2d564521c0 treewide: add literalDocBook text to options with complex defaults 3 years ago
Naïm Favier 2ddc335e6f
nixos/doc: clean up defaults and examples 3 years ago
Peter Ferenczy 3936313b1f nixos/firewall: document log location 3 years ago
Andrew Childs e110f5ecc1 nixos/firewall: fix types in reverse path assertion 4 years ago
Andrew Childs 2c121f4215 nixos/firewall: fix inverted assertion for reverse path filtering 4 years ago
Bernardo Meurer 5ee439eb08
nixos: fix ip46tables invocation in nat 5 years ago
Jörg Thalheim ffa80e75b7
nixos/firewall: rename iptables-compat to iptables-nftables-compat 5 years ago
Izorkin 32f6ce33ed nixos/firewall: add package option 5 years ago
volth 35d68ef143 treewide: remove redundant quotes 5 years ago
Pierre Bourdon 18bc8203a1
nixos/firewall: canonicalize firewall ports lists 5 years ago
Pierre Bourdon 843215ac1c
nixos/firewall: use types.port where appropriate 5 years ago
Ben Blaxill 308ab4ea25 Rename back to default and better release notes 6 years ago
Ben Blaxill 32779b4c74 Refactor out the set operations 6 years ago
Ben Blaxill 551d2f7ed2 nixos/firewall: Always use global firewall.allowed rules 6 years ago
Nikolay Amiantov 69407cb013 firewall service: respect marks in rpfilter (#39054) 6 years ago
gnidorah c60c8aa759 nixos/firewall: per-interface port options 6 years ago
Nikolay Amiantov b81aa02800 firewall service: run stop commands in reload 6 years ago
Shea Levy fec543436d
nixos: Move uses of stdenv.shell to runtimeShell. 6 years ago
Mathijs Kwik 05761e9504 firewall: fix rpfilter blocking dhcp offers when no ip was bound yet 7 years ago
Florian Jacob 847beb558f nixos/firewall: Rename misleading rejected to refused in logging 7 years ago
Franz Pletz a49c2366ef
nixos/firewall: clean up rpfilter rules properly 7 years ago
Shea Levy 714fdb425a firewall: Fix check for rpfilter on manual-config kernels 7 years ago
Franz Pletz 8322a12ef2
firewall: disable conntrack helper autoloading by default 8 years ago
Franz Pletz 403fdd737e
linux: remove canDisableNetfilterConntrackHelpers feature 8 years ago
Michael Weiss 460b43dbfe firewall: Improve the comments (documentation) (#21862) 8 years ago
Nikolay Amiantov 820b4cd067 firewall service: allow DHCPv6 client traffic 8 years ago
Jaka Hudoklin afbe339e7d firewall service: add support for loose reverse path filter check (#19122) 8 years ago
aszlig fb46df8a9a
nixos: Fix ordering of firewall.service 8 years ago
Eelco Dolstra e090701e2d firewall: Order before sysinit 8 years ago
Eelco Dolstra abdc5961c3 Fix starting the firewall 8 years ago
Franz Pletz 76b21b7adb nixos/firewall: Refactor rpfilter, allow DHCPv4 (#17325) 8 years ago
Peter Simons a0ab4587b7 Set networking.firewall.allowPing = true by default. 8 years ago
Thomas Strobel a04a7272aa Add missing 'type', 'defaultText' and 'literalExample' in module definitions 9 years ago
William A. Kennington III abc7c1b013 nixos/firewall: Add the ability to specify additional packages for extraCommands 9 years ago
Eelco Dolstra f64589b2ef firewall: Don't depend on ipset 9 years ago
Eelco Dolstra 6e6a96d42c Some more type cleanup 9 years ago
Joachim Fasting 7023e03d77 firewall service: fix pingLimit example value 10 years ago
Vladimír Čunát da9a806fc4 fix a typo from 2627198b0c 10 years ago
William A. Kennington III 0f3a7b0e3c nixos/firewall: Add ipset utility 10 years ago
Vladimír Čunát 61d9f06760 fix a typo from 2627198b0c 10 years ago
William A. Kennington III 2627198b0c nixos/firewall: Add ipset utility 10 years ago
William A. Kennington III 8a94c06595 nixos: Add network-pre.target and adjust firewall start ordering 10 years ago
Boris Sukholitko 53b24d0c95 firewall: clear rpfilter on stop 10 years ago
William A. Kennington III ec9c4143a7 nixos/firewall: Cleanup in case reload fails 10 years ago
William A. Kennington III 6a43d51291 nixos/firewall: Support extraStopCommands 10 years ago
William A. Kennington III fd7b9b4291 nixos/firewall: Don't allow traffic during reload 10 years ago
Eelco Dolstra 0a256cc0ee Firewall: Only start if we have CAP_NET_ADMIN 10 years ago