networking.nftables.ruleset = lib.mkAfter ''
table inet filter {
chain input {
+ ip daddr 10.0.0.0/8 counter goto input-lan
+ ip daddr 172.16.0.0/12 counter goto input-lan
+ ip daddr 192.168.0.0/16 counter goto input-lan
+ ip daddr 224.0.0.0/3 counter goto input-lan
goto input-net
}
chain output {
systemd.services.sshd.serviceConfig.LoadCredentialEncrypted = [
"host.key:${ssh/host.key.cred}"
];
+
+ programs.wireshark = {
+ enable = true;
+ package = pkgs.wireshark-qt;
+ };
}