1 { inputs, pkgs, lib, config, ... }:
3 inherit (config) networking;
4 inherit (config.users) users;
8 (inputs.julm-nix + "/nixos/profiles/networking/nftables.nix")
10 networking.firewall.enable = false;
11 systemd.services.disable-kernel-module-loading.after = [ "nftables.service" ];
12 systemd.services.nftables.serviceConfig.TimeoutStartSec = "20";
13 networking.nftables = {
18 #udp dport mdns ip6 daddr ff02::fb counter accept comment "Accept mDNS"
19 #udp dport mdns ip daddr 224.0.0.251 counter accept comment "Accept mDNS"
20 tcp dport ssh counter accept comment "SSH"
21 udp dport 60000-61000 counter accept comment "Mosh"
24 tcp dport { ssh, 2222 } counter accept comment "SSH"
25 tcp dport { http, https } counter accept comment "HTTP"
26 udp dport ntp skuid ${users.systemd-timesync.name} counter accept comment "NTP"
27 tcp dport 1965 counter accept comment "Gemini"
28 tcp dport git counter accept comment "Git"
31 ct state { related, established } accept
32 jump output-connectivity