{
networking.nftables.ruleset = ''
# for lego to update ACME DNS-01 challenge
- add rule inet filter fw2net ip daddr ${hosts.mermet.extraArgs.ipv4} tcp dport 53 counter accept comment "ACME DNS-01"
- add rule inet filter fw2net ip daddr ${hosts.mermet.extraArgs.ipv4} udp dport 53 counter accept comment "ACME DNS-01"
+ add rule inet filter fw2net ip daddr ${hosts.mermet._module.args.ipv4} tcp dport 53 counter accept comment "ACME DNS-01"
+ add rule inet filter fw2net ip daddr ${hosts.mermet._module.args.ipv4} udp dport 53 counter accept comment "ACME DNS-01"
# for lego to check DNS propagation on ns6.gandi.net
add rule inet filter fw2net ip daddr 217.70.177.40 tcp dport 53 skuid ${users.acme.name} counter accept comment "DNS gandi"
add rule inet filter fw2net ip daddr 217.70.177.40 udp dport 53 skuid ${users.acme.name} counter accept comment "DNS gandi"