add rule inet filter output oifname "enp5s0" log level warn prefix "fw2net: " counter drop
add rule inet filter fw2net ip daddr ${lanNet} log level info prefix "fw2net: lan: " counter accept comment "LAN"
'';
-boot.kernel.sysctl."net.ipv6.conf.enp5s0.addr_gen_mode" = 3;
+boot.kernel.sysctl."net.ipv6.conf.enp5s0.addr_gen_mode" = 1;
+/*
security.gnupg.secrets."ipv6/enp5s0/stable_secret" = {};
# This is only active in stage2, the initrd will still use the MAC-based SLAAC IPv6.
system.activationScripts.ipv6 = ''
${pkgs.procps}/bin/sysctl --quiet net.ipv6.conf.enp5s0.stable_secret="$(cat ${gnupg.secrets."ipv6/enp5s0/stable_secret".path})"
'';
+*/
networking.interfaces.enp5s0 = {
useDHCP = true;
#ipv4.addresses = [ { address = lanIPv4; prefixLength = 24; } ];