Merge branch 'master' of pnp:stockholm

This commit is contained in:
makefu 2015-11-15 20:18:35 +01:00
commit dcf55255e6
3 changed files with 24 additions and 19 deletions

View File

@ -89,9 +89,9 @@ let
}; };
restartIfChanged = true; restartIfChanged = true;
serviceConfig = { serviceConfig = {
Type = "simple"; Type = "simple";
restart = "always";
ExecStartPre = pkgs.writeScript "tinc_graphs-init" '' ExecStartPre = pkgs.writeScript "tinc_graphs-init" ''
#!/bin/sh #!/bin/sh

View File

@ -17,7 +17,6 @@ in {
krebs.build.target = "root@gum.krebsco.de"; krebs.build.target = "root@gum.krebsco.de";
krebs.build.host = config.krebs.hosts.gum; krebs.build.host = config.krebs.hosts.gum;
# Chat # Chat
environment.systemPackages = with pkgs;[ environment.systemPackages = with pkgs;[
weechat weechat
@ -34,21 +33,24 @@ in {
services.udev.extraRules = '' services.udev.extraRules = ''
SUBSYSTEM=="net", ATTR{address}=="c8:0a:a9:c8:ee:dd", NAME="et0" SUBSYSTEM=="net", ATTR{address}=="c8:0a:a9:c8:ee:dd", NAME="et0"
''; '';
boot.kernelParams = [ "ipv6.disable=1" ];
networking = { networking = {
firewall = { enableIPv6 = false;
allowPing = true; firewall = {
allowedTCPPorts = [ allowPing = true;
# smtp logRefusedConnections = false;
25 allowedTCPPorts = [
# http # smtp
80 443 25
# tinc # http
655 80 443
]; # tinc
allowedUDPPorts = [ 655
# tinc ];
655 53 allowedUDPPorts = [
]; # tinc
655 53
];
}; };
interfaces.et0.ip4 = [{ interfaces.et0.ip4 = [{
address = external-ip; address = external-ip;

View File

@ -59,9 +59,12 @@ in {
}; };
networking = { networking = {
firewall.allowPing = true; firewall = {
firewall.allowedTCPPorts = [ 53 80 443 ]; allowPing = true;
firewall.allowedUDPPorts = [ 655 ]; logRefusedConnections = false;
allowedTCPPorts = [ 53 80 443 ];
allowedUDPPorts = [ 655 ];
};
interfaces.enp2s1.ip4 = [{ interfaces.enp2s1.ip4 = [{
address = external-ip; address = external-ip;
prefixLength = 24; prefixLength = 24;