reNixos/ada/services/firewalld.nix
s0me1newithhand7s ab9fff95a1 chore(ada): firewalld hardening
Signed-off-by: s0me1newithhand7s <git+me@hand7s.org>
2026-05-29 00:14:49 +03:00

32 lines
603 B
Nix

_: {
services = {
firewalld = {
enable = true;
settings = {
IPv6_rpfilter = "strict";
CleanupModulesOnExit = true;
StrictForwardPorts = true;
logDenied = "off";
FlushAllOnReload = "yes";
ReloadPolicy = "DROP";
RFC3964_IPv4 = "yes";
NftablesCounters = "no";
NftablesTableOwner = "yes";
IndividualCalls = "no";
};
zones = {
"wan" = {
interfaces = [
"ens1"
];
services = [
"sunshine"
];
};
};
};
};
}