diff options
author | tv <tv@krebsco.de> | 2016-02-18 00:50:10 +0100 |
---|---|---|
committer | tv <tv@krebsco.de> | 2016-02-18 00:50:10 +0100 |
commit | 0402f725bcfc8a6966bafc74f40b9acd2341a88d (patch) | |
tree | 49a75dbb6f2a2ea6944159df62426394033e9e83 /tv/2configs/xu-qemu0.nix | |
parent | e09ef6ad6875c822848db809e462d6fffa11c176 (diff) |
xu-qemu0 host: setup iptables
Diffstat (limited to 'tv/2configs/xu-qemu0.nix')
-rw-r--r-- | tv/2configs/xu-qemu0.nix | 18 |
1 files changed, 12 insertions, 6 deletions
diff --git a/tv/2configs/xu-qemu0.nix b/tv/2configs/xu-qemu0.nix index 2b67a8b..5be4899 100644 --- a/tv/2configs/xu-qemu0.nix +++ b/tv/2configs/xu-qemu0.nix @@ -15,17 +15,23 @@ in # # make [install] system=xu-qemu0 target_host=10.56.0.101 -# TODO iptables -A FORWARD -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT -# TODO iptables -A FORWARD -i qemubr0 -s 10.56.0.1/24 -m conntrack --ctstate NEW -j ACCEPT -# TODO iptables -A POSTROUTING -t nat -j MASQUERADE -# TODO iptables -A INPUT -i qemubr0 -p udp -m udp --dport bootps -j ACCEPT -# TODO iptables -A INPUT -i qemubr0 -p udp -m udp --dport domain -j ACCEPT - with config.krebs.lib; { networking.dhcpcd.denyInterfaces = [ "qemubr0" ]; + tv.iptables.extra = { + nat.POSTROUTING = ["-j MASQUERADE"]; + filter.FORWARD = [ + "-m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT" + "-i qemubr0 -s 10.56.0.1/24 -m conntrack --ctstate NEW -j ACCEPT" + ]; + filter.INPUT = [ + "-i qemubr0 -p udp -m udp --dport bootps -j ACCEPT" + "-i qemubr0 -p udp -m udp --dport domain -j ACCEPT" + ]; + }; + systemd.network.enable = true; systemd.services.systemd-networkd-wait-online.enable = false; |