!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

882 Members
Declaratively manage your switching, routing, wireless, tunneling and more. | Don't rely on `networking.*` for interface and routing setup, use systemd-networkd, ifstate or NetworkManager instead. | Set `SYSTEMD_LOG_LEVEL=debug` to debug networking issues with networkd | No bad nft puns, please. | Room recommendations: #sysops:nixos.org259 Servers

Load older messages


SenderMessageTime
6 Jun 2026
@nico:c3d2.deNicoUuuuh nice, I'm waiting for it to finally get rid of the broken clatd https://github.com/secshellnet/nixos-tests/pull/316:49:53
7 Jun 2026
@likiusinik:matrix.orgLikius Inik joined the room.05:25:08
@likiusinik:matrix.orgLikius InikCan I manage Ubiquity Unifi and Edgerouter with Nix?05:25:38
@nico:c3d2.deNicoI don't think so. Sure you could generate the vyatta config for the edgerouter using nix code But especially the unifi controller stuff, that cannot really be configured via cli will probally not work with nix.10:32:11
@nico:c3d2.deNico* I don't think so. Sure you could generate the vyatta config for the edgerouter using nix code But especially the unifi controller stuff, that cannot really be configured via cli can probally not be done with nix.10:32:23
@me:m4rc3l.deMarcelyou ccould use https://github.com/astro/nix-openwrt-imagebuilder10:34:02
@nico:c3d2.deNicoSure, you can use the platform on which unifi is based, but this removes all unifi related features from these boxes. You could definitly use cheaper access points as well, because you don't need the original unifi remote management features10:44:16
@elisaado:elisaado.comEli SaadoI'm trying to skip NAT when packets come from a certain source IP, is there a way to do this using the networking.nat.* options?12:25:47
@elisaado:elisaado.comEli Saadouse case is my homelab having it's own 10.0.0.0/8 network, but my home network being on 192.168.0.0/16, I'm trying to skip NAT when packets originate on the homelab's "WAN" interface from 192.168.0.0/1612:26:46
@elisaado:elisaado.comEli Saado a new option like networking.nat.extraPreRules would help here, not sure if there are other usecases for it though 12:30:19
@zimward:zimward.moezimward changed their display name from zimward @GPN24 to zimward.21:08:15
10 Jun 2026
@g8dg5_s-+s50=z/:matrix.orgsharp-dressed-man changed their display name from g8dg5_s-+s50=z/ to sharp-dressed-man.08:08:19
11 Jun 2026
@lav:xmr.selav joined the room.23:50:30
12 Jun 2026
@matthewcroughan:defenestrate.itmatthewcroughanHow do you usually dish out V4 addresses to people?19:57:16
@matthewcroughan:defenestrate.itmatthewcroughanis it any different than when doing NAT with local addr ranges ?19:57:39
@magic_rb:matrix.redalder.orgmagic_rbid recommend you write your own firewall, its not that hard. i can share mine, though theyre not well written sadly, didnt have time or energy to do a proper clean up20:35:56
@magic_rb:matrix.redalder.orgmagic_rbyou'd have to olearn nftables tho20:36:01
@elisaado:elisaado.comEli Saado yeah I'm contemplating it quite hard rn 20:36:48
@elisaado:elisaado.comEli SaadoI already do some rule generation20:36:53
@elisaado:elisaado.comEli Saadofor allowing NAT traffic to be forwarded20:37:31
@elisaado:elisaado.comEli Saadoimage.png
Download image.png
20:37:31
@magic_rb:matrix.redalder.orgmagic_rbwell, youd want to use a set for that but yes20:40:17
@magic_rb:matrix.redalder.orgmagic_rb the complexity of the above is O(n) 20:40:27
@elisaado:elisaado.comEli Saadooh20:42:56
@elisaado:elisaado.comEli Saadooh...20:42:58
@elisaado:elisaado.comEli Saadoevaluation time is my biggest opponent20:43:05
@magic_rb:matrix.redalder.orgmagic_rb i would recommend to just not include the rule gen in nix, as in have a mostly static firewall.nft file 20:43:42
@magic_rb:matrix.redalder.orgmagic_rbthen into that you can inject values, by using, uh, there is a command to add an entry to a set, dont ask me what it is20:44:08
@magic_rb:matrix.redalder.orgmagic_rb* then into that you can inject values, by using, uh, there is a command to add an entry to a set, dont ask me what it is rn20:44:10
@magic_rb:matrix.redalder.orgmagic_rbi have a lot of ideas on how to do this, but not enough energy20:44:19

Show newer messages


Back to Room ListRoom Version: 6