!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

916 Members
Declaratively manage your switching, routing, wireless, tunneling and more.274 Servers

Load older messages


SenderMessageTime
29 May 2026
@lassulus:lassul.uslassulus changed their profile picture.07:07:21
@elisaado:elisaado.comEli Saado is anyone aware of networking.firewall.* options that only apply to one address family? e.g. networking.firewall.allowedTCPPorts for v6 only? 20:05:43
@me:m4rc3l.deMarcelyou can use extraInputRules of nftables and specify it in the rules directly => ip vs. ip620:10:23
@elisaado:elisaado.comEli Saadoyeah I was afraid that'd be the case20:11:06
@me:m4rc3l.deMarcelhttps://gitea.c3d2.de/c3d2/nix-config/src/branch/master/hosts/librespeed/default.nix#L21-L2220:11:31
@elisaado:elisaado.comEli Saadoshouldn't be too hard though20:11:38
@me:m4rc3l.deMarcel nftables syntaxt is realy simple 20:11:44
@me:m4rc3l.deMarcel * nftables syntax is realy simple 20:11:49
@elisaado:elisaado.comEli Saadoyep20:11:53
@elisaado:elisaado.comEli Saado thanks for the example 20:11:56
@elisaado:elisaado.comEli SaadoI think I'm going to make a very ugly networking.firewall.family override xD20:12:10
@elisaado:elisaado.comEli Saado* I think I'm going to make a very ugly networking.firewall.family module override xD20:12:13
31 May 2026
@613fd0ba9f744876:matrix.orgFlakeyForger joined the room.17:47:06
1 Jun 2026
@tanja:catgirl.cloudTanja (she/her) 📞 TNJA (8652) changed their display name from Tanja (she/her) to Tanja (she/her) 📞 TNJA (8652).15:33:23
3 Jun 2026
@frk7:matrix.orgfrk7 joined the room.11:11:35
@frk7:matrix.orgfrk7

Hello, if anyone is interested in system wide tor networking there is this patch that enables the networking.tor option with various ways to exclude traffic and other cool stuff: https://github.com/NixOS/nixpkgs/pull/515904

Disclaimer: I am the author

11:12:16
4 Jun 2026
@callmeecho:matrix.orgEcho changed their profile picture.04:24:55
@andrew:matrix.andrewzah.comAndrew joined the room.04:26:51
@hexa:lossy.networkhexahttps://cfp.gulas.ch/gpn24/talk/HRXC7H/18:37:07
@hexa:lossy.networkhexaRedacted or Malformed Event18:37:22
5 Jun 2026
@zimward:zimward.moezimward changed their display name from zimward to zimward @GPN24.19:38:16
6 Jun 2026
@hexa:lossy.networkhexahttps://media.ccc.de/v/gpn24-503-delegacy-forcing-ipv6-at-scale16:17:07
@hexa:lossy.networkhexatbh, this looks very dnssec breaky16:24:40
@hexa:lossy.networkhexaat least with validating clients16:24:58
@hexa:lossy.networkhexa we can probably have our own q&a if we just yank mynacol in this room 16:42:09
@hexa:lossy.networkhexaRedacted or Malformed Event16:42:16
@nico:c3d2.deNicoThanks for sharing, I haven't been aware of DNAME records DNS64 breaks dnssec, this is known and one of the reasons why this should be done on the client side (e.g. pref64), but as your name expresses this doesn't really that well on linux yet.16:47:03
@hexa:lossy.networkhexanetworkmanager has a clat in the next release16:48:44
@hexa:lossy.networkhexaso we have answer for this question :p16:48:52
@nico:c3d2.deNicoUuuuh nice, I'm waiting for it to finally get rid of the broken clatd https://github.com/secshellnet/nixos-tests/pull/316:49:53

Show newer messages


Back to Room ListRoom Version: 6