!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

918 Members
Declaratively manage your switching, routing, wireless, tunneling and more.266 Servers

Load older messages


SenderMessageTime
12 Sep 2021
@janne.hess:helsinki-systems.dedas_j ElvishJerricco: I don't think you need a comma between the nameservers 09:52:50
@janne.hess:helsinki-systems.dedas_j Just "8.8.8.8 8.8.4.4" (with the quotes) 09:53:07
@elvishjerricco:matrix.orgElvishJerricco
In reply to @janne.hess:helsinki-systems.de
ElvishJerricco: I don't think you need a comma between the nameservers
Dhcpd4 gives me a syntax error if I remove that
10:03:15
@janne.hess:helsinki-systems.dedas_joof10:03:23
@janne.hess:helsinki-systems.dedas_j ah yes your syntax seems to be correct: option domain-name-servers 192.168.0.1, 1.1.1.1, 1.0.0.1; 10:03:42
@janne.hess:helsinki-systems.dedas_j * ah yes your syntax seems to be correct: option domain-name-servers 192.168.0.1, 1.1.1.1, 1.0.0.1;, sorry 10:03:50
@janne.hess:helsinki-systems.dedas_jummm10:04:16
@janne.hess:helsinki-systems.dedas_j
127.0.0.53
10:04:20
@janne.hess:helsinki-systems.dedas_jhttps://wiki.archlinux.org/title/Systemd-resolved10:04:29
@elvishjerricco:matrix.orgElvishJerriccodas_j: what's your point?10:06:40
@janne.hess:helsinki-systems.dedas_j resolvectl status should show the nameservers 10:06:54
@elvishjerricco:matrix.orgElvishJerricco

das_j:

[will@nixos:~]$ resolvectl status
Global
           Protocols: +LLMNR +mDNS -DNSOverTLS DNSSEC=allow-downgrade/supported     
    resolv.conf mode: stub                                                          
Fallback DNS Servers: 1.1.1.1 8.8.8.8 1.0.0.1 8.8.4.4 2606:4700:4700::1111          
                      2001:4860:4860::8888 2606:4700:4700::1001 2001:4860:4860::8844

Link 2 (eth0)
Current Scopes: none                                                                   
     Protocols: -DefaultRoute +LLMNR -mDNS -DNSOverTLS DNSSEC=allow-downgrade/supported

Link 3 (wlan0)
Current Scopes: none                                                                   
     Protocols: -DefaultRoute +LLMNR -mDNS -DNSOverTLS DNSSEC=allow-downgrade/supported

Link 4 (br0)
    Current Scopes: DNS LLMNR/IPv4 LLMNR/IPv6                                              
         Protocols: +DefaultRoute +LLMNR -mDNS -DNSOverTLS DNSSEC=allow-downgrade/supported
Current DNS Server: 8.8.4.4                                                                
       DNS Servers: 8.8.8.8 8.8.4.4                                                        

[will@nixos:~]$ ping google.com
ping: google.com: Name or service not known
10:07:43
@elvishjerricco:matrix.orgElvishJerriccohuh, guess it has something to do with how I'm setting up the hostapd thing10:08:18
13 Sep 2021
@elvishjerricco:matrix.orgElvishJerricco I don't understand then. If resolvectl status shows some DNS servers on br0, why is DNS not working? 01:24:36
@elvishjerricco:matrix.orgElvishJerricco
$ resolvectl query google.com
google.com: resolve call failed: DNSSEC validation failed: signature-expired

Huh...

01:53:51
@lukegb:zxcvbnm.ninjalukegb (he/him)So... is your clock set correctly? :P02:01:25
@elvishjerricco:matrix.orgElvishJerriccoProbably not?02:02:16
@elvishjerricco:matrix.orgElvishJerricco I set services.resolved.dnssec = "false";, and then DNS started working. Then I removed that, and DNS continued working, even after a reboot 02:03:04
@elvishjerricco:matrix.orgElvishJerriccoWas it really a clock thing?02:03:09
@lukegb:zxcvbnm.ninjalukegb (he/him)I was guessing based on the "signature-expired" thing02:03:41
@lukegb:zxcvbnm.ninjalukegb (he/him)it's possible that you couldn't sync with NTP because DNS was broken, and DNS was broken because you couldn't sync with NTP02:03:55
@elvishjerricco:matrix.orgElvishJerricco I have no idea what the clock was set to, but I did notice that the logs for resolved included a lot of failures for ntp domains 02:04:37
@elvishjerricco:matrix.orgElvishJerriccoDidn't think that would be important...02:04:52
@elvishjerricco:matrix.orgElvishJerriccoYea just noticed journalctl logs thought it was June 29. Probably because that's when I last booted this device...02:07:22
@disrupt_the_flow:matrix.orgdisrupt_the_flow changed their profile picture.11:59:23
@hexa:lossy.networkhexaif your machine does not have an RTC you are in for some fun with NTP/DNSSEC setups13:34:29
14 Sep 2021
@Las:matrix.orgLas joined the room.08:04:46
@Las:matrix.orgLas Does anyone know of a nix-y way of doing this in order to make upnpc work? Should I just use networking.firewall.extraCommands? 08:07:05
@linus.heckemann:matrix.mayflower.deLinux Hackerman
In reply to @Las:matrix.org
Does anyone know of a nix-y way of doing this in order to make upnpc work? Should I just use networking.firewall.extraCommands?
Yep pretty much. Put your rules in the nixos-fw chain so that they don't get duplicated every time firewall.service gets restarted
08:10:55
@Las:matrix.orgLasThanks08:19:04

There are no newer messages yet.


Back to Room ListRoom Version: 6