!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

886 Members
Declaratively manage your switching, routing, wireless, tunneling and more. | Don't rely on `networking.*` for interface and routing setup, use systemd-networkd, ifstate or NetworkManager instead. | Set `SYSTEMD_LOG_LEVEL=debug` to debug networking issues with networkd | No bad nft puns, please. | Room recommendations: #sysops:nixos.org255 Servers

Load older messages


SenderMessageTime
19 Jan 2026
@washort:greyface.org@washort:greyface.org left the room.16:16:45
20 Jan 2026
@cloudcyclist:matrix.orgladadofar changed their display name from cloudcyclist to ladadofar.07:15:58
22 Jan 2026
@trix:nope.chattrix joined the room.20:03:18
@trix:nope.chattrixHas anyone tested IP Address certificates yet? I'm trying on 25.11 w/ shortlived profile, but I'm getting a badCSR error, with "CSR contains IP address in Common Name". I believe it's from the remote, but I'm not fully sure, and it would not make much sense, unless I majorily misunderstood how this works.20:16:24
@trix:nope.chattrixThere seems to be a hint that the common name must be disabled in CSR. Looking into how to do that20:30:39
@hexa:lossy.networkhexa (clat on linux when)IP address can only be a SAN entry20:38:52
@hexa:lossy.networkhexa (clat on linux when)In principle you should be able to skip the common name altogether20:39:13
@hexa:lossy.networkhexa (clat on linux when)but not sure we allow that20:39:19
@hexa:lossy.networkhexa (clat on linux when)* but not sure we (or lego) allow that20:39:26
@tom:dragar.deTom there is btw. #acme:nixos.org 20:42:52
@trix:nope.chattrixthanks i was unaware21:02:18
@astro:envs.netMoved to: @astro:c3d2.de changed their display name from Astro to Moved to: @astro:c3d2.de.21:38:10
@astro:c3d2.deAstro joined the room.21:58:24
23 Jan 2026
@elisaado:matrix.orgelisaadohmm firewalld looks interesting for declerative networking22:05:31
@elisaado:matrix.orgelisaadoanyone using it over nftables?22:05:37
@k900:0upti.meK900Not worth the effort if you want declarative22:09:10
@k900:0upti.meK900Just write static rules22:09:13
@k900:0upti.meK900firewalld works when you need to adjust things as you go22:09:29
24 Jan 2026
@elisaado:matrix.orgelisaadomm00:01:29
@elisaado:matrix.orgelisaadobut nftable syntax is kinda foreign to nixos right?00:01:39
@elisaado:matrix.orgelisaadoyou just put nftables strings in your nixos config00:01:46
@antifuchs:asf.computerantifuchsif you want to write fw rules in nix syntax, I can recommend https://github.com/thequux/nix-zone-firewall01:43:51
@leon:lhax.xyzleon joined the room.09:11:50
@tom:dragar.deTom

https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2107

A clat in Networkmanager

09:54:58
@elisaado:matrix.orgelisaadooh cute10:23:23
@leona:leona.isleonabut also actually nftables syntax is quite easy to understand and use (in comparsion to iptables at least) and for the most common use cases, there are abstractions in NixOS. So unsure if an abstraction in Nixpkgs would actually help10:24:40
@magic_rb:matrix.redalder.orgmagic_rbOr if youre insane you can use https://github.com/chayleaf/notnft10:28:00
@antifuchs:asf.computerantifuchsI tend to go in circles between "this configuration language sucks, write it in nixlang" / "this evals really slow (and the nixlang repr isn't good), write it in configuration language"14:41:28
@nico:c3d2.deNicoThings like nftables can get merged from multiple files quiet well, so I think this is less of an problem. frr for example is much worse and you basicly are only allowed to have one file per router17:54:31
@kdk12:matrix.orgKDK12 set a profile picture.22:12:54

There are no newer messages yet.


Back to Room ListRoom Version: 6