!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

881 Members
Declaratively manage your switching, routing, wireless, tunneling and more. | Don't rely on `networking.*` for interface and routing setup, use systemd-networkd, ifstate or NetworkManager instead. | Set `SYSTEMD_LOG_LEVEL=debug` to debug networking issues with networkd | No bad nft puns, please. | Room recommendations: #sysops:nixos.org251 Servers

Load older messages


SenderMessageTime
14 Dec 2025
@n4ch723hr3r:nope.chat@n4ch723hr3r:nope.chat changed their display name from n4ch723hr3r to n4ch723hr3r (stuff in name is cringe).03:42:57
@suua:matrix.orgsuua joined the room.13:29:56
15 Dec 2025
@n4ch723hr3r:nope.chat@n4ch723hr3r:nope.chat changed their display name from n4ch723hr3r (stuff in name is cringe) to MOVED TO n4ch7@n3831.net.00:16:13
@denkn:denkn.atDenKn* these rules are a little bit strange. typicaly first via contrack established connections are allowed, and at the end of the table anything else is REJECT (do not use DROP, you do not know, which effects it has, right?).14:36:27
16 Dec 2025
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe) joined the room.05:12:39
@n4ch723hr3r:nope.chat@n4ch723hr3r:nope.chat left the room.05:12:45
@sandro:supersandro.deSandro 🐧FYI https://github.com/NixOS/nixpkgs/pull/46879023:45:40
17 Dec 2025
@mall0c:matrix.orgmall0c joined the room.20:37:22
@marcusramberg:matrix.orgMarcusWhat's the right way to configure the nixos firewall with ipv6 so it allows internet connections from the trusted interfaces, but doesn't forward connections from the wan? Seems I can ssh straight into my lan interface from the internet if filterForward is off, but can't ssh out of my lan if it's on.21:43:40
@marcusramberg:matrix.orgMarcushrm, I guess this is because filterforward uses externalInterface, but my ipv6 is routed through a HE tunnel rather than the wan interface.22:05:01
@marcusramberg:matrix.orgMarcusyeah, filterforward even uses config from nat, so I guess it doesn't like non-natted ipv6 well. Fixed it with a extra ruleset for the HE tunnel.22:15:33
18 Dec 2025
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe)i have a dns server which for a machine name returns the VPN IP. however systemd only allows interface specific DNS lookups for a TLD. so my plan was to redirect $HOST.local for example to that DNS server. however the DNS server would return NXDOMAIN since it wants $HOST ONLY. so the question: how could i edit that DNS query. through a local dns proxy? graphically: client ---- $HOST.local ---> proxy ---- $HOST -----> DNS server 07:53:25
@acidbong:envs.netAcid Bong joined the room.07:58:50
@k900:0upti.meK900Uhh what08:03:52
@k900:0upti.meK900What do you even mean by "only allows lookups for a TLD"08:04:04
@dag0bertz:matrix.orgDieselgert Baghetto joined the room.08:39:11
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe)you define multiple DNS servers in resolved with the option to for example only use 1.1.1.1 for .local domains09:39:32
@k900:0upti.meK900...and?09:39:45
@k900:0upti.meK900It can be any prefix09:39:47
@k900:0upti.meK900Not just a TLD09:39:49
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe)yeah but the dns is just the hostname (which in my case are alphanumeric chars)09:56:48
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe) so the dns does NOT work with something like dig myhost.local @myserver. instead you have to do dig myhost @myserver 09:57:53
@k900:0upti.meK900You should use a separate domain name (possibly under arpa.home if you don't have a public one) and then set the search domain instead09:58:08
@k900:0upti.meK900So the canonical names for your hosts are foo.n4ch723hr3r.home.arpa or whatever09:58:36
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe)yes but the nebula DNS server does not have the functionality for that09:58:38
@k900:0upti.meK900And your search domain is n4ch723hr3r.home.arpa09:58:42
@magic_rb:matrix.redalder.orgmagic_rbThats a nebula bug then09:59:03
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe)i need a reverse proxy but for DNS09:59:05
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe)its experimental09:59:11
@magic_rb:matrix.redalder.orgmagic_rbYou need to put your local dns under a tld09:59:18

Show newer messages


Back to Room ListRoom Version: 6