!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

911 Members
Declaratively manage your switching, routing, wireless, tunneling and more.273 Servers

Load older messages


SenderMessageTime
21 Aug 2021
@6aa4fd:tchncs.de6aa4fdif all your LAN traffic already goes through it, then you don't need to do anything except setting up dhcp02:28:34
@6aa4fd:tchncs.de6aa4fdif not, you can change the routing rules on the router02:29:45
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zone 6aa4fd: I meant to say that I want an ipv6 address on my laptop, even when I'm at a coffee shop, via 6in4. 02:32:19
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneso I'm happy with the setup I have at home where the router does it, but I was wondering whether I could have it all happen on my laptop and screw the network I'm on.02:32:40
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneAnd what a dream it would be to have Nix configure my home router.02:33:08
@6aa4fd:tchncs.de6aa4fd
In reply to @matthewcroughan:defenestrate.it
so I'm happy with the setup I have at home where the router does it, but I was wondering whether I could have it all happen on my laptop and screw the network I'm on.
oh, you want a 6in4 or other type of VPN then
02:33:19
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneHmm.. Maybe tailscale should provide this.02:33:42
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneWould be quite a cool feature.02:33:47
@6aa4fd:tchncs.de6aa4fdyou can get a VPN set up with hurricane electric, not sure about price. or just set up a VPN to your home router and run that traffic through the 6in402:34:17
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneI would want the default route to be ipv4 anyway.02:34:33
@6aa4fd:tchncs.de6aa4fdso what does the ipv6 do?02:34:49
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zonegive me access to machines without a vpn 02:35:03
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zonethe way the internet was supposed to be 02:35:17
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zonebut 6in4 means I have to go through hurricane electric, which I don't want to do on youtube, and youtube isn't ssh, so yeah :D02:35:39
@6aa4fd:tchncs.de6aa4fdyou should really use a VPN, these admin tools are not properly hardened02:35:46
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneadmin tools?02:35:57
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zonewhat one are you referring to/02:36:04
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zone * what one are you referring to?02:36:06
@6aa4fd:tchncs.de6aa4fdthe stuff on the machines you want access to02:36:16
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneThe machines I'm accessing are just NixOS machines in Wales, meanwhile I'm in Liverpool.02:36:43
@6aa4fd:tchncs.de6aa4fdSOP for any machine is basically locally initiated connections and VPN is all that should go through the firewall02:37:01
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneThe NixOS machines in Wales have access to ipv6 natively thanks to BT. Whereas in Liverpool, the ISPs aren't IPv6 enabled.02:37:05
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneSo, I just did 6in4 on my openwrt router at home, and voila, I can ssh into that machine without a VPN.02:37:18
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zone * So, I just did 6in4 on my openwrt router at home, and voila, I can ssh into that machine in Wales without a VPN.02:37:22
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zone
In reply to @6aa4fd:tchncs.de
SOP for any machine is basically locally initiated connections and VPN is all that should go through the firewall
NixOS runs its own firewall, and it's quite decent by default.
02:37:44
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneNAT isn't security, either.02:37:58
@6aa4fd:tchncs.de6aa4fdyeah I'm saying you shouldn't be punching holes in it02:38:05
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zone
In reply to @6aa4fd:tchncs.de
yeah I'm saying you shouldn't be punching holes in it
I'm not punching holes through it, the only thing open is ssh.
02:38:19
@6aa4fd:tchncs.de6aa4fdNat is not security but stateful, TCP aware firewalls are02:38:24
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneMaybe you misunderstand what I'm doing? There's no hole punching happening.02:38:53

Show newer messages


Back to Room ListRoom Version: 6