diff options
| author | Fuwn <[email protected]> | 2024-09-22 14:48:17 -0700 |
|---|---|---|
| committer | Fuwn <[email protected]> | 2024-09-22 14:48:17 -0700 |
| commit | ea494e9d76a76363ac9b652dc758f3daf1d499b6 (patch) | |
| tree | 5b001e6a60f7e013e1cd6e04ade31117236cd185 /modules/desktop/networking/firewall/fail2ban.nix | |
| parent | tailscale: authenticate on all systems (diff) | |
| download | nixos-config-ea494e9d76a76363ac9b652dc758f3daf1d499b6.tar.xz nixos-config-ea494e9d76a76363ac9b652dc758f3daf1d499b6.zip | |
modules: move desktop networking to desktop
Diffstat (limited to 'modules/desktop/networking/firewall/fail2ban.nix')
| -rw-r--r-- | modules/desktop/networking/firewall/fail2ban.nix | 20 |
1 files changed, 20 insertions, 0 deletions
diff --git a/modules/desktop/networking/firewall/fail2ban.nix b/modules/desktop/networking/firewall/fail2ban.nix new file mode 100644 index 0000000..6311b14 --- /dev/null +++ b/modules/desktop/networking/firewall/fail2ban.nix @@ -0,0 +1,20 @@ +{ pkgs, lib, ... }: +{ + services.fail2ban = { + enable = false; + banaction = "nftables-multiport"; + banaction-allports = lib.mkDefault "nftables-allport"; + + extraPackages = with pkgs; [ + nftables + ipset + ]; + + ignoreIP = [ + "10.0.0.0/8" + "172.16.0.0/12" + "100.64.0.0/16" + "192.168.0.0/16" + ]; + }; +} |