From 9e0867dcd9e0caaa5ef73061e9c7a3375d45f0fb Mon Sep 17 00:00:00 2001 From: Fuwn Date: Thu, 5 Sep 2024 02:49:29 -0700 Subject: Bump --- modules/system/networking/firewall/default.nix | 11 +++++++++++ 1 file changed, 11 insertions(+) create mode 100644 modules/system/networking/firewall/default.nix (limited to 'modules/system/networking/firewall/default.nix') diff --git a/modules/system/networking/firewall/default.nix b/modules/system/networking/firewall/default.nix new file mode 100644 index 0000000..074f398 --- /dev/null +++ b/modules/system/networking/firewall/default.nix @@ -0,0 +1,11 @@ +{ + imports = [ ./fail2ban.nix ]; + + networking.firewall = { + enable = true; + allowPing = false; + logReversePathDrops = true; + logRefusedConnections = false; + checkReversePath = "loose"; + }; +} -- cgit v1.2.3