Firewall: Difference between revisions

Pigs (talk | contribs)
Reword and refactor layout
DHCP (talk | contribs)
m fix indentation
 
(4 intermediate revisions by 3 users not shown)
Line 6: Line 6:


{{file|/etc/nixos/configuration.nix|nix|<nowiki>
{{file|/etc/nixos/configuration.nix|nix|<nowiki>
  networking.firewall.enable = true;
networking.firewall.enable = true;
</nowiki>}}
</nowiki>}}


Line 18: Line 18:


{{file|/etc/nixos/configuration.nix|nix|<nowiki>
{{file|/etc/nixos/configuration.nix|nix|<nowiki>
  networking.firewall = {
networking.firewall = {
    enable = true;
  enable = true;
    allowedTCPPorts = [ 80 443 ];
  allowedTCPPorts = [ 80 443 ];
    allowedUDPPortRanges = [
  allowedUDPPortRanges = [
      { from = 4000; to = 4007; }
    { from = 4000; to = 4007; }
      { from = 8000; to = 8010; }
    { from = 8000; to = 8010; }
    ];
  ];
  };   
};   
</nowiki>}}
</nowiki>}}


Line 39: Line 39:


{{file|/etc/nixos/configuration.nix|nix|<nowiki>
{{file|/etc/nixos/configuration.nix|nix|<nowiki>
  networking.firewall.interfaces."eth0".allowedTCPPorts = [ 80 443 ];
networking.firewall.interfaces."eth0".allowedTCPPorts = [ 80 443 ];
</nowiki>}}
</nowiki>}}


In this case, ports <code>80</code> and <code>443</code> will be allowed for the interface <code>eth0</code>.
In this case, ports <code>80</code> and <code>443</code> will be allowed for the interface <code>eth0</code>.
=== Advanced Configuration ===
Some users may want more fine-grained control of how their firewall is configured. This can, when using nftables, be achieved by defining custom tables and chains through {{Nixos:option|networking.nftables.tables}}.
It is important to say that a <code>nixos-fw</code> table with multiple chains will be generated by setting {{Nixos:option|networking.nftables.enable}} to true. These chains can be modified with extra rules through various options within {{Nixos:option|networking.firewall}}. If possible, try to stick to these when customizing generated rules, as trying to dynamically delete and overwrite them at activation time can be ''very'' error-prone.
For instance, to expose a TCP port only to your local IPv4 and IPv6 subnets, add the following to your configuration:
{{file|/etc/nixos/configuration.nix|nix|<nowiki>
networking.firewall.extraInputRules = ''
  ip saddr 130.236.254.0/24 tcp dport 6600 accept
  ip6 saddr 2001:6b0:17:f0a0::/64 tcp dport 6600 accept
'';
</nowiki>}}
This will add the two specified rules to the <code>input-allow</code> chain in the <code>nixos-fw</code> table. You should, of course, replace the port and subnets with your own.


== Tips and tricks ==
== Tips and tricks ==
=== Log all dropped/rejected network packets ===
On a vanilla NixOS install, the [https://search.nixos.org/options?show=networking.firewall.logRefusedPackets&query=networking.firewall.logRefusedPackets <code>networking.firewall.logRefusedPackets = true;</code>] stanza lets you see lines in syslog with the prefix <code>refused packet:</code>, once you <code>sudo nixos-rebuild switch</code> and then <code>sudo dmesg --follow --human | grep 'refused packet:'</code>.


=== Temporary firewall rules ===
=== Temporary firewall rules ===


If using iptables, for temporary changes to the firewall rules, you can install the [https://search.nixos.org/packages?query=nixos-firewall-tool <code>nixos-firewall-tool</code>] package, which is a [https://github.com/NixOS/nixpkgs/blob/7eee17a8a5868ecf596bbb8c8beb527253ea8f4d/pkgs/by-name/ni/nixos-firewall-tool/nixos-firewall-tool.sh thin wrapper] around <code>iptables</code>.
For temporary changes to the firewall rules, you can install the [https://search.nixos.org/packages?query=nixos-firewall-tool <code>nixos-firewall-tool</code>] package, which is a [https://github.com/NixOS/nixpkgs/blob/7eee17a8a5868ecf596bbb8c8beb527253ea8f4d/pkgs/by-name/ni/nixos-firewall-tool/nixos-firewall-tool.sh thin wrapper] around <code>iptables</code> and <code>nftables</code>.


[[Category:Server]]
[[Category:Server]]
[[Category:Applications]]
[[Category:Applications]]