nixos/firewall: change networking.firewall.checkReversePath to "loose"

The current default strict is neither the default of the linux kernel
nor the default of systemd. Furthermore strict can break valid setups
involving split DNS where the DNS resolver is not in the same broadcast
domain as the client.

Systemd changed the default value in November 2018 from strict to loose
so this PR aligns the module with upstream (see systemd/systemd#10971).

The Kernel default is 0:
https://sysctl-explorer.net/net/ipv4/rp_filter/

Note that such an option does not exist for IPV6.
This commit is contained in:
Dr. Jonathan Berrisch
2026-08-10 11:00:09 +02:00
parent 89d3b41502
commit fa581aaa6b

View File

@@ -205,8 +205,8 @@ in
"loose"
]
);
default = true;
defaultText = lib.literalMD "`true` except if the iptables based firewall is in use and the kernel lacks rpfilter support";
default = "loose";
defaultText = "loose";
example = "loose";
description = ''
Performs a reverse path filter test on a packet. If a reply