mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-04 14:00:04 +00:00
nixos/firewall: change networking.firewall.checkReversePath to "loose"
The current default strict is neither the default of the linux kernel nor the default of systemd. Furthermore strict can break valid setups involving split DNS where the DNS resolver is not in the same broadcast domain as the client. Systemd changed the default value in November 2018 from strict to loose so this PR aligns the module with upstream (see systemd/systemd#10971). The Kernel default is 0: https://sysctl-explorer.net/net/ipv4/rp_filter/ Note that such an option does not exist for IPV6.
This commit is contained in:
@@ -205,8 +205,8 @@ in
|
||||
"loose"
|
||||
]
|
||||
);
|
||||
default = true;
|
||||
defaultText = lib.literalMD "`true` except if the iptables based firewall is in use and the kernel lacks rpfilter support";
|
||||
default = "loose";
|
||||
defaultText = "loose";
|
||||
example = "loose";
|
||||
description = ''
|
||||
Performs a reverse path filter test on a packet. If a reply
|
||||
|
||||
Reference in New Issue
Block a user