Update IPs on firewall services
This commit is contained in:
parent
054a85411e
commit
41b88911bc
4 changed files with 4 additions and 4 deletions
|
@ -4,7 +4,7 @@
|
||||||
enable = true;
|
enable = true;
|
||||||
maxretry = 5;
|
maxretry = 5;
|
||||||
bantime = "10m";
|
bantime = "10m";
|
||||||
ignoreIP = [ "10.0.0.0/8" ];
|
ignoreIP = [ "11.0.0.0/8" ];
|
||||||
};
|
};
|
||||||
|
|
||||||
environment.persistence."/persist".directories = [ "/var/lib/fail2ban" ];
|
environment.persistence."/persist".directories = [ "/var/lib/fail2ban" ];
|
||||||
|
|
|
@ -4,6 +4,6 @@
|
||||||
|
|
||||||
config = lib.mkIf config.services.nfs.server.enable {
|
config = lib.mkIf config.services.nfs.server.enable {
|
||||||
services.nfs.server.exports = "/storage *(rw,sync,no_subtree_check)";
|
services.nfs.server.exports = "/storage *(rw,sync,no_subtree_check)";
|
||||||
networking.firewall.extraInputRules = "ip saddr 10.0.0.0/8 tcp dport 2049 accept";
|
networking.firewall.extraInputRules = "ip saddr 11.0.0.0/8 tcp dport 2049 accept";
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
|
@ -23,7 +23,7 @@
|
||||||
}
|
}
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
networking.firewall.extraInputRules = "ip saddr { 10.0.0.0/8, ${config.secrets.ips.luna}, ${config.secrets.ips.corn} } tcp dport 1935 accept";
|
networking.firewall.extraInputRules = "ip saddr { 11.0.0.0/8, ${config.secrets.ips.luna}, ${config.secrets.ips.corn} } tcp dport 1935 accept";
|
||||||
systemd.services.nginx.serviceConfig.ReadWritePaths = [ "/var/www/landing-page/streams/hls/" ];
|
systemd.services.nginx.serviceConfig.ReadWritePaths = [ "/var/www/landing-page/streams/hls/" ];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
|
@ -7,7 +7,7 @@
|
||||||
port = 8060;
|
port = 8060;
|
||||||
rtmp-port = 1945;
|
rtmp-port = 1945;
|
||||||
};
|
};
|
||||||
networking.firewall.extraInputRules = "ip saddr 10.0.0.0/8 tcp dport 1945 accept";
|
networking.firewall.extraInputRules = "ip saddr 11.0.0.0/8 tcp dport 1945 accept";
|
||||||
environment.persistence."/persist".directories = [ "/var/lib/owncast" ];
|
environment.persistence."/persist".directories = [ "/var/lib/owncast" ];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue