add comments
This commit is contained in:
parent
1117f98afc
commit
f73a9d82dc
1 changed files with 5 additions and 2 deletions
|
@ -44,11 +44,14 @@ in
|
||||||
let svc = (pkgs.callPackage ./service.nix {}) params;
|
let svc = (pkgs.callPackage ./service.nix {}) params;
|
||||||
in svc // { dependencies = svc.dependencies ++ [loadModules]; };
|
in svc // { dependencies = svc.dependencies ++ [loadModules]; };
|
||||||
|
|
||||||
|
# For historical reasons the kernel config is split between
|
||||||
|
# monolithic options and modules. TODO: go through this list
|
||||||
|
# and see what can be moved into the "kconf" definiton above
|
||||||
kernel.config = {
|
kernel.config = {
|
||||||
NETFILTER_XT_MATCH_CONNTRACK = "y";
|
NETFILTER_XT_MATCH_CONNTRACK = "y";
|
||||||
|
|
||||||
IP6_NF_IPTABLES= "y"; # do we still need these
|
IP6_NF_IPTABLES= "y";
|
||||||
IP_NF_IPTABLES= "y"; # if using nftables directly
|
IP_NF_IPTABLES= "y";
|
||||||
|
|
||||||
IP_NF_NAT = "y";
|
IP_NF_NAT = "y";
|
||||||
IP_NF_TARGET_MASQUERADE = "y";
|
IP_NF_TARGET_MASQUERADE = "y";
|
||||||
|
|
Loading…
Reference in a new issue