allow dhcp client on wan

This commit is contained in:
Daniel Barlow 2023-06-28 23:51:21 +01:00
parent 8affb151b5
commit 1f1164cc98

View file

@ -106,6 +106,16 @@ in {
(accept "tcp dport 22") (accept "tcp dport 22")
]; ];
}; };
input-wan = {
type = "filter";
family = "ip6";
rules = [
(accept "udp dport 546") # dhcp client, needed for prefix delegation
];
};
input-ip6 = { input-ip6 = {
type = "filter"; type = "filter";
family = "ip6"; family = "ip6";
@ -114,6 +124,7 @@ in {
rules = [ rules = [
(accept "meta l4proto icmpv6") (accept "meta l4proto icmpv6")
"iifname int jump input-lan" "iifname int jump input-lan"
"iifname ppp0 jump input-wan"
(if allow-incoming (if allow-incoming
then accept "oifname \"int\" iifname \"ppp0\"" then accept "oifname \"int\" iifname \"ppp0\""
else "oifname \"int\" iifname \"ppp0\" jump incoming-allowed-ip6" else "oifname \"int\" iifname \"ppp0\" jump incoming-allowed-ip6"