diff options
| author | Tim Keller <tjk@tjkeller.xyz> | 2026-10-05 15:33:19 -0500 |
|---|---|---|
| committer | Tim Keller <tjk@tjkeller.xyz> | 2026-10-05 15:33:19 -0500 |
| commit | 8ec65b9d39f3a8f9b4039abe7ba6f15031c15843 (patch) | |
| tree | 060f5d2fc4ab8d2b13e1dfa491dc454854e2a215 /hosts/flex-wg-router/configuration.nix | |
| parent | 44faea7b8e2b561f9fa301097cd4c1d31a268521 (diff) | |
| download | nixos-8ec65b9d39f3a8f9b4039abe7ba6f15031c15843.tar.xz nixos-8ec65b9d39f3a8f9b4039abe7ba6f15031c15843.zip | |
wg update and routing for flex
Diffstat (limited to 'hosts/flex-wg-router/configuration.nix')
| -rw-r--r-- | hosts/flex-wg-router/configuration.nix | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/hosts/flex-wg-router/configuration.nix b/hosts/flex-wg-router/configuration.nix index 22fd06d..3f6ad06 100644 --- a/hosts/flex-wg-router/configuration.nix +++ b/hosts/flex-wg-router/configuration.nix @@ -48,6 +48,16 @@ in { allowedUDPPorts = [ 51820 ]; }; }; + # NAT/masquerade lan0 allowing wg0 clients to access lan0 + nftables.tables.wg-nat = { + family = "ip"; + content = '' + chain post { + type nat hook postrouting priority srcnat; policy accept; + iifname "wg0" oifname "lan0" masquerade comment "wg0 => lan0" + } + ''; + }; }; # Router config |
