forked from mirrors/nixpkgs
40 lines
1.4 KiB
XML
40 lines
1.4 KiB
XML
|
<section xmlns="http://docbook.org/ns/docbook" xmlns:xlink="http://www.w3.org/1999/xlink" xml:id="sec-firewall">
|
||
|
<title>Firewall</title>
|
||
|
<para>
|
||
|
NixOS has a simple stateful firewall that blocks incoming
|
||
|
connections and other unexpected packets. The firewall applies to
|
||
|
both IPv4 and IPv6 traffic. It is enabled by default. It can be
|
||
|
disabled as follows:
|
||
|
</para>
|
||
|
<programlisting language="bash">
|
||
|
networking.firewall.enable = false;
|
||
|
</programlisting>
|
||
|
<para>
|
||
|
If the firewall is enabled, you can open specific TCP ports to the
|
||
|
outside world:
|
||
|
</para>
|
||
|
<programlisting language="bash">
|
||
|
networking.firewall.allowedTCPPorts = [ 80 443 ];
|
||
|
</programlisting>
|
||
|
<para>
|
||
|
Note that TCP port 22 (ssh) is opened automatically if the SSH
|
||
|
daemon is enabled
|
||
|
(<literal>services.openssh.enable = true</literal>). UDP ports can
|
||
|
be opened through
|
||
|
<link xlink:href="options.html#opt-networking.firewall.allowedUDPPorts"><literal>networking.firewall.allowedUDPPorts</literal></link>.
|
||
|
</para>
|
||
|
<para>
|
||
|
To open ranges of TCP ports:
|
||
|
</para>
|
||
|
<programlisting language="bash">
|
||
|
networking.firewall.allowedTCPPortRanges = [
|
||
|
{ from = 4000; to = 4007; }
|
||
|
{ from = 8000; to = 8010; }
|
||
|
];
|
||
|
</programlisting>
|
||
|
<para>
|
||
|
Similarly, UDP port ranges can be opened through
|
||
|
<link xlink:href="options.html#opt-networking.firewall.allowedUDPPortRanges"><literal>networking.firewall.allowedUDPPortRanges</literal></link>.
|
||
|
</para>
|
||
|
</section>
|