eyJhb changed the topic of #nixos-on-your-router to: NixOS on your Router || https://logs.nix.samueldr.com/nixos-on-your-router
danderson has joined #nixos-on-your-router
early has joined #nixos-on-your-router
night has quit [Quit: night]
NightA has joined #nixos-on-your-router
NightA is now known as night
eyJhb has joined #nixos-on-your-router
<eyJhb> thefloweringash: maybe a discussion in here?
<thefloweringash> Oh, hi there. :-)
<eyJhb> But you use nftables on your router? Any public configs?
<thefloweringash> the config is public, don’t know if that’s a good idea, but here it is: https://bitbucket.org/thefloweringash/routernix-config/
<thefloweringash> My internet is slightly interesting. It’s map-e, which is native ipv6 with tunneled ipv4. The interesting part is that I get a static division of a public v4 address (16 sets of 16 ports), and do the nat locally
<thefloweringash> Since I don’t know of a nice way to do this in Linux, I implemented a layer of nat in bpf
<eyJhb> `ip6 saddr { 240e:f7:4f01:c::/64, 240e:d9:d800:200::/64 } counter drop comment "china probes"` ohh come on, we love those probes! - Yeah I can see that there is a lot af nice things in there
<eyJhb> I must however admit, that I have not gotten used to IPv6 yet. Maybe I should...
<eyJhb> Basically doing some nftables + IPv6 at home would be cool, also just to know the technology. But I rarely do much netwoking, simple tagging on interfaces seems like magic to me
<thefloweringash> I feel a bit bad for blocking as much of the internet as that, but it was making debugging things harder.
<eyJhb> Understandable, I am on a NAT network here were I live, so I have no real front facing IP. So I don't have that issue
<eyJhb> But it is understandable, there is a lot of.. Stuff from CN
lopsided98_ has quit [Quit: Disconnected]
lopsided98 has joined #nixos-on-your-router
ehmry has quit [Quit: https://quassel-irc.org - Chat comfortably. Anywhere.]
ehmry has joined #nixos-on-your-router
lopsided98_ has joined #nixos-on-your-router
lopsided98 has quit [Ping timeout: 260 seconds]
teto has joined #nixos-on-your-router