<bpye>
andi-: My scenario is pretty basic, I've ended up configuring dnsmasq for DHCP and a local DNS resolver because I want local machines to resolve - getting dhcpd4 and BIND working seemed a whole lot of hassle. And currently I'm using the iptables support under networking.firewall and networking.nat but I may change that to nftables because I want to
<bpye>
do things like have open ports only for specific IPs, which isn't something that can be achieved with the current Nix config options.