diff --git a/modules/core/network.nix b/modules/core/network.nix index 1d07504..8f7d819 100644 --- a/modules/core/network.nix +++ b/modules/core/network.nix @@ -12,21 +12,7 @@ # ]; ### https://nixos.wiki/wiki/WireGuard#Setting_up_WireGuard_with_NetworkManager - # if packets are still dropped, they will show up in dmesg - logReversePathDrops = true; - # wireguard trips rpfilter up - extraCommands = '' - iptables -t mangle -I nixos-fw-rpfilter -p udp -m udp --sport 51820 -j RETURN - ip6tables -t mangle -I nixos-fw-rpfilter -p udp -m udp --sport 51820 -j RETURN - iptables -t mangle -I nixos-fw-rpfilter -p udp -m udp --dport 51820 -j RETURN - ip6tables -t mangle -I nixos-fw-rpfilter -p udp -m udp --dport 51820 -j RETURN - ''; - extraStopCommands = '' - iptables -t mangle -D nixos-fw-rpfilter -p udp -m udp --sport 51820 -j RETURN || true - ip6tables -t mangle -D nixos-fw-rpfilter -p udp -m udp --sport 51820 -j RETURN || true - iptables -t mangle -D nixos-fw-rpfilter -p udp -m udp --dport 51820 -j RETURN || true - ip6tables -t mangle -D nixos-fw-rpfilter -p udp -m udp --dport 51820 -j RETURN || true - ''; + checkReversePath = "loose"; }; };