From 4b31600f4555f66002317eaf41343cbb6a4e760b Mon Sep 17 00:00:00 2001 From: Pedro Rey Anca Date: Tue, 18 Mar 2025 18:45:23 +0100 Subject: [PATCH] Fix the wireguard problems for good --- modules/core/network.nix | 16 +--------------- 1 file changed, 1 insertion(+), 15 deletions(-) diff --git a/modules/core/network.nix b/modules/core/network.nix index 1d07504..8f7d819 100644 --- a/modules/core/network.nix +++ b/modules/core/network.nix @@ -12,21 +12,7 @@ # ]; ### https://nixos.wiki/wiki/WireGuard#Setting_up_WireGuard_with_NetworkManager - # if packets are still dropped, they will show up in dmesg - logReversePathDrops = true; - # wireguard trips rpfilter up - extraCommands = '' - iptables -t mangle -I nixos-fw-rpfilter -p udp -m udp --sport 51820 -j RETURN - ip6tables -t mangle -I nixos-fw-rpfilter -p udp -m udp --sport 51820 -j RETURN - iptables -t mangle -I nixos-fw-rpfilter -p udp -m udp --dport 51820 -j RETURN - ip6tables -t mangle -I nixos-fw-rpfilter -p udp -m udp --dport 51820 -j RETURN - ''; - extraStopCommands = '' - iptables -t mangle -D nixos-fw-rpfilter -p udp -m udp --sport 51820 -j RETURN || true - ip6tables -t mangle -D nixos-fw-rpfilter -p udp -m udp --sport 51820 -j RETURN || true - iptables -t mangle -D nixos-fw-rpfilter -p udp -m udp --dport 51820 -j RETURN || true - ip6tables -t mangle -D nixos-fw-rpfilter -p udp -m udp --dport 51820 -j RETURN || true - ''; + checkReversePath = "loose"; }; };