mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 22:37:25 +03:00
fix(vds-nftables): remove allowPing — not a top-level networking option
networking.allowPing was a top-level networking option when firewall.enable = true. With firewall.enable = false (T3 Option A), the option no longer exists at the networking level. ICMP is now handled by the nftables ruleset directly (). Rebuild error: 'The option networking.allowPing does not exist. Definition values: networking.domain, networking.vlans, networking.wicd.' Fix: remove the line. No behavior change — ICMP is still accepted via nftables.
This commit is contained in:
@@ -89,7 +89,10 @@
|
|||||||
firewall.enable = false;
|
firewall.enable = false;
|
||||||
firewall.allowedTCPPorts = lib.mkForce [ ];
|
firewall.allowedTCPPorts = lib.mkForce [ ];
|
||||||
firewall.interfaces = lib.mkForce { };
|
firewall.interfaces = lib.mkForce { };
|
||||||
allowPing = true;
|
# allowPing removed 2026-10-10 (T3 Option A): with firewall.enable = false,
|
||||||
|
# `networking.allowPing` no longer exists as a top-level option. ICMP
|
||||||
|
# accept is now handled by the nftables ruleset below
|
||||||
|
# (`ip protocol icmp accept`).
|
||||||
nftables = {
|
nftables = {
|
||||||
enable = true;
|
enable = true;
|
||||||
ruleset = ''
|
ruleset = ''
|
||||||
|
|||||||
Reference in New Issue
Block a user