summaryrefslogtreecommitdiff
path: root/common
diff options
context:
space:
mode:
Diffstat (limited to 'common')
-rw-r--r--common/core.nix1
-rw-r--r--common/default.nix1
-rw-r--r--common/lan-discovery.nix22
3 files changed, 23 insertions, 1 deletions
diff --git a/common/core.nix b/common/core.nix
index c06069a..9e9ca7a 100644
--- a/common/core.nix
+++ b/common/core.nix
@@ -18,7 +18,6 @@
# for tailscale; open only its discovery/connection UDP port and let the
# normal host firewall rules apply to tailnet traffic too.
- networking.firewall.allowPing = true;
networking.firewall.allowedUDPPorts = [ 41641 ];
services.tailscale.enable = true;
diff --git a/common/default.nix b/common/default.nix
index 946b3a7..e977351 100644
--- a/common/default.nix
+++ b/common/default.nix
@@ -5,5 +5,6 @@
{
imports = [
./core.nix
+ ./lan-discovery.nix
];
}
diff --git a/common/lan-discovery.nix b/common/lan-discovery.nix
new file mode 100644
index 0000000..f12971f
--- /dev/null
+++ b/common/lan-discovery.nix
@@ -0,0 +1,22 @@
+# LAN reachability and mDNS discovery shared by all machines.
+{ ... }:
+
+{
+ # Allow IPv4 ICMP echo requests so hosts can be found with ping.
+ networking.firewall.allowPing = true;
+
+ # Avahi/mDNS: publish <hostname>.local and resolve other *.local LAN names.
+ # Keep the multicast DNS firewall opening scoped to the Wi-Fi LAN interface.
+ networking.firewall.interfaces.wlp8s0.allowedUDPPorts = [ 5353 ];
+ services.avahi = {
+ enable = true;
+ nssmdns4 = true;
+ openFirewall = false;
+ allowInterfaces = [ "wlp8s0" ];
+ publish = {
+ enable = true;
+ addresses = true;
+ workstation = true;
+ };
+ };
+}