Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Server Network — Centralized Subnets and Firewall

Purpose

The network module coordinates network subnet definitions and firewall rules, allowing for centralized configuration of subnets and automatic propagation of these settings to other servers in the cluster.

Entry Point

  • Main file: modules/nixos/server/network.nix

Options

server.network.openPortsForSubnet.tcp

Typelist of 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default[ ]

List of TCP ports to open on the firewall for each subnet.


server.network.openPortsForSubnet.udp

Typelist of 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default[ ]

List of UDP ports to open on the firewall for each subnet.


server.network.subnets

Typelist of (submodule)
Default{ }

This option has no description.


server.network.subnets.*.dns

Typestring

DNS server for the subnet.


server.network.subnets.*.domain

Typestring

Domain name for the subnet.


server.network.subnets.*.ipv4

Typesubmodule
Default{ }

IPv4 configuration for the subnet.


server.network.subnets.*.ipv4.arpa

Typenull or string
Defaultnull

ARPA notation for reverse DNS lookups.


server.network.subnets.*.ipv4.cidr

Typenull or string
Defaultnull

CIDR notation for the IP range.


server.network.subnets.*.ipv6

Typesubmodule
Default{ }

IPv6 configuration for the subnet.


server.network.subnets.*.ipv6.arpa

Typenull or string
Defaultnull

ARPA notation for reverse DNS lookups.


server.network.subnets.*.ipv6.cidr

Typenull or string
Defaultnull

CIDR notation for the IP range.


Architecture / Services / Scope

  • This module uses getIOPrimaryHostAttr to fetch the server.network.subnets configuration from the IO Coordinator (server.ioPrimaryHost), ensuring all servers in the cluster are aware of the network structure defined there.
  • The module automatically generates iptables and ip6tables rules for the specified ports, allowing traffic only from the defined subnets.
  • These rules are added to the nixos-fw chain and are managed through the networking.firewall.extraCommands and networking.firewall.extraStopCommands options.

Operational Notes / Assumptions

  • Subnets and per-subnet open ports are declared on the IO Coordinator via server.network.subnets and server.network.openPortsForSubnet.

References