feat: allow smb access from fritz-vlan

This commit is contained in:
Patrick 2025-01-14 22:19:27 +01:00
parent 1b983b62d1
commit e15f7aaf4d
Signed by: patrick
GPG key ID: 451F95EFB8BECD0F
3 changed files with 6 additions and 5 deletions

View file

@ -41,8 +41,8 @@
]; ];
}; };
user_rules = [ user_rules = [
"||homematic.internal^$dnsrewrite=${lib.net.cidr.host 30 globals.net.vlans.devices.cidrv4}" # "||homematic.internal^$dnsrewrite=${lib.net.cidr.host 30 globals.net.vlans.devices.cidrv4}"
"||testberry.internal^$dnsrewrite=${lib.net.cidr.host 31 globals.net.vlans.devices.cidrv4}" # "||testberry.internal^$dnsrewrite=${lib.net.cidr.host 31 globals.net.vlans.devices.cidrv4}"
"||smb.internal^$dnsrewrite=${lib.net.cidr.host globals.services.samba.ip globals.net.vlans.home.cidrv4}" "||smb.internal^$dnsrewrite=${lib.net.cidr.host globals.services.samba.ip globals.net.vlans.home.cidrv4}"
"||${globals.domains.web}^$dnsrewrite=${lib.net.cidr.host 1 globals.net.vlans.services.cidrv4}" "||${globals.domains.web}^$dnsrewrite=${lib.net.cidr.host 1 globals.net.vlans.services.cidrv4}"
"@@||${globals.services.vaultwarden.domain}" "@@||${globals.services.vaultwarden.domain}"

View file

@ -62,9 +62,7 @@
networks.wlan01 = { networks.wlan01 = {
inherit (globals.hostapd) ssid; inherit (globals.hostapd) ssid;
apIsolate = true; apIsolate = true;
# not supporte by laptop :( #logLevel = 0;
#settings.ieee80211w = 0;
logLevel = 0;
settings = { settings = {
bridge = "br-iot"; bridge = "br-iot";
}; };

View file

@ -171,6 +171,7 @@ in
printer-smb = { printer-smb = {
from = [ from = [
"printer" "printer"
"fritz"
]; ];
to = [ "smb" ]; to = [ "smb" ];
allowedTCPPorts = [ 445 ]; allowedTCPPorts = [ 445 ];
@ -200,8 +201,10 @@ in
from = [ from = [
"home" "home"
"devices" "devices"
"fritz"
"guests" "guests"
"services" "services"
"fritz"
]; ];
to = [ "adguard" ]; to = [ "adguard" ];
allowedUDPPorts = [ 53 ]; allowedUDPPorts = [ 53 ];