Require tun device and trust Tailscale interface in firewall

This commit is contained in:
RingOfStorms (Joshua Bell) 2026-01-05 23:05:43 -06:00
parent 485694c33f
commit 3bb634f358

View file

@ -20,6 +20,16 @@
"--no-logs-no-support"
];
};
systemd.services.tailscaled = {
after = [
"systemd-modules-load.service"
"dev-net-tun.device"
];
wants = [ "dev-net-tun.device" ];
requires = [ "dev-net-tun.device" ];
};
networking.firewall.trustedInterfaces = [ config.services.tailscale.interfaceName ];
networking.firewall.checkReversePath = "loose";
}