From bbedc6d466ef240c2ff1956e4155fdeb8dfc6d78 Mon Sep 17 00:00:00 2001 From: seth Date: Sun, 14 May 2023 09:03:44 -0400 Subject: hosts: start using tailscale + endlessh -> fail2ban --- modules/nixos/server/default.nix | 20 ++++++-------------- 1 file changed, 6 insertions(+), 14 deletions(-) (limited to 'modules/nixos/server/default.nix') diff --git a/modules/nixos/server/default.nix b/modules/nixos/server/default.nix index 504a333..210484e 100644 --- a/modules/nixos/server/default.nix +++ b/modules/nixos/server/default.nix @@ -24,15 +24,6 @@ in { environment.systemPackages = [pkgs.cachix]; - networking = { - firewall = let - ports = [80 420]; - in { - allowedUDPPorts = ports; - allowedTCPPorts = ports; - }; - }; - nix = { gc.options = "--delete-older-than 7d --max-freed 50G"; settings = { @@ -63,16 +54,17 @@ in { }; services = { - endlessh = { - enable = mkDefault true; - port = mkDefault 22; - openFirewall = mkDefault true; + fail2ban = { + enable = true; + bantime-increment = { + enable = true; + }; + maxretry = 5; }; openssh = { enable = true; passwordAuthentication = mkDefault false; - ports = mkDefault [420]; }; }; }; -- cgit v1.2.3