From e076aca5a09e04928ccf14032c217662d5fd7aeb Mon Sep 17 00:00:00 2001 From: oddlama Date: Thu, 6 Jul 2023 15:09:33 +0200 Subject: [PATCH] chore: also disable per link DNS for ipv6 (dhcp, RA) on servers --- hosts/ward/net.nix | 4 +++- hosts/zackbiene/net.nix | 4 +++- modules/meta/microvms.nix | 4 +++- 3 files changed, 9 insertions(+), 3 deletions(-) diff --git a/hosts/ward/net.nix b/hosts/ward/net.nix index ad31253..f8f9dea 100644 --- a/hosts/ward/net.nix +++ b/hosts/ward/net.nix @@ -41,7 +41,9 @@ in { }; "10-wan" = { DHCP = "yes"; - dhcpConfig.UseDNS = false; + dhcpV4Config.UseDNS = false; + dhcpV6Config.UseDNS = false; + ipv6AcceptRAConfig.UseDNS = false; #address = [ # "192.168.178.2/24" # "fdee::1/64" diff --git a/hosts/zackbiene/net.nix b/hosts/zackbiene/net.nix index 66e0583..fb540fa 100644 --- a/hosts/zackbiene/net.nix +++ b/hosts/zackbiene/net.nix @@ -16,7 +16,9 @@ in { systemd.network.networks = { "10-lan1" = { DHCP = "yes"; - dhcpConfig.UseDNS = false; + dhcpV4Config.UseDNS = false; + dhcpV6Config.UseDNS = false; + ipv6AcceptRAConfig.UseDNS = false; matchConfig.MACAddress = config.repo.secrets.local.networking.interfaces.lan1.mac; networkConfig = { IPv6PrivacyExtensions = "yes"; diff --git a/modules/meta/microvms.nix b/modules/meta/microvms.nix index 9e02e78..ee6f4b0 100644 --- a/modules/meta/microvms.nix +++ b/modules/meta/microvms.nix @@ -174,7 +174,9 @@ "10-${vmCfg.networking.mainLinkName}" = { matchConfig.MACAddress = mac; DHCP = "yes"; - dhcpConfig.UseDNS = false; + dhcpV4Config.UseDNS = false; + dhcpV6Config.UseDNS = false; + ipv6AcceptRAConfig.UseDNS = false; networkConfig = { IPv6PrivacyExtensions = "yes"; MulticastDNS = true;