nixos-module/container/upstream: specify externalIP to use SNAT instead of MASQUERADE
This commit is contained in:
parent
1b4f761de8
commit
501f96a225
|
@ -56,6 +56,7 @@ in
|
||||||
enable = true;
|
enable = true;
|
||||||
internalInterfaces = [ "core" ];
|
internalInterfaces = [ "core" ];
|
||||||
externalInterface = firstUpstreamInterface;
|
externalInterface = firstUpstreamInterface;
|
||||||
|
externalIP = upstreamInterfaces.${firstUpstreamInterface}.upstream.staticIpv4Address;
|
||||||
extraCommands =
|
extraCommands =
|
||||||
# Provide IPv6 upstream for everyone, using NAT66 when not from
|
# Provide IPv6 upstream for everyone, using NAT66 when not from
|
||||||
# our static prefixes
|
# our static prefixes
|
||||||
|
|
Loading…
Reference in New Issue