diff --git a/modules/server/nftables/default.nix b/modules/server/nftables/default.nix index 5ba2ca7..222fa50 100644 --- a/modules/server/nftables/default.nix +++ b/modules/server/nftables/default.nix @@ -18,6 +18,8 @@ in{ ${if builtins.length cfg.db > 0 then ''tcp dport {5432, 6379} ip saddr { 10.0.0.0/8, 169.254.0.0/16 } accept'' else ""} ${if cfg.web then ''tcp dport {80, 443} accept udp dport {80, 443} accept'' else ""} + ${if cfg.wireguard then ''tcp dport {1515} accept + udp dport {1515} accept'' else ""} }