diff --git a/hosts/fw.cloonar.com/modules/firewall.nix b/hosts/fw.cloonar.com/modules/firewall.nix index 12d0f7c..8a10c1c 100644 --- a/hosts/fw.cloonar.com/modules/firewall.nix +++ b/hosts/fw.cloonar.com/modules/firewall.nix @@ -29,14 +29,21 @@ "wg_cloonar" } counter accept - # Allow networks to access the dns + # Allow networks to access the dns and dhcp iifname { "lan", "server", "wg_cloonar", "smart", "multimedia" - } udp dport { 53, 67, 68 } tcp dport { 80, 443, 853 } counter accept + } udp dport { 53, 67, 68 } counter accept + iifname { + "lan", + "server", + "wg_cloonar", + "smart", + "multimedia" + } tcp dport { 80, 443, 853 } counter accept # Accept mDNS for avahi reflection # iifname "multimedia" ip saddr tcp dport { llmnr } counter accept