allow traffic to dns from everywhere
This commit is contained in:
0
.gitea/workflows/default.yaml
Normal file
0
.gitea/workflows/default.yaml
Normal file
@@ -140,17 +140,7 @@
|
|||||||
"wg_cloonar",
|
"wg_cloonar",
|
||||||
"smart",
|
"smart",
|
||||||
"multimedia"
|
"multimedia"
|
||||||
} udp dport { 53, 67, 68 } counter accept
|
} udp dport { 67, 68 } counter accept
|
||||||
iifname {
|
|
||||||
"lan",
|
|
||||||
"server",
|
|
||||||
"vserver",
|
|
||||||
"vb-*",
|
|
||||||
"infrastructure",
|
|
||||||
"wg_cloonar",
|
|
||||||
"smart",
|
|
||||||
"multimedia"
|
|
||||||
} tcp dport { 80, 443, 853 } counter accept
|
|
||||||
|
|
||||||
# Accept mDNS for avahi reflection
|
# Accept mDNS for avahi reflection
|
||||||
# iifname "multimedia" ip saddr <chromecast IP> tcp dport { llmnr } counter accept
|
# iifname "multimedia" ip saddr <chromecast IP> tcp dport { llmnr } counter accept
|
||||||
@@ -192,6 +182,7 @@
|
|||||||
|
|
||||||
# lan and vpn to any
|
# lan and vpn to any
|
||||||
# TODO: disable wan when finished
|
# TODO: disable wan when finished
|
||||||
|
oifname { "server" } ip daddr 10.42.97.10 udp dport { 53 } accept
|
||||||
iifname { "lan", "server", "vserver", "wg_cloonar" } oifname { "lan", "vb-*", "server", "vserver", "infrastructure", "multimedia", "smart", "wg_cloonar" } counter accept
|
iifname { "lan", "server", "vserver", "wg_cloonar" } oifname { "lan", "vb-*", "server", "vserver", "infrastructure", "multimedia", "smart", "wg_cloonar" } counter accept
|
||||||
iifname { "lan", "server", "wg_cloonar" } oifname { "wrwks", "wg_epicenter", "wg_ghetto_at" } counter accept
|
iifname { "lan", "server", "wg_cloonar" } oifname { "wrwks", "wg_epicenter", "wg_ghetto_at" } counter accept
|
||||||
iifname { "infrastructure" } oifname { "server", "vserver" } counter accept
|
iifname { "infrastructure" } oifname { "server", "vserver" } counter accept
|
||||||
|
|||||||
Reference in New Issue
Block a user