From 5785169d43d82965ec7827c44318be4d6b64e90b Mon Sep 17 00:00:00 2001 From: Dominik Polakovics Date: Wed, 6 Dec 2023 17:41:25 +0100 Subject: [PATCH] fix firewall rule --- hosts/fw.cloonar.com/modules/firewall.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hosts/fw.cloonar.com/modules/firewall.nix b/hosts/fw.cloonar.com/modules/firewall.nix index 72680fc..0a23184 100644 --- a/hosts/fw.cloonar.com/modules/firewall.nix +++ b/hosts/fw.cloonar.com/modules/firewall.nix @@ -157,7 +157,7 @@ # iifname "multimedia" ip saddr udp dport { mdns, llmnr } counter accept # Accept web to git server - iifname "wan" oifname "server" tcp dst 10.42.97.50 dport { 22, 80, 443 } counter accept + iifname "wan" oifname "server" ip daddr 10.42.97.50 tcp dport { 22, 80, 443 } counter accept # Allow returning traffic from wg_cloonar and drop everthing else iifname "wg_cloonar" ct state { established, related } counter accept