firewall changes
This commit is contained in:
@@ -139,6 +139,7 @@
|
|||||||
"infrastructure",
|
"infrastructure",
|
||||||
"wg_cloonar",
|
"wg_cloonar",
|
||||||
"smart",
|
"smart",
|
||||||
|
"podman*",
|
||||||
"multimedia"
|
"multimedia"
|
||||||
} udp dport { 53, 67, 68 } counter accept
|
} udp dport { 53, 67, 68 } counter accept
|
||||||
|
|
||||||
@@ -148,6 +149,9 @@
|
|||||||
# iifname "multimedia" ip saddr <chromecast IP> tcp dport { llmnr } counter accept
|
# iifname "multimedia" ip saddr <chromecast IP> tcp dport { llmnr } counter accept
|
||||||
# iifname "multimedia" ip saddr <chromecast IP> udp dport { mdns, llmnr } counter accept
|
# iifname "multimedia" ip saddr <chromecast IP> udp dport { mdns, llmnr } counter accept
|
||||||
|
|
||||||
|
# Allow all returning traffic
|
||||||
|
ct state { established, related } counter accept
|
||||||
|
|
||||||
|
|
||||||
# Allow returning traffic from wg_cloonar and drop everthing else
|
# Allow returning traffic from wg_cloonar and drop everthing else
|
||||||
iifname "wg_cloonar" ct state { established, related } counter accept
|
iifname "wg_cloonar" ct state { established, related } counter accept
|
||||||
@@ -204,7 +208,7 @@
|
|||||||
"multimedia",
|
"multimedia",
|
||||||
"smart",
|
"smart",
|
||||||
"wg_cloonar",
|
"wg_cloonar",
|
||||||
"podman1",
|
"podman*",
|
||||||
} oifname {
|
} oifname {
|
||||||
"wan",
|
"wan",
|
||||||
} counter accept comment "Allow trusted LAN to WAN"
|
} counter accept comment "Allow trusted LAN to WAN"
|
||||||
|
|||||||
@@ -131,20 +131,6 @@ in
|
|||||||
labels = [
|
labels = [
|
||||||
"ubuntu-latest:docker://shivammathur/node:latest"
|
"ubuntu-latest:docker://shivammathur/node:latest"
|
||||||
];
|
];
|
||||||
settings = {
|
|
||||||
runner = {
|
|
||||||
envs = {
|
|
||||||
DOCKER_DAEMON_CONFIG = ''
|
|
||||||
{
|
|
||||||
"dns": ["10.42.97.10"]
|
|
||||||
}
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
};
|
|
||||||
# container = {
|
|
||||||
# options = "--network=server";
|
|
||||||
# };
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
|
|
||||||
# containers.git-runner = {
|
# containers.git-runner = {
|
||||||
|
|||||||
Reference in New Issue
Block a user