allow dns from everywhere

This commit is contained in:
2023-12-07 09:01:36 +01:00
parent 40fb010825
commit 83a2a9cd46

View File

@@ -136,13 +136,14 @@
"lan", "lan",
"server", "server",
"vserver", "vserver",
"podman1",
"infrastructure", "infrastructure",
"wg_cloonar", "wg_cloonar",
"smart", "smart",
"multimedia" "multimedia"
} udp dport { 53, 67, 68 } counter accept } udp dport { 53, 67, 68 } counter accept
udp dport { 53 } counter accept
# Accept mDNS for avahi reflection # Accept mDNS for avahi reflection
# iifname "multimedia" ip saddr <chromecast IP> tcp dport { llmnr } counter accept # iifname "multimedia" ip saddr <chromecast IP> tcp dport { llmnr } counter accept
# iifname "multimedia" ip saddr <chromecast IP> udp dport { mdns, llmnr } counter accept # iifname "multimedia" ip saddr <chromecast IP> udp dport { mdns, llmnr } counter accept
@@ -187,7 +188,6 @@
# lan and vpn to any # lan and vpn to any
# TODO: disable wan when finished # TODO: disable wan when finished
oifname { "server" } ip daddr 10.42.97.10 udp dport { 53 } accept
iifname { "lan", "server", "vserver", "wg_cloonar" } oifname { "lan", "vb-*", "server", "vserver", "infrastructure", "multimedia", "smart", "wg_cloonar" } counter accept iifname { "lan", "server", "vserver", "wg_cloonar" } oifname { "lan", "vb-*", "server", "vserver", "infrastructure", "multimedia", "smart", "wg_cloonar" } counter accept
iifname { "lan", "server", "wg_cloonar" } oifname { "wrwks", "wg_epicenter", "wg_ghetto_at" } counter accept iifname { "lan", "server", "wg_cloonar" } oifname { "wrwks", "wg_epicenter", "wg_ghetto_at" } counter accept
iifname { "infrastructure" } oifname { "server", "vserver" } counter accept iifname { "infrastructure" } oifname { "server", "vserver" } counter accept