diff --git a/hosts/fw.cloonar.com/modules/firewall.nix b/hosts/fw.cloonar.com/modules/firewall.nix index 1a08e0d..faebaa3 100644 --- a/hosts/fw.cloonar.com/modules/firewall.nix +++ b/hosts/fw.cloonar.com/modules/firewall.nix @@ -141,9 +141,13 @@ "smart", "podman*", "multimedia" - } udp dport { 53, 67, 68 } counter accept + } udp dport { 67, 68 } counter accept - udp dport { 53 } counter accept + # Allow networks to access web proxy + iifname { + "lan", + "wg_cloonar", + } tcp dport { 80, 443 } counter accept # Accept mDNS for avahi reflection # iifname "multimedia" ip saddr tcp dport { llmnr } counter accept