nftables: simplify nameserver control socket rules

This commit is contained in:
Daniel Micay 2025-06-27 13:10:16 -04:00
parent 719e1fcd35
commit 3b2f6d546c
2 changed files with 5 additions and 5 deletions

View file

@ -131,11 +131,11 @@ table inet filter {
skuid powerdns meta l4proto { tcp, udp } th sport 54 th dport >= 1024 notrack accept
skuid dnsdist meta l4proto { tcp, udp } th sport >= 1024 th dport 54 notrack accept
skuid powerdns meta l4proto tcp th sport 81 th dport >= 1024 notrack accept
skuid powerdns tcp sport 81 tcp dport >= 1024 notrack accept
skuid dnsdist meta l4proto tcp th sport 5199 th dport >= 1024 notrack accept
skuid dnsdist tcp sport 5199 tcp dport >= 1024 notrack accept
skuid zerotier-one meta l4proto tcp th sport 9993 th dport >= 1024 notrack accept
skuid zerotier-one tcp sport 9993 tcp dport >= 1024 notrack accept
skuid != root counter goto graceful-reject
notrack accept

View file

@ -129,9 +129,9 @@ table inet filter {
skuid powerdns meta l4proto { tcp, udp } th sport 54 th dport >= 1024 notrack accept
skuid dnsdist meta l4proto { tcp, udp } th sport >= 1024 th dport 54 notrack accept
skuid powerdns meta l4proto tcp th sport 81 th dport >= 1024 notrack accept
skuid powerdns tcp sport 81 tcp dport >= 1024 notrack accept
skuid dnsdist meta l4proto tcp th sport 5199 th dport >= 1024 notrack accept
skuid dnsdist tcp sport 5199 tcp dport >= 1024 notrack accept
skuid != root counter goto graceful-reject
notrack accept