nftables: extend notrack rules for ADoT changes

This commit is contained in:
Daniel Micay 2024-01-19 12:51:35 -05:00
parent a954a4a024
commit 5ed0c02e99
2 changed files with 4 additions and 4 deletions

View File

@ -8,7 +8,7 @@ table inet filter {
iif lo notrack accept
udp dport 53 notrack accept
tcp dport {22, 53} notrack accept
tcp dport {22, 53, 80, 443, 853} notrack accept
meta l4proto {icmp, ipv6-icmp} notrack accept
}
@ -17,7 +17,7 @@ table inet filter {
oif lo notrack accept
udp sport 53 notrack accept
tcp sport {22, 53} notrack accept
tcp sport {22, 53, 80, 443, 853} notrack accept
meta l4proto {icmp, ipv6-icmp} notrack accept
}

View File

@ -8,7 +8,7 @@ table inet filter {
iif lo notrack accept
udp dport 53 notrack accept
tcp dport {22, 53} notrack accept
tcp dport {22, 53, 80, 443, 853} notrack accept
meta l4proto {icmp, ipv6-icmp} notrack accept
}
@ -17,7 +17,7 @@ table inet filter {
oif lo notrack accept
udp sport 53 notrack accept
tcp sport {22, 53} notrack accept
tcp sport {22, 53, 80, 443, 853} notrack accept
meta l4proto {icmp, ipv6-icmp} notrack accept
}