mirror of
https://github.com/GrapheneOS/infrastructure.git
synced 2025-12-16 00:43:53 -05:00
move dnsdist control socket to port 55
This avoids unnecessary overlap with our ephemeral port range.
This commit is contained in:
parent
76b5b554ca
commit
a948b7c244
2 changed files with 2 additions and 2 deletions
|
|
@ -133,7 +133,7 @@ table inet filter {
|
||||||
|
|
||||||
skuid powerdns tcp sport 81 tcp dport >= 1024 notrack accept
|
skuid powerdns tcp sport 81 tcp dport >= 1024 notrack accept
|
||||||
|
|
||||||
skuid dnsdist tcp sport 5199 tcp dport >= 1024 notrack accept
|
skuid dnsdist tcp sport 55 tcp dport >= 1024 notrack accept
|
||||||
|
|
||||||
skuid zerotier-one tcp sport 9993 tcp dport >= 1024 notrack accept
|
skuid zerotier-one tcp sport 9993 tcp dport >= 1024 notrack accept
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -131,7 +131,7 @@ table inet filter {
|
||||||
|
|
||||||
skuid powerdns tcp sport 81 tcp dport >= 1024 notrack accept
|
skuid powerdns tcp sport 81 tcp dport >= 1024 notrack accept
|
||||||
|
|
||||||
skuid dnsdist tcp sport 5199 tcp dport >= 1024 notrack accept
|
skuid dnsdist tcp sport 55 tcp dport >= 1024 notrack accept
|
||||||
|
|
||||||
skuid != root counter goto graceful-reject
|
skuid != root counter goto graceful-reject
|
||||||
notrack accept
|
notrack accept
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue