mirror of
https://github.com/GrapheneOS/infrastructure.git
synced 2025-07-24 15:25:23 -04:00
move dnsdist control socket to port 55
This avoids unnecessary overlap with our ephemeral port range.
This commit is contained in:
parent
3b2f6d546c
commit
ac0dc27596
2 changed files with 2 additions and 2 deletions
|
@ -133,7 +133,7 @@ table inet filter {
|
||||||
|
|
||||||
skuid powerdns tcp sport 81 tcp dport >= 1024 notrack accept
|
skuid powerdns tcp sport 81 tcp dport >= 1024 notrack accept
|
||||||
|
|
||||||
skuid dnsdist tcp sport 5199 tcp dport >= 1024 notrack accept
|
skuid dnsdist tcp sport 55 tcp dport >= 1024 notrack accept
|
||||||
|
|
||||||
skuid zerotier-one tcp sport 9993 tcp dport >= 1024 notrack accept
|
skuid zerotier-one tcp sport 9993 tcp dport >= 1024 notrack accept
|
||||||
|
|
||||||
|
|
|
@ -131,7 +131,7 @@ table inet filter {
|
||||||
|
|
||||||
skuid powerdns tcp sport 81 tcp dport >= 1024 notrack accept
|
skuid powerdns tcp sport 81 tcp dport >= 1024 notrack accept
|
||||||
|
|
||||||
skuid dnsdist tcp sport 5199 tcp dport >= 1024 notrack accept
|
skuid dnsdist tcp sport 55 tcp dport >= 1024 notrack accept
|
||||||
|
|
||||||
skuid != root counter goto graceful-reject
|
skuid != root counter goto graceful-reject
|
||||||
notrack accept
|
notrack accept
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue