replace nginx with dnsdist for DNS-over-TLS

This commit is contained in:
Daniel Micay 2025-05-13 19:37:34 -04:00
parent 27fe524af6
commit e75172d57c
10 changed files with 14 additions and 14 deletions

View file

@ -119,7 +119,7 @@ table inet filter {
type filter hook output priority raw
oif lo goto output-raw-loopback
skuid != { root, systemd-network, unbound, alpm, chrony, http, powerdns, geoipupdate, zerotier-one, bird } counter goto graceful-reject
skuid != { root, systemd-network, unbound, alpm, chrony, http, powerdns, dnsdist, geoipupdate, zerotier-one, bird } counter goto graceful-reject
udp sport 53 notrack accept
meta l4proto { icmp, ipv6-icmp } notrack accept
}
@ -128,8 +128,8 @@ table inet filter {
skuid unbound meta l4proto { tcp, udp } th sport 53 th dport >= 1024 notrack accept
skuid { alpm, chrony, geoipupdate, zerotier-one } meta l4proto { tcp, udp } th sport >= 1024 th dport 53 notrack accept
skuid powerdns meta l4proto tcp th sport 54 th dport >= 1024 notrack accept
skuid http meta l4proto tcp th sport >= 1024 th dport 54 notrack accept
skuid powerdns meta l4proto { tcp, udp } th sport 54 th dport >= 1024 notrack accept
skuid dnsdist meta l4proto { tcp, udp } th sport >= 1024 th dport 54 notrack accept
skuid powerdns meta l4proto tcp th sport 81 th dport >= 1024 notrack accept

View file

@ -117,7 +117,7 @@ table inet filter {
type filter hook output priority raw
oif lo goto output-raw-loopback
skuid != { root, systemd-network, unbound, alpm, chrony, http, powerdns, geoipupdate } counter goto graceful-reject
skuid != { root, systemd-network, unbound, alpm, chrony, http, powerdns, dnsdist, geoipupdate } counter goto graceful-reject
udp sport 53 notrack accept
meta l4proto { icmp, ipv6-icmp } notrack accept
}
@ -126,8 +126,8 @@ table inet filter {
skuid unbound meta l4proto { tcp, udp } th sport 53 th dport >= 1024 notrack accept
skuid { alpm, chrony, geoipupdate } meta l4proto { tcp, udp } th sport >= 1024 th dport 53 notrack accept
skuid powerdns meta l4proto tcp th sport 54 th dport >= 1024 notrack accept
skuid http meta l4proto tcp th sport >= 1024 th dport 54 notrack accept
skuid powerdns meta l4proto { tcp, udp } th sport 54 th dport >= 1024 notrack accept
skuid dnsdist meta l4proto { tcp, udp } th sport >= 1024 th dport 54 notrack accept
skuid powerdns meta l4proto tcp th sport 81 th dport >= 1024 notrack accept

View file

@ -4,6 +4,7 @@ certbot
chrony
cloud-guest-utils
conntrack-tools
dnsdist
fish
geoip
geoipupdate
@ -21,7 +22,6 @@ mtr
neovim
nftables
nginx
nginx-mod-stream
nmap
openssh
pacman-contrib

View file

@ -3,6 +3,7 @@ certbot
chrony
cloud-guest-utils
conntrack-tools
dnsdist
fish
geoip
geoipupdate
@ -20,7 +21,6 @@ mtr
neovim
nftables
nginx
nginx-mod-stream
nmap
openssh
pacman-contrib

View file

@ -3,6 +3,7 @@ bird
chrony
cloud-guest-utils
conntrack-tools
dnsdist
fish
geoip
geoipupdate
@ -20,7 +21,6 @@ mtr
neovim
nftables
nginx
nginx-mod-stream
nmap
openssh
pacman-contrib

View file

@ -2,6 +2,7 @@ base
chrony
cloud-guest-utils
conntrack-tools
dnsdist
fish
geoip
geoipupdate
@ -19,7 +20,6 @@ mtr
neovim
nftables
nginx
nginx-mod-stream
nmap
openssh
pacman-contrib

View file

@ -3,6 +3,7 @@ bird
chrony
cloud-guest-utils
conntrack-tools
dnsdist
fish
geoip
geoipupdate
@ -20,7 +21,6 @@ mtr
neovim
nftables
nginx
nginx-mod-stream
nmap
openssh
pacman-contrib

View file

@ -2,6 +2,7 @@ base
chrony
cloud-guest-utils
conntrack-tools
dnsdist
fish
geoip
geoipupdate
@ -19,7 +20,6 @@ mtr
neovim
nftables
nginx
nginx-mod-stream
nmap
openssh
pacman-contrib

View file

@ -3,6 +3,7 @@ bird
chrony
cloud-guest-utils
conntrack-tools
dnsdist
fish
geoip
geoipupdate
@ -20,7 +21,6 @@ mtr
neovim
nftables
nginx
nginx-mod-stream
nmap
openssh
pacman-contrib

View file

@ -4,6 +4,7 @@ certbot
chrony
cloud-guest-utils
conntrack-tools
dnsdist
fish
geoip
geoipupdate
@ -21,7 +22,6 @@ mtr
neovim
nftables
nginx
nginx-mod-stream
nmap
openssh
pacman-contrib