summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKenny Ballou <kballou@devnulllabs.io>2021-02-24 18:33:19 -0700
committerKenny Ballou <kballou@devnulllabs.io>2021-02-24 18:33:19 -0700
commita58ee47301a46fe7d319467b73491dcfcae885d1 (patch)
tree80c2f19dfd14e7879f3ee30e03a063150b9accd4
parentb54a13223c10f583aa2f17c9db7ee26588dad7d0 (diff)
downloadcfg.nix-a58ee47301a46fe7d319467b73491dcfcae885d1.tar.gz
cfg.nix-a58ee47301a46fe7d319467b73491dcfcae885d1.tar.xz
update firewall rules
Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
-rw-r--r--daeva/nftables-rules.nft7
-rw-r--r--eligos/nftables-rules.nft4
2 files changed, 10 insertions, 1 deletions
diff --git a/daeva/nftables-rules.nft b/daeva/nftables-rules.nft
index 8d78807..792b684 100644
--- a/daeva/nftables-rules.nft
+++ b/daeva/nftables-rules.nft
@@ -11,7 +11,7 @@ table inet filter {
udp dport domain ip saddr 172.16.0.0/12 counter accept
tcp dport 3000 ip saddr 127.0.0.1/8 counter accept
tcp dport 8000 ip saddr 127.0.0.1/8 counter accept
- tcp dport http-alt ip saddr { 127.0.0.1/8, 10.100.0.0/8 } counter accept
+ tcp dport http-alt ip saddr { 127.0.0.1/8, 10.0.0.0/8 } counter accept
counter
}
@@ -53,6 +53,11 @@ table inet filter {
ip daddr 127.0.0.0/8 counter accept
tcp dport 5222 counter accept
tcp dport 6697 counter accept
+ tcp dport 2049 ip daddr 10.0.0.0/8 counter accept
+ udp dport 2049 ip daddr 10.0.0.0/8 counter accept
+ tcp dport 20048 ip daddr 10.0.0.0/8 counter accept
+ udp dport 20048 ip daddr 10.0.0.0/8 counter accept
+ tcp dport 13052 counter accept
counter
}
}
diff --git a/eligos/nftables-rules.nft b/eligos/nftables-rules.nft
index adc8507..c26071e 100644
--- a/eligos/nftables-rules.nft
+++ b/eligos/nftables-rules.nft
@@ -13,6 +13,10 @@ table inet filter {
tcp dport 8000 ip saddr 127.0.0.1/8 counter accept
tcp dport 8384 ip saddr 127.0.0.1/8 counter accept
tcp dport 8080 ip saddr { 127.0.0.1/8, 10.1.0.0/8 } counter accept
+ tcp dport 20048 ip saddr 10.0.0.0/8 counter accept
+ udp dport 20048 ip saddr 10.0.0.0/8 counter accept
+ udp dport 2049 ip saddr 10.0.0.0/8 counter accept
+ tcp dport 2049 ip saddr 10.0.0.0/8 counter accept
tcp dport ssh counter accept
counter
}