summaryrefslogtreecommitdiff
path: root/services/nftables-rules.nft
Commit message (Collapse)AuthorAge
* firewall: allow http-alt from internal networkKenny Ballou2019-10-30
| | | | | | | Allow clients from the internal network to access the alternative HTTP port. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* firewall: restrict postgresql connectionsKenny Ballou2019-10-30
| | | | | | Restrict postgresql connections to local and internal networks only. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* firewall: allow postgres connections outKenny Ballou2019-09-26
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* nft: add local app server 3000 portKenny Ballou2019-08-01
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* firewall: add docker masquerade and forward rulesKenny Ballou2019-07-18
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* firewall: update docker input traffic saddrKenny Ballou2019-07-18
| | | | | | | Instead of allowing the entire `172/8` block which includes more than we actually want, appropriately limit to the `172.16/12`. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* firewall: add icmp echo-{request,reply} output rulesKenny Ballou2019-07-10
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* firewall: add openvpn output ruleKenny Ballou2019-07-10
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* firewall: add http-alt portsKenny Ballou2019-07-05
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* firewall: :rose: fix spacingKenny Ballou2019-06-27
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* firewall: remove nat default policiesKenny Ballou2019-06-27
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* firewall: remove unnecessary chainsKenny Ballou2019-06-27
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* firewall: add counter to related forwarded connectionsKenny Ballou2019-06-27
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* services: configure netfilter firewallKenny Ballou2019-06-07
Add an initial configuration for netflter. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>