From c02245fb5dd88474a978cbf637224ca17b667c6f Mon Sep 17 00:00:00 2001 From: Kenny Ballou Date: Wed, 30 Oct 2019 22:09:24 -0600 Subject: firewall: restrict postgresql connections Restrict postgresql connections to local and internal networks only. Signed-off-by: Kenny Ballou --- services/nftables-rules.nft | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'services') diff --git a/services/nftables-rules.nft b/services/nftables-rules.nft index 2c58e3d..98b4be6 100644 --- a/services/nftables-rules.nft +++ b/services/nftables-rules.nft @@ -53,7 +53,7 @@ table inet filter { tcp dport http-alt counter accept tcp dport 3000 ip daddr 127.0.0.1/8 counter accept udp dport openvpn counter accept - tcp dport postgresql ip daddr counter accept + tcp dport postgresql ip daddr { 127.0.0.1/8, 10.0.0.0/8 } counter accept counter } } -- cgit v1.2.1