Fix firewall
This commit is contained in:
@@ -1,4 +1,4 @@
|
|||||||
capabilities = ["NET_RAW", "NET_ADMIN"]
|
capabilities = ["NET_RAW", "NET_ADMIN", "NET_BIND_SERVICE"]
|
||||||
|
|
||||||
[service]
|
[service]
|
||||||
name = "adguard"
|
name = "adguard"
|
||||||
|
|||||||
@@ -68,15 +68,19 @@ table inet firewall {
|
|||||||
|
|
||||||
ip saddr $lan_net tcp dport 22 accept # Allow SSH from LAN network
|
ip saddr $lan_net tcp dport 22 accept # Allow SSH from LAN network
|
||||||
|
|
||||||
# AdGuard admin access (8888) only from LAN and VPN
|
# AdGuard admin access (8888) accept for LAN and VPN
|
||||||
ip saddr { $lan_net, $vpn_net } tcp dport 8888 accept
|
ip saddr { $lan_net, $vpn_net } tcp dport 8888 accept
|
||||||
ip6 saddr $lan_net6 tcp dport 8888 accept
|
ip6 saddr $lan_net6 tcp dport 8888 accept
|
||||||
|
|
||||||
# Adguard DNS, DHCP, DoT, DoQ ports only from LAN and VPN
|
# Adguard DHCP, DoT, DoQ ports
|
||||||
ip saddr { $lan_net, $vpn_net} udp dport { 53, 67, 68, 784 } accept
|
udp dport { 67, 68, 784 } accept
|
||||||
ip saddr { $lan_net, $vpn_net} tcp dport { 53, 853 } accept
|
tcp dport { 853 } accept
|
||||||
ip6 saddr $lan_net6 udp dport { 53, 67, 68, 784 } accept
|
|
||||||
ip6 saddr $lan_net6 tcp dport { 53, 853 } accept
|
# Allow DNS from LAN and VPN
|
||||||
|
ip saddr { $lan_net, $vpn_net } udp dport 53 accept
|
||||||
|
ip6 saddr $lan_net6 udp dport 53 accept
|
||||||
|
ip saddr { $lan_net, $vpn_net } tcp dport 53 accept
|
||||||
|
ip6 saddr $lan_net6 tcp dport 53 accept
|
||||||
|
|
||||||
# Rules for WAN interface only
|
# Rules for WAN interface only
|
||||||
iifname $wan udp dport 51820 accept # Allow Wireguard incoming from WAN
|
iifname $wan udp dport 51820 accept # Allow Wireguard incoming from WAN
|
||||||
|
|||||||
Reference in New Issue
Block a user