refactor(security): reworked firewall configuration and added support for DNS, HTTP and ICMP rules; added autoconf for resolv.conf to match FW rules

This commit is contained in:
NaeiKinDus 2024-01-06 00:00:00 +00:00
parent 3a7440f570
commit da45c7c409
Signed by: WoodSmellParticle
GPG key ID: 8E52ADFF7CA8AE56
22 changed files with 169 additions and 48 deletions

View file

@ -11,23 +11,20 @@ security:
policy:
prerouting: accept
input: accept
postrouting: accept
output: accept
additional_rules: ""
postrouting: accept
mangle:
drop_privatenets: true
policy:
prerouting: accept
postrouting: accept
output: accept
forward: drop
additional_rules: ""
postrouting: accept
filter:
policy:
input: drop
output: drop
forward: drop
additional_rules: ""
custom_security: {}
recursive_combine: true