Only NAT internal DNS requests.
This commit is contained in:
parent
310fea89ae
commit
edfdb203a0
@ -30,9 +30,9 @@ rdr pass on jail_nat inet proto tcp from $jail_nat_v4 to $not_jail_nat_v4 port 6
|
|||||||
# nat pass on $not_ext_if proto {tcp, udp} from $not_jail_nat_v4 to 10.215.1.210 port 65099 -> (jail_nat)
|
# nat pass on $not_ext_if proto {tcp, udp} from $not_jail_nat_v4 to 10.215.1.210 port 65099 -> (jail_nat)
|
||||||
# nat pass on $not_ext_if proto {tcp, udp} from $jail_nat_v4 to 10.215.1.210 port 65099 -> (lagg0)
|
# nat pass on $not_ext_if proto {tcp, udp} from $jail_nat_v4 to 10.215.1.210 port 65099 -> (lagg0)
|
||||||
|
|
||||||
rdr pass inet proto {tcp, udp} from any to ($ext_if) port 53 -> 10.215.1.211 port 53
|
rdr pass proto {tcp, udp} from $not_jail_nat_v4 to ($ext_if) port 53 -> 10.215.1.211 port 53
|
||||||
nat pass on jail_nat proto {tcp, udp} from { 10.215.1.0/24, !10.215.1.1 } to 10.215.1.211 -> (jail_nat)
|
rdr pass proto {tcp, udp} from $jail_nat_v4 to ($ext_if) port 53 tag REDIRINTERNAL -> 10.215.1.211 port 53
|
||||||
|
nat pass proto {tcp, udp} tagged REDIRINTERNAL -> (jail_nat)
|
||||||
|
|
||||||
# filtering
|
# filtering
|
||||||
block log all
|
block log all
|
||||||
|
@ -67,3 +67,6 @@ _carddavs._tcp IN SRV 0 1 443 carddav.fastmail.com
|
|||||||
|
|
||||||
_caldav._tcp IN SRV 0 0 0 .
|
_caldav._tcp IN SRV 0 0 0 .
|
||||||
_caldavs._tcp IN SRV 0 1 443 caldav.fastmail.com
|
_caldavs._tcp IN SRV 0 1 443 caldav.fastmail.com
|
||||||
|
|
||||||
|
home IN A 68.197.252.22
|
||||||
|
opstunnel IN CNAME home.fizz.buzz.
|
||||||
|
Loading…
x
Reference in New Issue
Block a user