From f6a51c63e49d2ecde468f6d5b6dceb316efb36f2 Mon Sep 17 00:00:00 2001 From: Matthias Schiffer Date: Sat, 5 Jul 2014 15:56:22 +0200 Subject: [PATCH] gluon-firewall: reject DNS queries from br-client (they should be accepted on local-node only) --- .../{011-wan-firewall => 011-firewall-rules} | 11 +++++++++++ 1 file changed, 11 insertions(+) rename package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/{011-wan-firewall => 011-firewall-rules} (79%) diff --git a/package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/011-wan-firewall b/package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/011-firewall-rules similarity index 79% rename from package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/011-wan-firewall rename to package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/011-firewall-rules index 792e06a2..1a422ca3 100755 --- a/package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/011-wan-firewall +++ b/package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/011-firewall-rules @@ -26,5 +26,16 @@ c:section('firewall', 'rule', 'wan_ssh', } ) + +c:section('firewall', 'rule', 'client_dns', + { + name = 'client_dns', + src = 'client', + dest_port = '53', + target = 'REJECT', + } +) + + c:save('firewall') c:commit('firewall')