]> git.donarmstrong.com Git - dsa-puppet.git/commitdiff
Attempt not to track DNS traffic
authorPeter Palfrader <peter@palfrader.org>
Sun, 1 Dec 2013 09:49:17 +0000 (10:49 +0100)
committerPeter Palfrader <peter@palfrader.org>
Sun, 1 Dec 2013 09:49:17 +0000 (10:49 +0100)
modules/ferm/manifests/per-host.pp

index 8ba8e6a2ccace5c2a7b023292f65e83b6633582d..2401338063a1b6c26b47f87d3f37d556df8094e0 100644 (file)
@@ -169,6 +169,37 @@ class ferm::per-host {
                        @ferm::rule { 'dsa-conntrackd':
                                rule            => 'interface vlan2 daddr 225.0.0.50 jump ACCEPT',
                        }
+                       @ferm::rule { 'dsa-bind-notrack-in':
+                               domain      => 'ip',
+                               description => 'NOTRACK for nameserver traffic',
+                               table       => 'raw',
+                               chain       => 'PREROUTING',
+                               rule        => 'proto (tcp udp) daddr 5.153.231.24 dport 53 jump NOTRACK'
+                       }
+
+                       @ferm::rule { 'dsa-bind-notrack-out':
+                               domain      => 'ip',
+                               description => 'NOTRACK for nameserver traffic',
+                               table       => 'raw',
+                               chain       => 'OUTPUT',
+                               rule        => 'proto (tcp udp) saddr 5.153.231.24 sport 53 jump NOTRACK'
+                       }
+
+                       @ferm::rule { 'dsa-bind-notrack-in6':
+                               domain      => 'ip6',
+                               description => 'NOTRACK for nameserver traffic',
+                               table       => 'raw',
+                               chain       => 'PREROUTING',
+                               rule        => 'proto (tcp udp) daddr 2001:41c8:1000:21::21:24 dport 53 jump NOTRACK'
+                       }
+
+                       @ferm::rule { 'dsa-bind-notrack-out6':
+                               domain      => 'ip6',
+                               description => 'NOTRACK for nameserver traffic',
+                               table       => 'raw',
+                               chain       => 'OUTPUT',
+                               rule        => 'proto (tcp udp) saddr 2001:41c8:1000:21::21:24 sport 53 jump NOTRACK'
+                       }
                }
                default: {}
        }