diff options
author | Emil Renner Berthing <esmil@labitat.dk> | 2021-01-19 13:14:10 +0100 |
---|---|---|
committer | Emil Renner Berthing <esmil@labitat.dk> | 2021-01-19 13:14:10 +0100 |
commit | 48d0db45d2ac05e42f6219667008bf73ea41d19d (patch) | |
tree | 02437d4d7b6267dbe157688abeaf2c60cce9f49c /roles/space_server/files/nftables.conf | |
parent | c28fe3ed473a195b5d9067c8c65676b409c19ce0 (diff) | |
download | labitat-ansible-48d0db45d2ac05e42f6219667008bf73ea41d19d.tar.gz labitat-ansible-48d0db45d2ac05e42f6219667008bf73ea41d19d.tar.xz labitat-ansible-48d0db45d2ac05e42f6219667008bf73ea41d19d.zip |
space_server: chrony: run chrony ntp server
Diffstat (limited to 'roles/space_server/files/nftables.conf')
-rw-r--r-- | roles/space_server/files/nftables.conf | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/roles/space_server/files/nftables.conf b/roles/space_server/files/nftables.conf index a0c17c1..066c03e 100644 --- a/roles/space_server/files/nftables.conf +++ b/roles/space_server/files/nftables.conf @@ -96,6 +96,9 @@ table ip filter { tcp dport 53 ip saddr { $int_net4, $ext_net4 } accept udp dport 53 ip saddr { $int_net4, $ext_net4 } accept + # ntp + udp dport 123 ip saddr { $int_net4, $ext_net4 } accept + # avahi ip daddr 224.0.0.251 udp dport 5353 iif $avahi_ifs accept ip protocol igmp iif $avahi_ifs accept @@ -173,6 +176,9 @@ table ip6 filter { tcp dport 53 ip6 saddr $ext_net6 accept udp dport 53 ip6 saddr $ext_net6 accept + # ntp + udp dport 123 ip6 saddr $ext_net6 accept + # avahi ip6 daddr ff02::fb udp dport 5353 iif $avahi_ifs accept |