Also allow dns out

Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
This commit is contained in:
Patrick Uiterwijk 2018-01-11 23:02:44 +00:00
parent cc859650e0
commit f94a5f94cd

View file

@ -30,6 +30,12 @@
# Allow connection to the database
-A OUTPUT --dst 10.5.126.71 -p tcp -m tcp --dport 5432 -j ACCEPT
# Allow DNS
-A OUTPUT --dst 10.5.126.21 -p udp -m udp --dport 53 -j ACCEPT
-A OUTPUT --dst 10.5.126.21 -p tcp -m tcp --dport 53 -j ACCEPT
-A OUTPUT --dst 10.5.126.22 -p udp -m udp --dport 53 -j ACCEPT
-A OUTPUT --dst 10.5.126.22 -p tcp -m tcp --dport 53 -j ACCEPT
# otherwise kick everything out
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited