Skip to content

Commit 4125e60

Browse files
author
Federico Ceratto
committed
Add probe services -> amsmetadb firewall rules
1 parent ec896cc commit 4125e60

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

ansible/templates/iptables.filter.part/amsmetadb.ooni.nu

+5
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,11 @@
44
-A INPUT -s {{ lookup('dig', 'ams-api.ooni.nu/A') }}/32 -p tcp -m tcp --dport 5432 -j ACCEPT
55
-A INPUT -s {{ lookup('dig', 'fastpath.ooni.nu/A') }}/32 -p tcp -m tcp --dport 5432 -j ACCEPT
66
-A INPUT -s {{ lookup('dig', 'ams-jupyter.ooni.nu/A') }}/32 -p tcp -m tcp --dport 5432 -j ACCEPT
7+
# Incoming Prio traffic from probe services
8+
-A INPUT -s {{ lookup('dig', 'mia-ps2.ooni.nu') }}/32 -p tcp -m tcp --dport 5432 -j ACCEPT
9+
-A INPUT -s {{ lookup('dig', 'hkg-ps.ooni.nu') }}/32 -p tcp -m tcp --dport 5432 -j ACCEPT
10+
-A INPUT -s {{ lookup('dig', 'ams-ps.ooni.nu') }}/32 -p tcp -m tcp --dport 5432 -j ACCEPT
11+
-A INPUT -s {{ lookup('dig', 'ams-ps2.ooni.nu') }}/32 -p tcp -m tcp --dport 5432 -j ACCEPT
712

813
# allow openvpn connections
914
-A INPUT -s {{ lookup('dig', 'hkgmetadb.infra.ooni.io/A') }}/32 -p udp --dport 1194 -j ACCEPT

0 commit comments

Comments
 (0)