diff --git a/zones/dmz.nft b/zones/dmz.nft index 1d0bd5e..80a8d33 100644 --- a/zones/dmz.nft +++ b/zones/dmz.nft @@ -129,7 +129,7 @@ table inet firewall { ip daddr @minecraft tcp dport { 22, 25565 } accept ip daddr @minecraft udp dport { 22, 25565 } accept - ip daddr @latoilescoute udp dport { 22, 161 } accept + ip daddr @latoilescoute udp dport { 22, 161, 16384-32768 } accept ip daddr @latoilescoute tcp dport { 22 } accept ip saddr @ldap_clients ip daddr @ldap tcp dport { 389, 636 } accept ip saddr @ldap_clients ip daddr @ldap udp dport { 636 } accept