diff options
| author | Xiao Pan <xyz@flylightning.xyz> | 2024-12-29 10:12:50 +0000 | 
|---|---|---|
| committer | Xiao Pan <xyz@flylightning.xyz> | 2024-12-29 10:17:35 +0000 | 
| commit | a03e816d9d49c7f23be39f3cda19e02b37237832 (patch) | |
| tree | b3907122b4dcd4dfc78e4028ae3d763afd000b65 /etc/opendmarc | |
| parent | c9375e787f1fbdafb4c3fd280e6e564e6ef57b09 (diff) | |
Better ns0 network namespace configs
Enable nft. Use different nft config for ns0. Host open emails port. ns0
open wireguard and qbt ports. ns0 configure wireguard. host not
configure wiregurad, so also no need ip forwarding sysctl kernel
parameters. ns0 use /etc/netns/ns0/nftables.conf that will bind mount to
ns0.
Host and ns0 both run dnsmasq for dns cache. ns0 dnsmasq I disable dbus
because it will conficts with host dnsmasq dbus. Dnsmasq use dbus for
config cahnge?
I disable systemd-resolved and switch to dnsmasq because
systemd-resolved use dbus for dns query? which is maybe easy for dns
leak, e.g., when systemd-resolved is only running on host, ns0 with
different /etc/resolv.conf still get dns from host open public ip when
run resolvectl query, although drill does not leak.
sye add enabled systemd units
Diffstat (limited to 'etc/opendmarc')
0 files changed, 0 insertions, 0 deletions
