From f2402b66976e57c457b36141444a3687ce918bfe Mon Sep 17 00:00:00 2001 From: Aaron LI Date: Wed, 14 Mar 2018 17:50:33 +0800 Subject: security/pf: allow IRC bouncer by ZNC --- roles/security/templates/pf.conf.j2 | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'roles/security') diff --git a/roles/security/templates/pf.conf.j2 b/roles/security/templates/pf.conf.j2 index 01d6d12..a2c1381 100644 --- a/roles/security/templates/pf.conf.j2 +++ b/roles/security/templates/pf.conf.j2 @@ -167,12 +167,13 @@ vpn_net = "{{ vpn.network4 }}/24" # * http & https: web service # * git: Git clone etc. # * {{ shadowsocks.port }}: ShadowSocks server +# * {{ znc.port }}: ZNC IRC bouncer (tcp) # * {{ vpn.port }}: OpenVPN service (tcp & udp) # # For restrictive incoming rules in_tcp_services_restricted = "{ {{ ansible_ssh_port }}, smtp, submission, imaps }" # For non-restrictive incoming rules -in_tcp_services = "{ domain, http, https, {{ vpn.port }}, {{ shadowsocks.port }} }" +in_tcp_services = "{ domain, http, https, {{ shadowsocks.port }}, {{ znc.port }}, {{ vpn.port }} }" # For incoming UDP rules in_udp_services = "{ domain, {{ vpn.port }}, {{ ansible_ssh_port+1 }} }" # For outgoing rules -- cgit v1.2.2