From f6a51c63e49d2ecde468f6d5b6dceb316efb36f2 Mon Sep 17 00:00:00 2001
From: Matthias Schiffer <mschiffer@universe-factory.net>
Date: Sat, 5 Jul 2014 15:56:22 +0200
Subject: [PATCH] gluon-firewall: reject DNS queries from br-client (they
 should be accepted on local-node only)

---
 .../{011-wan-firewall => 011-firewall-rules}          | 11 +++++++++++
 1 file changed, 11 insertions(+)
 rename package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/{011-wan-firewall => 011-firewall-rules} (79%)

diff --git a/package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/011-wan-firewall b/package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/011-firewall-rules
similarity index 79%
rename from package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/011-wan-firewall
rename to package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/011-firewall-rules
index 792e06a2c..1a422ca37 100755
--- a/package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/011-wan-firewall
+++ b/package/gluon-firewall/files/lib/gluon/upgrade/firewall/invariant/011-firewall-rules
@@ -26,5 +26,16 @@ c:section('firewall', 'rule', 'wan_ssh',
 	  }
 )
 
+
+c:section('firewall', 'rule', 'client_dns',
+	  {
+		  name = 'client_dns',
+		  src = 'client',
+		  dest_port = '53',
+		  target = 'REJECT',
+	  }
+)
+
+
 c:save('firewall')
 c:commit('firewall')
-- 
GitLab