mirror of
https://github.com/evilsocket/opensnitch.git
synced 2026-06-08 20:27:34 +00:00
Restrict permissions to 127.0.0.1 and ::1 instead of the whole loopback range. This way, we allow localhost connections from common processes (dirmngr, kdeinit5, xbrlapi, etc.), while giving users control to allow or deny DNS queries to the local DNS stub resolver (which for example usually listens on 127.0.0.53). More info: #1416.
19 lines
503 B
JSON
19 lines
503 B
JSON
{
|
|
"created": "2025-04-09T23:21:35-06:00",
|
|
"updated": "2025-04-09T23:21:35-06:00",
|
|
"name": "000-allow-localhost",
|
|
"description": "Allow connections to localhost. More information:\n\nhttps://github.com/evilsocket/opensnitch/wiki/Rules#localhost-connections",
|
|
"action": "allow",
|
|
"duration": "always",
|
|
"operator": {
|
|
"operand": "dest.ip",
|
|
"data": "127.0.0.1",
|
|
"type": "simple",
|
|
"list": [],
|
|
"sensitive": false
|
|
},
|
|
"enabled": true,
|
|
"precedence": true,
|
|
"nolog": true
|
|
}
|