qubes_setup_dnat_to_ns script sets up DNAT rules for DNS traffic; it is triggered by dhclient or NetworkManager, and manually (in case there is a static resolv.conf). Put IP-dependent rules in qubes-core, after local ip is known. It could be further improved by introducing custom chains, to enable iptables save. Restrict FORWARD. |
||
|---|---|---|
| .. | ||
| core-appvm.spec | ||
| core-netvm.spec | ||
| dom0-cleanup.spec | ||