netcup: back to UDP upstream for unbound (reverts 0e9be99)
netcup's firewall policy now allows inbound UDP from source ports 53 and 123, so replies to the box's DNS and NTP queries arrive. The same block had kept the shared box's clock from ever syncing (31 s behind).
1 files changed,  +0, -7
M modules/netcup.nix
+0, -7
 1@@ -44,11 +44,4 @@ in
 2     "2a03:4000:0:1::e1e6"
 3     "2a03:4000:8000::fce6"
 4   ];
 5-
 6-  # netcup's firewall policy allows only listed inbound ports, so replies to
 7-  # outbound UDP DNS (to a random high port) never arrive; only netcup's own
 8-  # resolvers get through. TCP replies do. A recursive unbound (sovrn's
 9-  # Stalwart resolver, nix/modules/stalwart.nix) therefore queries upstream
10-  # over TCP only. Inert where unbound isn't enabled.
11-  services.unbound.settings.server.tcp-upstream = true;
12 }