This avoids lots of annoying messing about with NFS. Maybe when
wheezy is released I'll move these back.
ssh \
ident \
smtp submission \
+ imaps \
http https \
- imaps
+ git
## Provide DNS resolution to local untrusted hosts.
for p in tcp udp; do
ident \
ftp ftp_data \
rsync \
- http https squid \
- git
+ http https squid
## Provide DNS resolution to local untrusted hosts.
for p in tcp udp; do
ssh \
ident \
smtp submission \
+ imaps \
http https \
- imaps
+ git
## Other interesting things.
dnsresolver inbound
ident \
ftp ftp_data \
rsync \
- http https squid \
- git
+ http https squid
## Other interesting things.
dnsresolver inbound