Firewalling from in or outside of qubes?

Why would i fiddle with firewall rules inside a qube when one could do it from dom0 qvm-firewall as also automate it easily?

Only needed if you want to change advanced stuff like the QubesOS DNS “magic”™, or alter the default forwarding behavior of “provide network” qubes, or accept incoming connections without using the built-in qvm-connect-tcp and so on.

1 Like

hi barto, thanks for responding, “only needed” is a bit vague. I assume net qube dvm is compromised, so an attacker would have full access to the qube (non root available), if i set the firewall rules via qvm-firewall with strict network routes, dns, allow only certain ports for outside communication etc. it would be quiet hard to exit the boundaries from inside the qube or is that assumption wrong?