[guide] how-to setup a sys-dns qube

Fedora replaces iptables with iptables-nft, which converts rules to nftables on the fly:

lrwxrwxrwx. 1 root root 26 Nov 17 15:02 /usr/sbin/iptables -> /etc/alternatives/iptables
lrwxrwxrwx. 1 root root 22 Nov 17 15:02 /etc/alternatives/iptables -> /usr/sbin/iptables-nft

I’m not sure how you got it to work unless you have some iptables leftovers. The PR-QBS chain is not present in Qubes 4.2 since it has been replaced by dnat-dns. Also, FORWARD and INPUT are not accepted by nftables because it’s case sensitive.

Related issue: Some R4.1 firewall scripts do not work after upgrading to R4.2 · Issue #8487 · QubesOS/qubes-issues · GitHub