Syncthing firewall rules (allow syncthing only)

So - all my Syncthing issues solved.
I have following setup:

  • Qubes OS Notebook with Syncthing in a “Syncthing AppVM”
  • Graphene OS Smartphone with Rethink DNS (Firewall and DNS FIlter)
  • need only direct local connection, no need to synchronize when in other LAN or mobile

Setup:
Smartphone:

  • in Graphene OS adjustment: VPN only connection allowed, VPN always active
  • RethinkDNS: configuration → Apps → Syncthing: bypass DNS & Firewall activated (option Bypass app from all proxies enabled too).
  • Syncthing Fork: assigned a static IP (from my network of the QubesOS Notebook)

Notebook (QubesOS):

  • AppVM with syncthing → firewall-rules: allow only connection to the static ip of Smartphone
  • assigned static ip of the Smarthone device

Solution is based on the information from this thread:

Everything works fine. Full speed (27MB/s) synchronisation speed). Connects immediately. No need for mobile synchronisation.

Hope this will help some people.
I have a standard QubesOS setup: AppVM → sys-firewall → sys-net → network → GrapheneOS smartphone.
Adjustments only done in AppVM - and on smartphone.