On Sat, May 12, 2018 3:31 pm, mk2mix via qubes-users wrote:
> @aworkd
> thank you for your answer, always fast (I am sometimes connected with
> caropelin, for memory I had recovered a G505s that I sent back, which did
> not prevent me to order the hardware for coreboot).
> I already have all the appVmM on none (for those without networks).
> I will try to pass the filtration by the firewall (instead of iptables).
> when you say minimal, it is with the minimum of applications? or something
> else ?
I mean a template like
https://www.qubes-os.org/doc/templates/fedora-minimal/.
I saw in your other post a lot of it looked like NTP queries, like you
said. For troubleshooting, you might want to try manually setting three or
four NTP servers in sys-net instead of automatic selection. I think there
is also a way to temporarily disable checking for updates but can't find
it right now. Should cut down on some noise, but reverse the changes when
done.
> it is not possible to block by "hosts" or iptables?
> I saw that some used scripts, but I did not manage to have a (complex)
> result.
You should be able to customize iptables/nft further in sys-firewall;
check out
https://www.qubes-os.org/doc/firewall/. I haven't done much with
that, though.