maybe these firewall rules are better