Firewall: forbid the _apt user to talk to DNS ports.

I've seen it trying to talk to UDP port 5353 (and being blocked), which makes
the logs noisy. APT works very well without DNS access since we only have Onion
APT sources, so let's silence the logs.
......@@ -67,6 +67,7 @@ domain ip {
# White-list access to system DNS and Tor's DNSPort
daddr proto udp dport (53 5353) {
mod owner uid-owner $amnesia_uid ACCEPT;
mod owner uid-owner _apt DROP;
# White-list access to the accessibility daemon
