diff options
| author | Jan Tuomi <jan@jantuomi.fi> | 2025-06-23 14:42:09 +0300 |
|---|---|---|
| committer | Jan Tuomi <jan@jantuomi.fi> | 2025-06-23 14:45:50 +0300 |
| commit | fbe2f24e25f510c61556e052f71611277a68e1b2 (patch) | |
| tree | d5a4ff7f17d50c21a7ed5e11c61b7d77178f385b | |
| parent | 41237d7d8bd8de160df93ae583cf6296039283c1 (diff) | |
Add pf rules
| -rw-r--r-- | tasks/network.yml | 18 | ||||
| -rw-r--r-- | templates/etc_pf.conf.j2 | 31 |
2 files changed, 49 insertions, 0 deletions
diff --git a/tasks/network.yml b/tasks/network.yml index 5a59e30..2a4ec23 100644 --- a/tasks/network.yml +++ b/tasks/network.yml @@ -40,3 +40,21 @@ - name: Disable syslogd remote listening shell: sysrc syslogd_flags="-s" && service syslogd restart + +- name: Configure pf + template: + src: etc_pf.conf.j2 + dest: /etc/pf.conf + owner: root + group: wheel + mode: "0644" + backup: yes + +- name: Enable and start pf + service: + name: pf + enabled: true + state: started + +- name: Reload pf rules + shell: pfctl -f /etc/pf.conf diff --git a/templates/etc_pf.conf.j2 b/templates/etc_pf.conf.j2 new file mode 100644 index 0000000..3802fae --- /dev/null +++ b/templates/etc_pf.conf.j2 @@ -0,0 +1,31 @@ +lan_if = "lan0" +wan_if = "wan0" + +# Default policy +set skip on lo +set block-policy return +block in all + +# Allow all outbound traffic +pass out all keep state + +# Allow inbound HTTP/HTTPS on both interfaces +pass in on $wan_if proto tcp from any to ($wan_if) port { 80, 443 } keep state +pass in on $lan_if proto tcp from any to ($lan_if) port { 80, 443 } keep state + +# Allow SSH only on lan0 +pass in on $lan_if proto tcp from any to ($lan_if) port 22 keep state + +# Allow DHCPv4 (client side): from server port 67 to client port 68 +pass in quick on $lan_if proto udp from any port 67 to any port 68 keep state +pass in quick on $wan_if proto udp from any port 67 to any port 68 keep state + +# Allow DHCPv6 (client side): from server port 547 to client port 546 +pass in quick on $lan_if proto udp from any port 547 to any port 546 keep state +pass in quick on $wan_if proto udp from any port 547 to any port 546 keep state + +# Allow all ICMPv6 (required for IPv6 to function correctly) +pass inet6 proto ipv6-icmp from any to any keep state + +# Allow all ICMPv4 +pass inet proto icmp from any to any keep state |
