diff options
| author | Jan Tuomi <jan@jantuomi.fi> | 2025-11-13 18:45:10 +0200 |
|---|---|---|
| committer | Jan Tuomi <jan@jantuomi.fi> | 2025-11-13 18:45:10 +0200 |
| commit | 28379e016d4ab80a0d0529d6ca08083c75a0be4d (patch) | |
| tree | adf5c7edbf5903de6d7023db200bbd74172a41c4 /templates/etc_pf.conf.j2 | |
| parent | 1df3d09ae131bf4709820205b562a04c22bdd85b (diff) | |
WIP
Diffstat (limited to 'templates/etc_pf.conf.j2')
| -rw-r--r-- | templates/etc_pf.conf.j2 | 15 |
1 files changed, 4 insertions, 11 deletions
diff --git a/templates/etc_pf.conf.j2 b/templates/etc_pf.conf.j2 index ceae731..87ae43a 100644 --- a/templates/etc_pf.conf.j2 +++ b/templates/etc_pf.conf.j2 @@ -1,8 +1,10 @@ lan_if = "lan0" -wan_if = "wan0" +wan_if = "brwan0" # Default policy set skip on lo +# Allow all traffic on $wan_if. Proper firewall rules are implemented in the ingress jail. +set skip on $wan_if set block-policy return scrub in @@ -12,21 +14,12 @@ block in all # Allow all outbound traffic pass out all keep state -# Allow inbound HTTP/HTTPS on both interfaces -pass in on $wan_if proto tcp from any to any port { 80, 443 } keep state +# Allow inbound HTTP/HTTPS on lan0 pass in on $lan_if proto tcp from any to ($lan_if) port { 80, 443 } keep state # Allow SSH only on lan0 pass in on $lan_if proto tcp from any to ($lan_if) port 22 keep state -# Allow DHCPv4 (client side): from server port 67 to client port 68 -pass in quick on $lan_if proto udp from any port 67 to any port 68 keep state -pass in quick on $wan_if proto udp from any port 67 to any port 68 keep state - -# Allow DHCPv6 (client side): from server port 547 to client port 546 -pass in quick on $lan_if proto udp from any port 547 to any port 546 keep state -pass in quick on $wan_if proto udp from any port 547 to any port 546 keep state - # Allow all ICMPv6 (required for IPv6 to function correctly) pass inet6 proto ipv6-icmp from any to any keep state |
