aboutsummaryrefslogtreecommitdiffstats
path: root/templates/ingress/etc_pf.conf.j2
diff options
context:
space:
mode:
authorJan Tuomi <jan@jantuomi.fi>2025-12-29 23:16:22 +0200
committerJan Tuomi <jan@jantuomi.fi>2025-12-29 23:16:22 +0200
commit533bc95c751337d5f2952252b0378848cf078357 (patch)
tree2bf4ccadc31baf02d2a586fe7357af99787265dc /templates/ingress/etc_pf.conf.j2
parent39feba1c79c1a0c2743932af35e157ba29d089d1 (diff)
Add crawler tarpit
Diffstat (limited to 'templates/ingress/etc_pf.conf.j2')
-rw-r--r--templates/ingress/etc_pf.conf.j25
1 files changed, 5 insertions, 0 deletions
diff --git a/templates/ingress/etc_pf.conf.j2 b/templates/ingress/etc_pf.conf.j2
index feb35d5..c0528e1 100644
--- a/templates/ingress/etc_pf.conf.j2
+++ b/templates/ingress/etc_pf.conf.j2
@@ -5,6 +5,8 @@ lan = "epl{{ jail.num }}b"
wan = "epw{{ jail.num }}b"
lan_net = "{{ lan_ipv4_network }}"
+table <blocked> persist
+
# Keep PF out of loopback, drop by default if you add blocks later
set skip on lo0
set block-policy drop
@@ -12,6 +14,9 @@ set block-policy drop
# NAT: translate LAN traffic to the WAN interface address
nat on $wan from $lan_net to any -> ($wan)
+# Block traffic from IPs in the blocked table
+block in quick from <blocked> to any
+
# Allow all outbound traffic from the jail and LAN via both interfaces
# NAT will be applied automatically when source is in $lan_net and going out $wan
pass out on $wan all keep state