aboutsummaryrefslogtreecommitdiffstats
path: root/templates/ingress/etc_pf.conf.j2
diff options
context:
space:
mode:
authorJan Tuomi <jan@jantuomi.fi>2026-05-13 00:13:57 +0300
committerJan Tuomi <jan@jantuomi.fi>2026-05-16 18:42:27 +0300
commitb5860daf11ac353049cb1654b9414a129e5cfb96 (patch)
tree87ed89711e4f0e85ace0a97fa123199152c67302 /templates/ingress/etc_pf.conf.j2
parent4715a28fdcd87440400d17154bfa361d99db29cc (diff)
Rework
Diffstat (limited to 'templates/ingress/etc_pf.conf.j2')
-rw-r--r--templates/ingress/etc_pf.conf.j227
1 files changed, 0 insertions, 27 deletions
diff --git a/templates/ingress/etc_pf.conf.j2 b/templates/ingress/etc_pf.conf.j2
deleted file mode 100644
index c0528e1..0000000
--- a/templates/ingress/etc_pf.conf.j2
+++ /dev/null
@@ -1,27 +0,0 @@
-{% for jail in jails -%}
-{% if jail.name == 'ingress' -%}
-# Interfaces & nets
-lan = "epl{{ jail.num }}b"
-wan = "epw{{ jail.num }}b"
-lan_net = "{{ lan_ipv4_network }}"
-
-table <blocked> persist
-
-# Keep PF out of loopback, drop by default if you add blocks later
-set skip on lo0
-set block-policy drop
-
-# NAT: translate LAN traffic to the WAN interface address
-nat on $wan from $lan_net to any -> ($wan)
-
-# Block traffic from IPs in the blocked table
-block in quick from <blocked> to any
-
-# Allow all outbound traffic from the jail and LAN via both interfaces
-# NAT will be applied automatically when source is in $lan_net and going out $wan
-pass out on $wan all keep state
-pass out on $lan all keep state
-
-pass in on $wan inet proto {tcp, udp} from any to any port {80, 443} keep state
-{% endif %}
-{% endfor %}