diff options
| author | Jan Tuomi <jan@jantuomi.fi> | 2025-11-30 11:50:29 +0200 |
|---|---|---|
| committer | Jan Tuomi <jan@jantuomi.fi> | 2025-11-30 11:50:29 +0200 |
| commit | 5c1f0e17b8b0e9ebba6078854c1224e7f5d93ac2 (patch) | |
| tree | 00412c3090e0fb48cccc074d02f0afffee9bbcc5 /templates | |
| parent | 28379e016d4ab80a0d0529d6ca08083c75a0be4d (diff) | |
pf changes
Diffstat (limited to 'templates')
| -rw-r--r-- | templates/etc_jail.conf.d_[jailname].conf.j2 | 4 | ||||
| -rw-r--r-- | templates/etc_periodic.conf.j2 | 2 | ||||
| -rw-r--r-- | templates/etc_pf.conf.j2 | 27 | ||||
| -rw-r--r-- | templates/ingress/etc_pf.conf.j2 | 2 |
4 files changed, 7 insertions, 28 deletions
diff --git a/templates/etc_jail.conf.d_[jailname].conf.j2 b/templates/etc_jail.conf.d_[jailname].conf.j2 index a12226d..3e11e4f 100644 --- a/templates/etc_jail.conf.d_[jailname].conf.j2 +++ b/templates/etc_jail.conf.d_[jailname].conf.j2 @@ -22,12 +22,14 @@ exec.poststart += "jexec ${name} ifconfig epl{{ jail.num }}b up"; exec.poststart += "ifconfig epl{{ jail.num }}a up"; exec.poststart += "jexec ${name} ifconfig epl{{ jail.num }}b 192.168.2.{{ jail.num }}/16"; + exec.poststart += "jexec ${name} route delete default || echo 'No default route to delete'"; + {% if jail.name != "ingress" %} {% for ing in jails -%} {% if ing.name == "ingress" -%} exec.poststart += "jexec ${name} route add default 192.168.2.{{ ing.num }} || echo 'Failed to add default route'"; {% endif %} {% endfor %} - {% if jail.name == "ingress" -%} + {% else %} exec.poststart += "ifconfig epw{{ jail.num }}b vnet ${name}"; exec.poststart += "jexec ${name} ifconfig epw{{ jail.num }}b up"; exec.poststart += "ifconfig epw{{ jail.num }}a up"; diff --git a/templates/etc_periodic.conf.j2 b/templates/etc_periodic.conf.j2 index 0e70471..176b55d 100644 --- a/templates/etc_periodic.conf.j2 +++ b/templates/etc_periodic.conf.j2 @@ -1,2 +1,4 @@ daily_status_smart_enable="YES" +daily_status_security_inline="YES" +daily_status_zfs_enable="YES" weekly_certbot_enable="YES" diff --git a/templates/etc_pf.conf.j2 b/templates/etc_pf.conf.j2 deleted file mode 100644 index 87ae43a..0000000 --- a/templates/etc_pf.conf.j2 +++ /dev/null @@ -1,27 +0,0 @@ -lan_if = "lan0" -wan_if = "brwan0" - -# Default policy -set skip on lo -# Allow all traffic on $wan_if. Proper firewall rules are implemented in the ingress jail. -set skip on $wan_if -set block-policy return -scrub in - -# Default block all -block in all - -# Allow all outbound traffic -pass out all keep state - -# Allow inbound HTTP/HTTPS on lan0 -pass in on $lan_if proto tcp from any to ($lan_if) port { 80, 443 } keep state - -# Allow SSH only on lan0 -pass in on $lan_if proto tcp from any to ($lan_if) port 22 keep state - -# Allow all ICMPv6 (required for IPv6 to function correctly) -pass inet6 proto ipv6-icmp from any to any keep state - -# Allow all ICMPv4 -pass inet proto icmp from any to any keep state diff --git a/templates/ingress/etc_pf.conf.j2 b/templates/ingress/etc_pf.conf.j2 index 3cdad6e..feb35d5 100644 --- a/templates/ingress/etc_pf.conf.j2 +++ b/templates/ingress/etc_pf.conf.j2 @@ -16,5 +16,7 @@ nat on $wan from $lan_net to any -> ($wan) # NAT will be applied automatically when source is in $lan_net and going out $wan pass out on $wan all keep state pass out on $lan all keep state + +pass in on $wan inet proto {tcp, udp} from any to any port {80, 443} keep state {% endif %} {% endfor %} |
