aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--tasks/network.yml18
-rw-r--r--templates/etc_pf.conf.j231
2 files changed, 49 insertions, 0 deletions
diff --git a/tasks/network.yml b/tasks/network.yml
index 5a59e30..2a4ec23 100644
--- a/tasks/network.yml
+++ b/tasks/network.yml
@@ -40,3 +40,21 @@
- name: Disable syslogd remote listening
shell: sysrc syslogd_flags="-s" && service syslogd restart
+
+- name: Configure pf
+ template:
+ src: etc_pf.conf.j2
+ dest: /etc/pf.conf
+ owner: root
+ group: wheel
+ mode: "0644"
+ backup: yes
+
+- name: Enable and start pf
+ service:
+ name: pf
+ enabled: true
+ state: started
+
+- name: Reload pf rules
+ shell: pfctl -f /etc/pf.conf
diff --git a/templates/etc_pf.conf.j2 b/templates/etc_pf.conf.j2
new file mode 100644
index 0000000..3802fae
--- /dev/null
+++ b/templates/etc_pf.conf.j2
@@ -0,0 +1,31 @@
+lan_if = "lan0"
+wan_if = "wan0"
+
+# Default policy
+set skip on lo
+set block-policy return
+block in all
+
+# Allow all outbound traffic
+pass out all keep state
+
+# Allow inbound HTTP/HTTPS on both interfaces
+pass in on $wan_if proto tcp from any to ($wan_if) port { 80, 443 } keep state
+pass in on $lan_if proto tcp from any to ($lan_if) port { 80, 443 } keep state
+
+# Allow SSH only on lan0
+pass in on $lan_if proto tcp from any to ($lan_if) port 22 keep state
+
+# Allow DHCPv4 (client side): from server port 67 to client port 68
+pass in quick on $lan_if proto udp from any port 67 to any port 68 keep state
+pass in quick on $wan_if proto udp from any port 67 to any port 68 keep state
+
+# Allow DHCPv6 (client side): from server port 547 to client port 546
+pass in quick on $lan_if proto udp from any port 547 to any port 546 keep state
+pass in quick on $wan_if proto udp from any port 547 to any port 546 keep state
+
+# Allow all ICMPv6 (required for IPv6 to function correctly)
+pass inet6 proto ipv6-icmp from any to any keep state
+
+# Allow all ICMPv4
+pass inet proto icmp from any to any keep state