diff options
| -rw-r--r-- | tasks/network.yml | 18 | ||||
| -rw-r--r-- | templates/etc_pf.conf.j2 | 31 |
2 files changed, 49 insertions, 0 deletions
diff --git a/tasks/network.yml b/tasks/network.yml index 5a59e30..2a4ec23 100644 --- a/tasks/network.yml +++ b/tasks/network.yml @@ -40,3 +40,21 @@ - name: Disable syslogd remote listening shell: sysrc syslogd_flags="-s" && service syslogd restart + +- name: Configure pf + template: + src: etc_pf.conf.j2 + dest: /etc/pf.conf + owner: root + group: wheel + mode: "0644" + backup: yes + +- name: Enable and start pf + service: + name: pf + enabled: true + state: started + +- name: Reload pf rules + shell: pfctl -f /etc/pf.conf diff --git a/templates/etc_pf.conf.j2 b/templates/etc_pf.conf.j2 new file mode 100644 index 0000000..3802fae --- /dev/null +++ b/templates/etc_pf.conf.j2 @@ -0,0 +1,31 @@ +lan_if = "lan0" +wan_if = "wan0" + +# Default policy +set skip on lo +set block-policy return +block in all + +# Allow all outbound traffic +pass out all keep state + +# Allow inbound HTTP/HTTPS on both interfaces +pass in on $wan_if proto tcp from any to ($wan_if) port { 80, 443 } keep state +pass in on $lan_if proto tcp from any to ($lan_if) port { 80, 443 } keep state + +# Allow SSH only on lan0 +pass in on $lan_if proto tcp from any to ($lan_if) port 22 keep state + +# Allow DHCPv4 (client side): from server port 67 to client port 68 +pass in quick on $lan_if proto udp from any port 67 to any port 68 keep state +pass in quick on $wan_if proto udp from any port 67 to any port 68 keep state + +# Allow DHCPv6 (client side): from server port 547 to client port 546 +pass in quick on $lan_if proto udp from any port 547 to any port 546 keep state +pass in quick on $wan_if proto udp from any port 547 to any port 546 keep state + +# Allow all ICMPv6 (required for IPv6 to function correctly) +pass inet6 proto ipv6-icmp from any to any keep state + +# Allow all ICMPv4 +pass inet proto icmp from any to any keep state |
