aboutsummaryrefslogtreecommitdiffstats
path: root/roles/jails/01_ingress/templates/etc_pf.conf.j2
diff options
context:
space:
mode:
Diffstat (limited to 'roles/jails/01_ingress/templates/etc_pf.conf.j2')
-rw-r--r--roles/jails/01_ingress/templates/etc_pf.conf.j227
1 files changed, 27 insertions, 0 deletions
diff --git a/roles/jails/01_ingress/templates/etc_pf.conf.j2 b/roles/jails/01_ingress/templates/etc_pf.conf.j2
new file mode 100644
index 0000000..c0528e1
--- /dev/null
+++ b/roles/jails/01_ingress/templates/etc_pf.conf.j2
@@ -0,0 +1,27 @@
+{% for jail in jails -%}
+{% if jail.name == 'ingress' -%}
+# Interfaces & nets
+lan = "epl{{ jail.num }}b"
+wan = "epw{{ jail.num }}b"
+lan_net = "{{ lan_ipv4_network }}"
+
+table <blocked> persist
+
+# Keep PF out of loopback, drop by default if you add blocks later
+set skip on lo0
+set block-policy drop
+
+# NAT: translate LAN traffic to the WAN interface address
+nat on $wan from $lan_net to any -> ($wan)
+
+# Block traffic from IPs in the blocked table
+block in quick from <blocked> to any
+
+# Allow all outbound traffic from the jail and LAN via both interfaces
+# NAT will be applied automatically when source is in $lan_net and going out $wan
+pass out on $wan all keep state
+pass out on $lan all keep state
+
+pass in on $wan inet proto {tcp, udp} from any to any port {80, 443} keep state
+{% endif %}
+{% endfor %}