From b5860daf11ac353049cb1654b9414a129e5cfb96 Mon Sep 17 00:00:00 2001 From: Jan Tuomi Date: Wed, 13 May 2026 00:13:57 +0300 Subject: Rework --- roles/jails/01_ingress/templates/etc_pf.conf.j2 | 27 +++++++++++++++++++++++++ 1 file changed, 27 insertions(+) create mode 100644 roles/jails/01_ingress/templates/etc_pf.conf.j2 (limited to 'roles/jails/01_ingress/templates/etc_pf.conf.j2') diff --git a/roles/jails/01_ingress/templates/etc_pf.conf.j2 b/roles/jails/01_ingress/templates/etc_pf.conf.j2 new file mode 100644 index 0000000..c0528e1 --- /dev/null +++ b/roles/jails/01_ingress/templates/etc_pf.conf.j2 @@ -0,0 +1,27 @@ +{% for jail in jails -%} +{% if jail.name == 'ingress' -%} +# Interfaces & nets +lan = "epl{{ jail.num }}b" +wan = "epw{{ jail.num }}b" +lan_net = "{{ lan_ipv4_network }}" + +table persist + +# Keep PF out of loopback, drop by default if you add blocks later +set skip on lo0 +set block-policy drop + +# NAT: translate LAN traffic to the WAN interface address +nat on $wan from $lan_net to any -> ($wan) + +# Block traffic from IPs in the blocked table +block in quick from to any + +# Allow all outbound traffic from the jail and LAN via both interfaces +# NAT will be applied automatically when source is in $lan_net and going out $wan +pass out on $wan all keep state +pass out on $lan all keep state + +pass in on $wan inet proto {tcp, udp} from any to any port {80, 443} keep state +{% endif %} +{% endfor %} -- cgit v1.3