From 533bc95c751337d5f2952252b0378848cf078357 Mon Sep 17 00:00:00 2001 From: Jan Tuomi Date: Mon, 29 Dec 2025 23:16:22 +0200 Subject: Add crawler tarpit --- templates/ingress/etc_pf.conf.j2 | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'templates/ingress/etc_pf.conf.j2') diff --git a/templates/ingress/etc_pf.conf.j2 b/templates/ingress/etc_pf.conf.j2 index feb35d5..c0528e1 100644 --- a/templates/ingress/etc_pf.conf.j2 +++ b/templates/ingress/etc_pf.conf.j2 @@ -5,6 +5,8 @@ lan = "epl{{ jail.num }}b" wan = "epw{{ jail.num }}b" lan_net = "{{ lan_ipv4_network }}" +table persist + # Keep PF out of loopback, drop by default if you add blocks later set skip on lo0 set block-policy drop @@ -12,6 +14,9 @@ set block-policy drop # NAT: translate LAN traffic to the WAN interface address nat on $wan from $lan_net to any -> ($wan) +# Block traffic from IPs in the blocked table +block in quick from to any + # Allow all outbound traffic from the jail and LAN via both interfaces # NAT will be applied automatically when source is in $lan_net and going out $wan pass out on $wan all keep state -- cgit v1.3