Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- firewall {
- all-ping enable
- broadcast-ping disable
- group {
- address-group vlan10 {
- address 192.168.10.0/23
- description "vlan10 subnet (192.168.10.0/23)"
- }
- address-group vlan20 {
- address 192.168.20.0/23
- description "vlan20 subnet (192.168.20.0/23)"
- }
- address-group vlan30 {
- address 192.168.30.0/23
- description "vlan30 subnet (192.168.30.0/23)"
- }
- address-group vlan40 {
- address 192.168.40.0/23
- description "vlan40 subnet (192.168.40.0/23)"
- }
- network-group RFC-1918_networks {
- description "Used to easily block RFC-1918_networks"
- network 192.168.0.0/16
- network 172.16.0.0/12
- network 10.0.0.0/8
- }
- }
- ipv6-receive-redirects disable
- ipv6-src-route disable
- ip-src-route disable
- log-martians enable
- name LAN_IN {
- default-action accept
- description "Internal network to Internet"
- rule 1 {
- action accept
- description "Allow Admin To Wired (redundant)"
- destination {
- group {
- address-group vlan20
- }
- }
- log disable
- protocol all
- source {
- group {
- address-group vlan10
- }
- }
- }
- rule 2 {
- action accept
- description "Allow Admin To Member (redundant)"
- destination {
- group {
- address-group vlan30
- }
- }
- log disable
- protocol all
- source {
- group {
- address-group vlan10
- }
- }
- }
- rule 3 {
- action accept
- description "Allow Admin To Guest (redundant)"
- destination {
- group {
- address-group vlan40
- }
- }
- log disable
- protocol all
- source {
- group {
- address-group vlan10
- }
- }
- }
- rule 4 {
- action drop
- description "Drop Wired to Admin"
- destination {
- group {
- address-group vlan10
- }
- }
- log disable
- protocol all
- source {
- group {
- address-group vlan20
- }
- }
- }
- rule 5 {
- action drop
- description "Drop Wired to Member"
- destination {
- group {
- address-group vlan30
- }
- }
- log disable
- protocol all
- source {
- group {
- address-group vlan20
- }
- }
- }
- rule 6 {
- action drop
- description "Drop Wired to Guest"
- destination {
- group {
- address-group vlan40
- }
- }
- log disable
- protocol all
- source {
- group {
- address-group vlan20
- }
- }
- }
- rule 7 {
- action drop
- description "Drop Member to Admin"
- destination {
- group {
- address-group vlan10
- }
- }
- log disable
- protocol all
- source {
- group {
- address-group vlan30
- }
- }
- }
- rule 8 {
- action drop
- description "Drop Member to Wired"
- destination {
- group {
- address-group vlan20
- }
- }
- log disable
- protocol all
- source {
- group {
- address-group vlan30
- }
- }
- }
- rule 9 {
- action drop
- description "Drop Member to Guest"
- destination {
- group {
- address-group vlan40
- }
- }
- log disable
- protocol all
- source {
- group {
- address-group vlan30
- }
- }
- }
- rule 10 {
- action drop
- description "Drop Guest to Admin"
- destination {
- group {
- address-group vlan10
- }
- }
- log disable
- protocol all
- source {
- group {
- address-group vlan40
- }
- }
- }
- rule 11 {
- action drop
- description "Drop Guest to Wired"
- destination {
- group {
- address-group vlan20
- }
- }
- log disable
- protocol all
- source {
- group {
- address-group vlan40
- }
- }
- }
- rule 12 {
- action drop
- description "Drop Guest to Member"
- destination {
- group {
- address-group vlan30
- }
- }
- log disable
- protocol all
- source {
- group {
- address-group vlan40
- }
- }
- }
- }
- name LAN_LOCAL {
- default-action accept
- description "Internal network to router"
- }
- name Member-VLAN {
- default-action accept
- description "Isolate Member VLAN"
- rule 1 {
- action drop
- description "Drop Route to RFC-1918_networks"
- destination {
- group {
- network-group RFC-1918_networks
- }
- }
- log enable
- protocol all
- }
- rule 2 {
- action drop
- description "Drop Traffic Between Clients"
- destination {
- group {
- address-group vlan30
- }
- }
- log disable
- protocol all
- source {
- group {
- address-group vlan30
- }
- }
- }
- }
- name WAN_IN {
- default-action drop
- description "packets from Internet to LAN & WLAN"
- enable-default-log
- rule 1 {
- action accept
- description "allow established sessions"
- log disable
- protocol all
- state {
- established enable
- invalid disable
- new disable
- related enable
- }
- }
- rule 2 {
- action drop
- description "drop invalid state"
- log disable
- protocol all
- state {
- established disable
- invalid enable
- new disable
- related disable
- }
- }
- rule 3 {
- action accept
- description "Allow RDP Music"
- destination {
- port 35560
- }
- log disable
- protocol tcp_udp
- }
- rule 4 {
- action accept
- description "Allow iperf"
- destination {
- address 192.168.10.50
- port 5201
- }
- log disable
- protocol tcp_udp
- }
- }
- name WAN_LOCAL {
- default-action drop
- description "packets from Internet to the router"
- enable-default-log
- rule 1 {
- action accept
- description "allow established sessions"
- log disable
- protocol all
- state {
- established enable
- invalid disable
- new disable
- related enable
- }
- }
- rule 2 {
- action drop
- description "drop invalid state"
- log disable
- protocol all
- state {
- established disable
- invalid enable
- new disable
- related disable
- }
- }
- }
- receive-redirects disable
- send-redirects enable
- source-validation disable
- syn-cookies enable
- }
- interfaces {
- ethernet eth0 {
- address dhcp
- address dhcpv6
- description "WAN To FiberJack"
- duplex auto
- firewall {
- in {
- name WAN_IN
- }
- local {
- name WAN_LOCAL
- }
- }
- speed auto
- }
- ethernet eth1 {
- description "Trunk To Switch"
- duplex auto
- firewall {
- in {
- name LAN_IN
- }
- }
- speed auto
- vif 10 {
- address 192.168.10.1/23
- }
- vif 20 {
- address 192.168.20.1/23
- }
- vif 30 {
- address 192.168.30.1/23
- firewall {
- in {
- name Member-VLAN
- }
- }
- }
- vif 40 {
- address 192.168.40.1/23
- }
- }
- ethernet eth2 {
- address 192.168.2.1/24
- description "Local Config Port"
- duplex auto
- speed auto
- }
- loopback lo {
- }
- }
- port-forward {
- auto-firewall enable
- hairpin-nat enable
- lan-interface eth1.10
- rule 1 {
- description "rdp music"
- forward-to {
- address 192.168.10.50
- port 3389
- }
- original-port 35560
- protocol tcp_udp
- }
- wan-interface eth0
- }
- service {
- dhcp-server {
- disabled false
- hostfile-update enable
- shared-network-name vlan10 {
- authoritative disable
- description vlan10-dhcp-pool
- subnet 192.168.10.0/23 {
- default-router 192.168.10.1
- dns-server 192.168.10.1
- lease 86400
- start 192.168.10.100 {
- stop 192.168.10.249
- }
- static-mapping Music {
- ip-address 192.168.10.50
- mac-address f0:4d:a2:f7:7a:b6
- }
- static-mapping WIFI-AP1 {
- ip-address 192.168.10.20
- mac-address 88:dc:96:37:1d:f8
- }
- static-mapping WIFI-AP2 {
- ip-address 192.168.10.21
- mac-address 88:dc:96:37:1d:fc
- }
- static-mapping sw1 {
- ip-address 192.168.10.10
- mac-address a0:63:91:96:f1:5c
- }
- }
- }
- shared-network-name vlan20 {
- authoritative disable
- description vlan20-dhcp-pool
- subnet 192.168.20.0/23 {
- default-router 192.168.20.1
- dns-server 192.168.20.1
- lease 86400
- start 192.168.20.100 {
- stop 192.168.20.249
- }
- }
- }
- shared-network-name vlan30 {
- authoritative disable
- description vlan30-dhcp-pool
- subnet 192.168.30.0/23 {
- default-router 192.168.30.1
- dns-server 192.168.30.1
- lease 86400
- start 192.168.30.100 {
- stop 192.168.30.249
- }
- }
- }
- shared-network-name vlan40 {
- authoritative disable
- description vlan40-dhcp-pool
- subnet 192.168.40.0/23 {
- default-router 192.168.40.1
- dns-server 192.168.40.1
- lease 86400
- start 192.168.40.100 {
- stop 192.168.40.249
- }
- }
- }
- }
- dns {
- dynamic {
- interface eth0 {
- service dyndns {
- host-name redacted
- login redacted
- password redacted
- server dynupdate.no-ip.com
- }
- }
- }
- forwarding {
- cache-size 150
- listen-on eth1
- listen-on eth1.10
- listen-on eth1.20
- listen-on eth1.30
- listen-on eth1.40
- name-server 8.8.8.8
- name-server 8.8.4.4
- }
- }
- gui {
- https-port 443
- }
- nat {
- rule 1 {
- description "port forward iperf 35561 to 5201 "
- destination {
- port 35561
- }
- disable
- inbound-interface eth0
- inside-address {
- address 192.168.10.50
- port 5201
- }
- log enable
- protocol tcp_udp
- type destination
- }
- rule 5010 {
- description "masquerade from all LANs to eth0 WAN"
- log disable
- outbound-interface eth0
- protocol all
- source {
- address 192.168.0.0/16
- }
- type masquerade
- }
- rule 5011 {
- description "Allow VLAN10 Internet"
- disable
- log disable
- outbound-interface eth0
- protocol all
- source {
- group {
- address-group ADDRv4_eth1.10
- }
- }
- type masquerade
- }
- rule 5012 {
- description "MASQ for hairpin"
- destination {
- address 192.168.0.0/16
- port 5201
- }
- log disable
- outbound-interface eth1
- protocol tcp_udp
- source {
- address 192.168.0.0/16
- }
- type masquerade
- }
- }
- ssh {
- port 22
- protocol-version v2
- }
- }
- system {
- host-name redacted
- login {
- user redacted {
- authentication {
- encrypted-password redacted
- plaintext-password ""
- public-keys redacted@ubnt {
- key redacted
- type ssh-rsa
- }
- }
- full-name "redacted"
- level admin
- }
- }
- name-server 8.8.8.8
- name-server 8.8.4.4
- name-server 2001:4860:4860::8888
- name-server 2001:4860:4860::8844
- ntp {
- server 0.ubnt.pool.ntp.org {
- }
- server 1.ubnt.pool.ntp.org {
- }
- server 2.ubnt.pool.ntp.org {
- }
- server 3.ubnt.pool.ntp.org {
- }
- }
- offload {
- ipsec enable
- ipv4 {
- forwarding enable
- }
- ipv6 {
- forwarding disable
- }
- }
- package {
- repository wheezy {
- components "main contrib non-free"
- distribution wheezy
- password ""
- url http://http.us.debian.org/debian
- username ""
- }
- repository wheezy-security {
- components main
- distribution wheezy/updates
- password ""
- url http://security.debian.org
- username ""
- }
- }
- syslog {
- global {
- facility all {
- level notice
- }
- facility protocols {
- level debug
- }
- }
- }
- time-zone America/Chicago
- traffic-analysis {
- dpi enable
- export enable
- }
- }
- /* Warning: Do not remove the following line. */
- /* === vyatta-config-version: "config-management@1:conntrack@1:cron@1:dhcp-relay@1:dhcp-server@4:firewall@5:ipsec@4:nat@3:qos@1:quagga@2:system@4:ubnt-pptp@1:ubnt-util@1:vrrp@1:webgui@1:webproxy@1:zone-policy@1" === */
- /* Release version: v1.7.0.4783374.150622.1534 */
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement