Advertisement
Guest User

Untitled

a guest
Oct 26th, 2016
68
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.31 KB | None | 0 0
  1. dmz_if = "em1"
  2. lan_if = "em0"
  3. table <dmz> persist { 192.168.19.0/24 }
  4. table <lan> persist { 192.168.1.0/24 }
  5.  
  6. # NAT
  7. nat on $dmz_if from { 192.168.19.0/24 } to any -> ($dmz_if)
  8. nat on $lan_if from { 192.168.1.0/24 } to any -> ($lan_if)
  9.  
  10. # Filter rules
  11. pass all
  12. pass in from <dmz> to any rtable 1
  13. pass out from <dmz> to any rtable 1
  14. pass in from <lan> to any rtable 0
  15. pass out from <lan> to any rtable 0
  16.  
  17. ifconfig_em0="inet 192.168.1.198/24"
  18. ifconfig_em1="inet 192.168.19.236/24"
  19. nginx_enable="YES"
  20. pf_enable="YES"
  21. pf_rules="/etc/pf.conf"
  22. pf_flags=""
  23. pflog_enable="YES"
  24.  
  25. # Routes
  26. # define default routes
  27. setfib 1 route delete default
  28. setfib 1 route add default 192.168.19.254
  29. #setfib 1 route add default 10.1.6.25
  30. setfib 0 route delete default
  31. setfib 0 route add default 192.168.1.1
  32. #
  33. # assing route tables to interfaces
  34. ipfw -f flush
  35. ipfw add allow ip from any to any via lo0
  36. #ipfw add setfib 1 ip from any to any via em0
  37. #ipfw add setfib 0 ip from any to any via em1
  38. ipfw add setfib 1 ip from any to any via em1
  39. ipfw add setfib 0 ip from any to any via em0
  40. ipfw add allow ip from any to any
  41.  
  42. root@kanneldev:~ # netstat
  43. Active Internet connections
  44. Proto Recv-Q Send-Q Local Address Foreign Address (state)
  45. tcp4 0 0 192.168.19.236.http 192.168.1.112.17649 SYN_RCVD
  46.  
  47. net.fibs: 16
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement