Advertisement
Guest User

Untitled

a guest
May 4th, 2015
201
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.56 KB | None | 0 0
  1. ext_if = "re0" # macro for external interface - use tun0 or pppoe0 for PPPoE
  2. int_if = "re1" # macro for internal interface
  3. localnet = $int_if:network
  4. client_out = "{ ftp-data, ftp, ssh, domain, pop3, auth, nntp, http,https, 446, cvspserver, 2628, 5999, 8000, 8080 }"
  5. udp_services = "{ domain, ntp }"
  6. # ext_if IP address could be dynamic, hence ($ext_if)
  7. nat on $ext_if from $localnet to any -> ($ext_if)
  8. block all
  9. pass inet proto tcp from $localnet to port $client_out
  10. pass in inet proto tcp to $ext_if port ssh
  11. pass quick inet proto { tcp, udp } to port $udp_services
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement