Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ext_if = "re0" # macro for external interface - use tun0 or pppoe0 for PPPoE
- int_if = "re1" # macro for internal interface
- localnet = $int_if:network
- client_out = "{ ftp-data, ftp, ssh, domain, pop3, auth, nntp, http,https, 446, cvspserver, 2628, 5999, 8000, 8080 }"
- udp_services = "{ domain, ntp }"
- # ext_if IP address could be dynamic, hence ($ext_if)
- nat on $ext_if from $localnet to any -> ($ext_if)
- block all
- pass inet proto tcp from $localnet to port $client_out
- pass in inet proto tcp to $ext_if port ssh
- pass quick inet proto { tcp, udp } to port $udp_services
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement