Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- tcp_ports="{ 22, 80, 443, 860, 2049, 111, 3260 }"
- udp_ports="{ tftp, 111, 2049 }"
- set block-policy drop
- set skip on lo
- set skip on vlan1
- scrub in all fragment reassemble
- rdr pass on tap0 proto tcp from any to 192.94.73.210 rtable 2 -> 192.168.60.4
- #rdr pass on tap1 proto tcp from any to 178.63.35.230 rtable 3 -> 192.168.60.5
- block in all
- pass out all keep state
- #ldap
- pass in quick on vlan0 inet proto tcp from 192.168.50.0/24 to any port 389
- #end ldap
- pass in on vlan0 inet6 proto icmp6 from any to any
- pass in on tap0 proto tcp from any to any port 22 rtable 2
- pass in on tap0 proto icmp from any to any rtable 2
- #pass in on tap1 proto tcp from any to any port 22 rtable 3
- #pass in on tap1 proto tcp from any to any port 80 rtable 3
- #pass in on tap1 proto icmp from any to any rtable 3
- pass in on vlan0 proto tcp from any to any port $tcp_ports
- pass in on vlan0 proto udp from any to any port $udp_ports
- pass in on vlan0 inet6 proto tcp from any to any port $tcp_ports
- pass in on vlan0 inet6 proto udp from any to any port $udp_ports
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement