Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ext_if="re0"
- int_if="re1"
- tcp_srv="{ www, https }"
- udp_srv="{ sip, 10000:20000 }"
- set skip on lo
- # route lan to wan
- pass out on $ext_if from $int_if:network to any nat-to ($ext_if)
- # allow access to services from wan
- pass in on $ext_if proto tcp from any to ($ext_if) port $tcp_srv synproxy state
- pass in on $ext_if proto udp from any to ($ext_if) port $udp_srv
- # allow egress
- pass out on $ext_if from ($ext_if) to any modulate state
- # allow in/out for lan
- pass on $int_if modulate state
- block all
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement