Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- int_if = "vether0"
- nat_if = "iwm0"
- out_tcp_svc = "{ domain, www, https, smtp, whois, ftp, ftp-data, ssh, 5544, ntp, 9001 , pop3, pop3s, 6697, 465 }"
- out_udp_svc = "{ domain, ntp }"
- match out on $nat_if from $int_if:network to any nat-to ($nat_if)
- block log all
- pass on $int_if
- pass out on $nat_if proto tcp to any port $out_tcp_svc keep state
- pass out on $nat_if proto udp to any port $out_udp_svc keep state
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement