Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- firewall {
- all-ping enable
- broadcast-ping disable
- group {
- network-group MEO_IPTV_DESTINATION {
- description ""
- network 232.0.0.0/8
- network 235.0.0.0/8
- network 239.0.0.0/8
- }
- network-group MEO_IPTV_NETWORKS {
- description ""
- network 10.0.0.0/8
- network 195.0.0.0/8
- network 213.0.0.0/8
- network 194.0.0.0/8
- }
- network-group PROTECTED_NETWORKS {
- description ""
- network 172.16.0.0/16
- }
- }
- ipv6-receive-redirects disable
- ipv6-src-route disable
- ip-src-route disable
- log-martians enable
- name WAN_IN {
- default-action drop
- description "WAN to internal"
- rule 10 {
- action accept
- description "Allow Multicast"
- destination {
- group {
- network-group MEO_IPTV_DESTINATION
- }
- }
- log disable
- protocol udp
- source {
- group {
- network-group MEO_IPTV_NETWORKS
- }
- }
- }
- rule 20 {
- action accept
- description "Allow IGMP"
- log disable
- protocol igmp
- }
- rule 30 {
- action accept
- description "Allow established/related"
- state {
- established enable
- related enable
- }
- }
- rule 40 {
- action drop
- description "Drop invalid state"
- state {
- invalid enable
- }
- }
- }
- name WAN_LOCAL {
- default-action drop
- description "WAN to router"
- rule 10 {
- action accept
- description "Allow IGMP"
- log disable
- protocol igmp
- }
- rule 20 {
- action accept
- description "Allow ICMP"
- log disable
- protocol icmp
- }
- rule 30 {
- action accept
- description "Allow established/related"
- state {
- established enable
- related enable
- }
- }
- rule 40 {
- action drop
- description "Drop invalid state"
- state {
- invalid enable
- }
- }
- }
- receive-redirects disable
- send-redirects enable
- source-validation disable
- syn-cookies enable
- }
- interfaces {
- ethernet eth0 {
- description WAN
- duplex auto
- speed auto
- vif 12 {
- address dhcp
- description MEO VLAN
- firewall {
- in {
- name WAN_IN
- }
- local {
- name WAN_LOCAL
- }
- }
- }
- }
- ethernet eth1 {
- description LAN
- duplex auto
- speed auto
- }
- ethernet eth2 {
- description N/A
- disable
- duplex auto
- speed auto
- }
- ethernet eth3 {
- description N/A
- disable
- duplex auto
- speed auto
- }
- ethernet eth4 {
- address 172.16.253.1/24
- description IPTV
- duplex auto
- poe {
- output off
- }
- speed auto
- }
- loopback lo {
- }
- switch switch0 {
- address 172.16.10.1/24
- description "MAIN LAN"
- mtu 1500
- switch-port {
- interface eth1 {
- }
- vlan-aware disable
- }
- vif 1337 {
- address 172.16.254.1/24
- description "GUEST LAN"
- mtu 1500
- }
- }
- }
- port-forward {
- auto-firewall enable
- hairpin-nat enable
- lan-interface switch0
- wan-interface eth0.12
- }
- protocols {
- igmp-proxy {
- interface eth0.12 {
- alt-subnet 0.0.0.0/0
- role upstream
- threshold 1
- }
- interface eth4 {
- alt-subnet 172.16.253.0/24
- role downstream
- threshold 1
- }
- }
- }
- service {
- dhcp-server {
- disabled false
- hostfile-update disable
- shared-network-name GUEST {
- authoritative disable
- subnet 172.16.254.0/24 {
- default-router 172.16.254.1
- dns-server 172.16.254.1
- domain-name ragenetwork.guest
- lease 604800
- start 172.16.254.100 {
- stop 172.16.254.199
- }
- unifi-controller 172.16.10.202
- }
- }
- shared-network-name IPTV {
- authoritative disable
- subnet 172.16.253.0/24 {
- default-router 172.16.253.1
- dns-server 172.16.253.1
- domain-name ragenetwork.iptv
- lease 604800
- start 172.16.253.10 {
- stop 172.16.253.19
- }
- }
- }
- shared-network-name LAN {
- authoritative enable
- subnet 172.16.10.0/24 {
- default-router 172.16.10.1
- dns-server 172.16.10.1
- domain-name ragenetwork.lan
- lease 604800
- start 172.16.10.100 {
- stop 172.16.10.199
- }
- unifi-controller 172.16.10.202
- }
- }
- static-arp disable
- use-dnsmasq disable
- }
- dns {
- forwarding {
- cache-size 10000
- listen-on switch0
- listen-on switch0.1337
- listen-on eth4
- system
- }
- }
- gui {
- http-port 80
- https-port 443
- older-ciphers enable
- }
- nat {
- rule 5010 {
- description "masquerade for WAN"
- outbound-interface eth0.12
- type masquerade
- }
- }
- ssh {
- port 22
- protocol-version v2
- }
- ubnt-discover {
- disable
- }
- unms {
- disable
- }
- upnp {
- listen-on switch0 {
- outbound-interface eth0.12
- }
- }
- }
- system {
- domain-name ragenetwork.lan
- host-name Router
- }
- name-server 1.1.1.1
- name-server 1.0.0.1
- ntp {
- server 0.ubnt.pool.ntp.org {
- }
- server 1.ubnt.pool.ntp.org {
- }
- server 2.ubnt.pool.ntp.org {
- }
- server 3.ubnt.pool.ntp.org {
- }
- }
- offload {
- hwnat enable
- ipsec enable
- }
- syslog {
- global {
- facility all {
- level notice
- }
- facility protocols {
- level debug
- }
- }
- }
- time-zone UTC
- }
- traffic-control {
- smart-queue WAN {
- upload {
- ecn enable
- flows 1024
- fq-quantum 1514
- limit 10240
- rate 109mbit
- }
- download {
- ecn enable
- flows 1024
- fq-quantum 1514
- limit 10240
- rate 209mbit
- }
- wan-interface eth0.12
- }
- }
- /* Warning: Do not remove the following line. */
- /* === vyatta-config-version: "config-management@1:conntrack@1:cron@1:dhcp-relay@1:dhcp-server@4:firewall@5:ipsec@5:nat@3:qos@1:quagga@2:suspend@1:system@4:ubnt-pptp@1:ubnt-udapi-server@1:ubnt-unms@1:ubnt-util@1:vrrp@1:webgui@1:webproxy@1:zone-policy@1" === */
- /* Release version: v1.10.8.5142457.181120.1809 */
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement