Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- firewall {
- all-ping enable
- broadcast-ping disable
- ipv6-name WANv6_IN {
- default-action drop
- description "WAN IPv6 naar LAN"
- rule 10 {
- action accept
- description "Allow established/related"
- state {
- established enable
- related enable
- }
- }
- rule 20 {
- action drop
- description "Drop invalid state"
- state {
- invalid enable
- }
- }
- rule 30 {
- action accept
- description "Allow IPv6 icmp"
- icmpv6 {
- type echo-request
- }
- protocol ipv6-icmp
- }
- }
- ipv6-name WANv6_LOCAL {
- default-action drop
- description "WAN IPv6 naar Router"
- rule 10 {
- action accept
- description "Allow established/related"
- state {
- established enable
- related enable
- }
- }
- rule 20 {
- action drop
- description "Drop invalid state"
- state {
- invalid enable
- }
- }
- rule 30 {
- action accept
- description "Allow IPv6 icmp"
- protocol ipv6-icmp
- }
- rule 40 {
- action accept
- description "Allow dhcpv6"
- destination {
- port 546
- }
- protocol udp
- source {
- port 547
- }
- }
- }
- ipv6-receive-redirects disable
- ipv6-src-route disable
- ip-src-route disable
- log-martians enable
- name WAN_IN {
- default-action drop
- description "WAN naar LAN"
- rule 10 {
- action accept
- description "Allow established/related"
- log disable
- state {
- established enable
- related enable
- }
- }
- rule 20 {
- action accept
- description "Allow 27015 traffic"
- destination {
- port 27015
- }
- log disable
- protocol tcp_udp
- }
- rule 40 {
- action accept
- description "Allow 9987 teamspeak"
- destination {
- port 9987
- }
- log disable
- protocol tcp_udp
- }
- rule 50 {
- action accept
- description "Allow 80 traffic"
- destination {
- port 80
- }
- log disable
- protocol tcp_udp
- }
- rule 60 {
- action accept
- description "Allow 443"
- destination {
- port 443
- }
- log disable
- protocol tcp_udp
- }
- rule 70 {
- action drop
- description "Drop invalid state"
- state {
- invalid enable
- }
- }
- }
- name WAN_LOCAL {
- default-action drop
- description "WAN naar Router"
- rule 10 {
- action accept
- description "Allow established/related"
- log disable
- state {
- established enable
- invalid disable
- new disable
- related enable
- }
- }
- rule 20 {
- action drop
- description "Drop invalid state"
- state {
- established disable
- invalid enable
- new disable
- related disable
- }
- }
- }
- options {
- mss-clamp {
- interface-type all
- mss 1412
- }
- }
- receive-redirects disable
- send-redirects enable
- source-validation disable
- syn-cookies enable
- }
- interfaces {
- ethernet eth0 {
- description FTTH
- duplex auto
- speed auto
- vif 4 {
- address dhcp
- description "KPN IPTV"
- dhcp-options {
- client-option "send vendor-class-identifier "IPTV_RG";
- "
- client-option "request subnet-mask, routers, rfc3442-classless-s
- tatic-routes;"
- default-route no-update
- default-route-distance 210
- name-server update
- }
- mtu 1500
- }
- vif 6 {
- description "KPN Internet"
- pppoe 0 {
- default-route auto
- dhcpv6-pd {
- no-dns
- pd 0 {
- interface eth1 {
- prefix-id :1
- service slaac
- }
- interface switch0 {
- host-address ::1
- prefix-id :1
- service slaac
- }
- prefix-length /48
- }
- rapid-commit disable
- }
- firewall {
- in {
- ipv6-name WANv6_IN
- name WAN_IN
- }
- local {
- ipv6-name WANv6_LOCAL
- name WAN_LOCAL
- }
- }
- idle-timeout 180
- ipv6 {
- address {
- autoconf
- }
- dup-addr-detect-transmits 1
- enable {
- }
- }
- mtu 1500
- name-server auto
- password ****************
- user-id 74-83-c2-72-b2-e7@internet
- }
- }
- }
- ethernet eth1 {
- description "Poort 1 TV ontvanger"
- duplex auto
- speed auto
- }
- ethernet eth2 {
- description "Poort 2 TV woonkamer"
- duplex auto
- speed auto
- }
- ethernet eth3 {
- description "Poort 3 gaming pc woonkamer"
- duplex auto
- speed auto
- }
- ethernet eth4 {
- description "Poort 4 Accesspoint woonkamer"
- duplex auto
- speed auto
- }
- ethernet eth5 {
- description "Poort 5 uplink 2e verdieping switcdh"
- duplex auto
- speed auto
- }
- ethernet eth6 {
- duplex auto
- speed auto
- }
- ethernet eth7 {
- duplex auto
- speed auto
- }
- ethernet eth8 {
- duplex auto
- speed auto
- }
- ethernet eth9 {
- description "Poort 9 Accesspoint 2de verdieping"
- duplex auto
- poe {
- output off
- }
- speed auto
- }
- loopback lo {
- }
- switch switch0 {
- address 192.168.178.254/24
- description "Thuis netwerk"
- ipv6 {
- dup-addr-detect-transmits 1
- router-advert {
- cur-hop-limit 64
- link-mtu 0
- managed-flag false
- max-interval 600
- name-server 2a02:a47f:e000::53
- name-server 2a02:a47f:e000::54
- other-config-flag false
- prefix ::/64 {
- autonomous-flag true
- on-link-flag true
- valid-lifetime 2592000
- }
- radvd-options "RDNSS 2a02:a47f:e000::53 2a02:a47f:e000::54 {};"
- reachable-time 0
- retrans-timer 0
- send-advert true
- }
- }
- mtu 1500
- switch-port {
- interface eth1 {
- }
- interface eth2 {
- }
- interface eth3 {
- }
- interface eth4 {
- }
- interface eth5 {
- }
- interface eth6 {
- }
- interface eth7 {
- }
- interface eth8 {
- }
- interface eth9 {
- }
- vlan-aware disable
- }
- }
- }
- port-forward {
- auto-firewall enable
- hairpin-nat enable
- lan-interface switch0
- rule 1 {
- description "CSGO server S01"
- forward-to {
- address 192.168.178.10
- port 27015
- }
- original-port 27015
- protocol tcp_udp
- }
- rule 2 {
- description "TeamSpeak server S01"
- forward-to {
- address 192.168.178.10
- port 9987
- }
- original-port 9987
- protocol tcp_udp
- }
- rule 3 {
- description "http s01"
- forward-to {
- address 192.168.178.10
- port 80
- }
- original-port 80
- protocol tcp_udp
- }
- rule 4 {
- description "https s01"
- forward-to {
- address 192.168.178.10
- port 443
- }
- original-port 443
- protocol tcp_udp
- }
- rule 5 {
- description ftp
- forward-to {
- address 192.168.178.10
- port 21
- }
- original-port 21
- protocol tcp_udp
- }
- wan-interface pppoe0
- }
- protocols {
- igmp-proxy {
- interface eth0.4 {
- alt-subnet 0.0.0.0/0
- role upstream
- threshold 1
- }
- interface switch0 {
- alt-subnet 0.0.0.0/0
- role downstream
- threshold 1
- }
- }
- static {
- interface-route6 ::/0 {
- next-hop-interface pppoe0 {
- }
- }
- }
- }
- service {
- dhcp-server {
- disabled false
- global-parameters "option vendor-class-identifier code 60 = string;"
- global-parameters "option broadcast-address code 28 = ip-address;"
- hostfile-update disable
- shared-network-name Thuis-Mark {
- authoritative disable
- subnet 192.168.178.0/24 {
- default-router 192.168.178.254
- dns-server 195.121.1.34
- dns-server 195.121.1.66
- lease 86400
- start 192.168.178.50 {
- stop 192.168.178.199
- }
- }
- }
- static-arp disable
- use-dnsmasq enable
- }
- dns {
- forwarding {
- cache-size 4000
- listen-on switch0
- name-server 195.121.1.34
- name-server 195.121.1.66
- name-server 2a02:a47f:e000::53
- name-server 2a02:a47f:e000::54
- options listen-address=192.168.2.254
- }
- }
- gui {
- http-port 80
- https-port 443
- older-ciphers enable
- }
- nat {
- rule 5000 {
- description IPTV
- destination {
- address 213.75.112.0/21
- }
- log disable
- outbound-interface eth0.4
- protocol all
- source {
- address 192.168.178.0/24
- }
- type masquerade
- }
- rule 5010 {
- description Internet
- log enable
- outbound-interface pppoe0
- protocol all
- type masquerade
- }
- }
- ssh {
- port 22
- protocol-version v2
- }
- telnet {
- port 23
- }
- unms {
- connection wss://fuuv.unmsapp.com:443+csIifnmNaIEBrKKq13NBGRPGgCRE1gHapp
- ecmRlYDaYAAAAA+allowUntrustedCertificate
- }
- upnp {
- listen-on switch0 {
- outbound-interface pppoe0
- }
- }
- }
- system {
- conntrack {
- expect-table-size 2048
- hash-size 32768
- modules {
- sip {
- disable
- }
- }
- table-size 262144
- }
- domain-name thuis.local
- host-name Thuis
- login {
- user admin {
- authentication {
- encrypted-password ****************
- plaintext-password ****************
- }
- level admin
- }
- }
- name-server 127.0.0.1
- ntp {
- server 0.nl.pool.ntp.org {
- }
- server 1.nl.pool.ntp.org {
- }
- server ntp0.nl.net {
- }
- server ntp1.nl.net {
- }
- server time.kpn.net {
- }
- }
- offload {
- hwnat enable
- ipsec enable
- }
- syslog {
- global {
- facility all {
- level notice
- }
- facility protocols {
- level debug
- }
- }
- }
- time-zone Europe/Amsterdam
- traffic-analysis {
- dpi enable
- export enable
- }
- }
- admin@Thuis:~$ H
Add Comment
Please, Sign In to add comment