Changeset 10694 in hybrid for branches/releng-9.0/nanobsd/files/etc
- Timestamp:
- May 6, 2012, 10:42:31 PM (13 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/releng-9.0/nanobsd/files/etc/pf.hybrid.conf
r10610 r10694 54 54 nat on $ext_if inet proto tcp from $wl_net to any port { $publicnat } -> ($ext_if) 55 55 56 # Redirect some internal facing services outside, please mind also need allow rules (bottom of file) (7)57 rdr on $ext_if inet proto tcp from any to $ext_if port 8081 -> 172.16.4.46 port http58 56 59 57 # Redirect user to captive portal they have not clicked OK yet (6) 60 58 no rdr on { $captive_portal_interfaces } proto tcp from <wlportal> to !$wl_net port http 61 59 rdr on { $captive_portal_interfaces } proto tcp from $wl_net to !$wl_net port http -> 172.31.255.1 port 8081 60 61 # Redirect some internal facing services outside (7) 62 rdr on $ext_if inet proto tcp from any to $ext_if port 8081 tag SRV -> 172.16.4.46 port http 63 64 # Make the device on WL find the proper gateway back (7) 65 nat on ! $ext_if inet from any to $wl_net tagged SRV -> $masterip 66 67 # Special allow rules for inbound piercing (7) 68 pass in quick on $ext_if inet tagged SRV keep state 62 69 63 70 # Localhost is considered safe (5) … … 84 91 pass in on $ext_if from $private to $wl_net keep state 85 92 86 # Allow exposing some (internal) WL Services to the inet - see rdr on top as well (7)87 pass in on $ext_if inet proto tcp from any to $ext_if port { 8081 } keep state88 89 93 # Packets going out are the ones to the internet with an certain limit (1) 90 94 pass out on $ext_if inet proto tcp from $wl_net to any port { $publicnat } keep state \
Note:
See TracChangeset
for help on using the changeset viewer.