Changeset 13772 in hybrid for branches/releng-11/nanobsd/files/etc
- Timestamp:
- Jan 23, 2017, 5:26:28 PM (8 years ago)
- Location:
- branches/releng-11/nanobsd/files/etc
- Files:
-
- 2 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/releng-11/nanobsd/files/etc/pf.hybrid.conf
r13724 r13772 71 71 72 72 # By default deny all outgoing traffic to avoid systems spamming the network (9) 73 block out on { $captive_portal_interfaces } from any to !$wl_net 73 block in on { $captive_portal_interfaces } from any to !$wl_net 74 75 # Quickly drop out, with nice return value, avoiding endless connections on portal setup (6) 76 block return in quick on { $captive_portal_interfaces } proto tcp from !<wlportal> to !$wl_net port { $publicnat } 74 77 75 78 # Note: not even HTTPS traffic allowed for those who has not clicked OK yet (6) 76 pass outon { $captive_portal_interfaces } proto tcp from <wlportal> to !$wl_net port { $publicnat } keep state79 pass in on { $captive_portal_interfaces } proto tcp from <wlportal> to !$wl_net port { $publicnat } keep state 77 80 78 81 # External interface is permissive (4) -
branches/releng-11/nanobsd/files/etc/pf.node.conf
r10745 r13772 39 39 40 40 # By default deny all outgoing traffic to avoid systems spamming the network (9) 41 block out on { $captive_portal_interfaces } from any to !$wl_net 41 block in on { $captive_portal_interfaces } from any to !$wl_net 42 43 # Quickly drop out, with nice return value, avoiding endless connections on portal setup (6) 44 block return in quick on { $captive_portal_interfaces } proto tcp from !<wlportal> to !$wl_net port { $publicnat } 42 45 43 46 # Note: not even HTTPS traffic allowed for those who has not clicked OK yet (6) 44 pass outon { $captive_portal_interfaces } proto tcp from <wlportal> to !$wl_net port { $ileiden_ports } keep state47 pass in on { $captive_portal_interfaces } proto tcp from <wlportal> to !$wl_net port { $ileiden_ports } keep state
Note:
See TracChangeset
for help on using the changeset viewer.