Changeset 8395 for 2.0/nanobsd


Ignore:
Timestamp:
Aug 26, 2010, 8:08:05 PM (14 years ago)
Author:
richardvm
Message:

block local network

File:
1 edited

Legend:

Unmodified
Added
Removed
  • 2.0/nanobsd/nanobsd/files/etc/ipfw.sh

    r8383 r8395  
    6161
    6262############
     63# Block the hosters network (and maybe others)
     64
     65for IP in ${firewall_block}
     66do
     67  ${fwcmd} add deny ip from any to ${IP} in via $internalif
     68done
    6369
    6470#############
    6571# Outbound NAT setup
     72
    6673${fwcmd} add nat 100 all from 172.16.0.0/12 to any out via $externalif
    6774${fwcmd} add nat 100 all from any to $externalip in via $externalif
    6875${fwcmd} nat 100 config if $externalif
    6976
    70 ############
    71 # Inbound NAT setup
    72 # ${fwcmd} add nat 200 all from any to 172.16.0.0/12 via $internalif
    73 # ${fwcmd} nat 200 config if $internalif
    74 
     77#############
    7578# WL -> Internet
    7679# Stateful firewalling
     
    98101${fwcmd} add 6003 allow tcp from any to me 3128 via $internalif keep-state
    99102
     103# lvrouted
     104${fwcmd} add 6004 allow udp from 172.16.0.0/12 to me 12345 via $internalif keep-state
     105
    100106# Block anything else
    101107${fwcmd} add 65000 deny ip from any to any
     108
Note: See TracChangeset for help on using the changeset viewer.