firewall/example.yaml

74 lines
1.1 KiB
YAML
Raw Normal View History

2023-04-16 23:11:54 +02:00
---
zones:
2023-08-13 18:40:29 +02:00
users-internet-allowed:
files: [example.yaml]
2023-06-17 00:19:19 +02:00
2023-08-13 18:40:29 +02:00
mgmt:
addrs: [10.203.0.0/16]
2023-06-17 00:19:19 +02:00
2023-08-13 18:40:29 +02:00
adm:
addrs: [2a09:6840::/29, 10.128.0.0/16]
2023-06-17 00:19:19 +02:00
2023-08-13 18:40:29 +02:00
internet:
negate: true
zones: [adm, mgmt]
# interne: negate KO
2023-04-16 23:11:54 +02:00
blacklist:
enabled: true
2023-06-17 00:19:19 +02:00
addr: [0.0.0.0]
2023-04-16 23:11:54 +02:00
reverse_path_filter:
enabled: true
filter:
input:
- iif: lo
verdict: accept
2023-06-17 00:19:19 +02:00
2023-04-16 23:11:54 +02:00
- src: mgmt
protocols:
tcp:
2023-06-16 23:26:07 +02:00
dport: [22, 240..242]
2023-04-16 23:11:54 +02:00
verdict: accept
2023-06-17 00:19:19 +02:00
2023-04-16 23:11:54 +02:00
- src: backbone
protocols:
ospf: true
vrrp: true
tcp:
2023-06-16 23:26:07 +02:00
dport: [179]
2023-04-16 23:11:54 +02:00
verdict: accept
2023-06-17 00:19:19 +02:00
2023-04-16 23:11:54 +02:00
- protocols:
icmp: true
verdict: accept
2023-06-17 00:19:19 +02:00
2023-04-16 23:11:54 +02:00
output:
- verdict: accept
2023-06-17 00:19:19 +02:00
2023-04-16 23:11:54 +02:00
forward:
- src: interco-crans
verdict: accept
2023-06-17 00:19:19 +02:00
2023-04-16 23:11:54 +02:00
- src: users-internet-allowed
protocols:
tcp:
2023-06-16 23:26:07 +02:00
dport: [25]
2023-04-16 23:11:54 +02:00
verdict: drop
2023-06-17 00:19:19 +02:00
2023-04-16 23:11:54 +02:00
- src: users-internet-allowed
dest:
2023-06-17 00:19:19 +02:00
addrs: [10.0.0.1]
zones: [internet]
2023-04-16 23:11:54 +02:00
verdict: accept
nat:
2023-06-17 00:19:19 +02:00
- src:
zones: [mgmt]
2023-04-16 23:11:54 +02:00
snat:
addr: 45.66.108.14
persistent: true
...