This commit is contained in:
sevan 2019-09-21 23:55:01 +00:00
parent 34b316756b
commit 6a10ef685a

View File

@ -1,4 +1,4 @@
# $NetBSD: soho_gw-npf.conf,v 1.16 2019/09/21 21:10:56 sevan Exp $
# $NetBSD: soho_gw-npf.conf,v 1.17 2019/09/21 23:55:01 sevan Exp $
#
# SOHO border
#
@ -42,14 +42,14 @@ group "external" on $ext_if {
# Block inbound traffic from those on the block table
block in from <block>
# Allow SSH on wired interface and log all connection attempts
# Allow inbound SSH and log all connection attempts
pass stateful in family inet4 proto tcp to $ext_v4 port ssh \
apply "log"
# Allow inbound traffic for services hosted on TCP
pass stateful in proto tcp to $ext_addrs port $services_tcp
# Allow inbound traffic for services hosted on TCP
# Allow inbound traffic for services hosted on UDP
pass stateful in proto udp to $ext_addrs port $services_udp
# Passive FTP