]> git.proxmox.com Git - pve-firewall.git/blame - example/100.fw
implement log level options
[pve-firewall.git] / example / 100.fw
CommitLineData
ec6b1100 1# Example VM firewall configuration
41b6fef1
DM
2
3[OPTIONS] # VM specific firewall options
4
5# disable/enable the whole thing
6enable: 1
7
8# disable/enable MAC address filter
9macfilter: 0
10
11# default policy
12policy-in: DROP
13policy-out: REJECT
14
15# filter SMURFS
16nosmurfs: 1
17
18# filter illegal combinations of TCP flags
19tcpflags: 1
20
21# enable DHCP
22dhcp: 1
23
ec6b1100 24
ec6b1100
DM
25[IN]
26
41b6fef1
DM
27#ACTION IFACE SOURCE DEST PROTO D-PORT S-PORT
28
29SSH(ACCEPT) net0
30SSH(ACCEPT) net0 # a comment
31SSH(ACCEPT) net0 192.168.2.192 # only allow SSH from 192.168.2.192
32|SSH(ACCEPT) net0 # disbaled rule
ec6b1100
DM
33
34[OUT]
35
36
37DNS(ACCEPT) net0
38Ping(ACCEPT) net0
39SSH(ACCEPT)
40
41
42