]> git.proxmox.com Git - pve-firewall.git/blame - example/100.fw
assemble debian package
[pve-firewall.git] / example / 100.fw
CommitLineData
ec6b1100 1# Example VM firewall configuration
41b6fef1
DM
2
3[OPTIONS] # VM specific firewall options
4
5# disable/enable the whole thing
6enable: 1
7
8# disable/enable MAC address filter
9macfilter: 0
10
11# default policy
12policy-in: DROP
13policy-out: REJECT
14
178a63be
DM
15# log dropped incoming connection
16log_level_in: info
17
18# disable log for outgoing connections
19log_level_out: nolog
20
41b6fef1
DM
21# filter SMURFS
22nosmurfs: 1
23
24# filter illegal combinations of TCP flags
25tcpflags: 1
26
27# enable DHCP
28dhcp: 1
29
ec6b1100 30
ec6b1100
DM
31[IN]
32
41b6fef1
DM
33#ACTION IFACE SOURCE DEST PROTO D-PORT S-PORT
34
35SSH(ACCEPT) net0
36SSH(ACCEPT) net0 # a comment
37SSH(ACCEPT) net0 192.168.2.192 # only allow SSH from 192.168.2.192
38|SSH(ACCEPT) net0 # disbaled rule
ec6b1100
DM
39
40[OUT]
41
42
43DNS(ACCEPT) net0
44Ping(ACCEPT) net0
45SSH(ACCEPT)
46
47
48