]> git.proxmox.com Git - pve-firewall.git/blame_incremental - debian/example/cluster.fw
remove optimize option
[pve-firewall.git] / debian / example / cluster.fw
... / ...
CommitLineData
1[OPTIONS]
2
3# enable firewall (cluster wide setting, default is disabled)
4enable: 1
5
6# default policy for host rules
7policy_in: DROP
8policy_out: ACCEPT
9
10[ALIASES]
11
12myserveralias 10.0.0.111
13mynetworkalias 10.0.0.0/24
14
15[RULES]
16
17IN SSH(ACCEPT) vmbr0
18
19[group group1]
20
21IN ACCEPT - - tcp 22 -
22OUT ACCEPT - - tcp 80 -
23OUT ACCEPT - - icmp - -
24
25[group group3]
26
27IN ACCEPT 10.0.0.1
28IN ACCEPT 10.0.0.1-10.0.0.10
29IN ACCEPT 10.0.0.1,10.0.0.2,10.0.0.3
30IN ACCEPT +mynetgroup
31IN ACCEPT myserveralias
32
33
34[ipset myipset]
35
36192.168.0.1 #mycomment
37172.16.0.10
38192.168.0.0/24
39! 10.0.0.0/8 #nomatch - needs kernel 3.7 or newer
40mynetworkalias
41
42#global ipset blacklist
43[ipset blacklist]
44
4510.0.0.8
46192.168.0./24