1 # Example VM firewall configuration
3 # VM specific firewall options
6 # disable/enable the whole thing
9 # disable/enable MAC address filter
16 # log dropped incoming connection
19 # disable log for outgoing connections
28 # specify nfqueue queues (optionnal)
32 [IPSET ipfilter-net0] # only allow specified IPs on net0
37 #TYPE ACTION [OPTIONS]
42 # -dport <DESTINATION_PORT>
43 # -sport <SOURCE_PORT>
45 IN SSH(ACCEPT) -i net0
46 IN SSH(ACCEPT) -i net0 # a comment
47 IN SSH(ACCEPT) -i net0 -source 192.168.2.192 # only allow SSH from 192.168.2.192
48 IN SSH(ACCEPT) -i net0 -source 10.0.0.1-10.0.0.10 #accept SSH for ip in range 10.0.0.1 to 10.0.0.10
49 IN SSH(ACCEPT) -i net0 -source 10.0.0.1,10.0.0.2,10.0.0.3 #accept ssh for 10.0.0.1 or 10.0.0.2 or 10.0.0.3
50 IN SSH(ACCEPT) -i net0 -source +mynetgroup #accept ssh for ipset mynetgroup
51 IN SSH(ACCEPT) -i net0 -source myserveralias #accept ssh for alias myserveralias
52 IN SSH(ACCEPT) -i net0 -source FE80:0000:0000:0000:0202:B3FF:FE1E:8329
53 IN ACCEPT -i net0 -p icmpv6
55 |IN SSH(ACCEPT) -i net0 # disabled rule
57 # add a security group
60 OUT DNS(ACCEPT) -i net0
61 OUT Ping(ACCEPT) -i net0