|
|
@ -20,13 +20,13 @@ table inet firewall { |
|
|
|
set dns { |
|
|
|
type ipv4_addr |
|
|
|
flags interval |
|
|
|
elements = { 193.48.225.248, 193.48.225.204 } |
|
|
|
elements = { 193.48.225.248, 193.48.225.204, 193.48.225.213, 193.48.225.29 } |
|
|
|
} |
|
|
|
|
|
|
|
set www { |
|
|
|
type ipv4_addr |
|
|
|
flags interval |
|
|
|
elements = { 193.48.225.241, 193.48.225.242, 193.48.225.243, 193.48.225.247, 193.48.225.200, 193.48.225.3, 193.48.225.203, 193.48.225.208 } |
|
|
|
elements = { 193.48.225.241, 193.48.225.242, 193.48.225.243, 193.48.225.247, 193.48.225.200, 193.48.225.3, 193.48.225.32, 193.48.225.34, 193.48.225.225, 193.48.225.25, 193.48.225.36, 193.48.225.42, 193.48.225.60, 193.48.225.61, 193.48.225.62, 193.48.225.63, 193.48.225.45, 193.48.225.20} |
|
|
|
} |
|
|
|
|
|
|
|
set irc { |
|
|
@ -44,13 +44,13 @@ table inet firewall { |
|
|
|
set smtp { |
|
|
|
type ipv4_addr |
|
|
|
flags interval |
|
|
|
elements = { 193.48.225.249, 193.48.225.245, 193.48.225.200 , 193.48.225.207} |
|
|
|
elements = { 193.48.225.207, 193.48.225.37 } |
|
|
|
} |
|
|
|
|
|
|
|
set letsencrypt { |
|
|
|
type ipv4_addr |
|
|
|
flags interval |
|
|
|
elements = {193.48.225.246, 193.48.225.248, 193.48.225.249} |
|
|
|
elements = {193.48.225.246, 193.48.225.248, 193.48.225.249, 193.48.225.20} |
|
|
|
} |
|
|
|
|
|
|
|
set federez { |
|
|
@ -108,8 +108,26 @@ table inet firewall { |
|
|
|
|
|
|
|
} |
|
|
|
|
|
|
|
set wireguard { |
|
|
|
type ipv4_addr |
|
|
|
flags interval |
|
|
|
elements = { 193.48.225.209 } |
|
|
|
} |
|
|
|
|
|
|
|
set radius { |
|
|
|
type ipv4_addr |
|
|
|
flags interval |
|
|
|
elements = { 193.48.225.20 } |
|
|
|
} |
|
|
|
|
|
|
|
set dns_recursif { |
|
|
|
type ipv4_addr |
|
|
|
flags interval |
|
|
|
elements = { 193.48.225.30 } |
|
|
|
} |
|
|
|
|
|
|
|
chain to_dmz { |
|
|
|
ip saddr 10.7.0.0/16 accept |
|
|
|
ip saddr 10.70.0.0/16 accept |
|
|
|
|
|
|
|
ip daddr @smtp tcp dport { 22, 25, 80, 443, 143, 993, 587} accept |
|
|
|
ip daddr @dns tcp dport { 22, 53 } accept |
|
|
@ -125,15 +143,19 @@ table inet firewall { |
|
|
|
ip daddr @video tcp dport { 37700, 6754 } accept |
|
|
|
ip daddr @video udp dport { 37800 } accept |
|
|
|
ip daddr @video tcp dport { 5678 } accept |
|
|
|
ip daddr @wireguard udp dport { 51820 } accept |
|
|
|
ip saddr $monitoring udp dport { 161 } accept |
|
|
|
|
|
|
|
|
|
|
|
ip daddr @minecraft tcp dport { 22, 25565 } accept |
|
|
|
ip daddr @minecraft udp dport { 22, 25565 } accept |
|
|
|
ip daddr @latoilescoute udp dport { 22, 161, 16384-32768 } accept |
|
|
|
ip daddr @latoilescoute tcp dport { 22 } accept |
|
|
|
ip saddr @ldap_clients ip daddr @ldap tcp dport { 389, 636 } accept |
|
|
|
ip saddr @ldap_clients ip daddr @ldap udp dport { 636 } accept |
|
|
|
|
|
|
|
|
|
|
|
ip daddr @radius udp dport { 1812, 1814 } accept |
|
|
|
ip daddr @dns_recursif udp dport { 53, 853, 443 } accept |
|
|
|
ip daddr @dns_recursif tcp dport { 53, 853, 443 } accept |
|
|
|
drop |
|
|
|
} |
|
|
|
|
|
|
|