wip firewall
This commit is contained in:
parent
23a7c9c59e
commit
618ab4f500
1 changed files with 2 additions and 3 deletions
|
@ -109,9 +109,8 @@
|
||||||
|
|
||||||
# --- Inter-VLAN Security ---
|
# --- Inter-VLAN Security ---
|
||||||
# Block any NEW connection attempts between LAN and Management
|
# Block any NEW connection attempts between LAN and Management
|
||||||
# Log prefix helps with debugging in `dmesg` or `journalctl -k`
|
iifname "vlan20" oifname "bond0" drop
|
||||||
iifname "vlan20" oifname "bond0" log-prefix "DROP LAN->MGMT: " drop
|
iifname "bond0" oifname "vlan20" drop
|
||||||
iifname "bond0" oifname "vlan20" log-prefix "DROP MGMT->LAN: " drop
|
|
||||||
|
|
||||||
# Explicitly allow LAN and Management to go to the WAN
|
# Explicitly allow LAN and Management to go to the WAN
|
||||||
oifname "vlan10" accept
|
oifname "vlan10" accept
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue