wip firewall
This commit is contained in:
parent
23a7c9c59e
commit
618ab4f500
1 changed files with 2 additions and 3 deletions
|
@ -109,9 +109,8 @@
|
|||
|
||||
# --- Inter-VLAN Security ---
|
||||
# Block any NEW connection attempts between LAN and Management
|
||||
# Log prefix helps with debugging in `dmesg` or `journalctl -k`
|
||||
iifname "vlan20" oifname "bond0" log-prefix "DROP LAN->MGMT: " drop
|
||||
iifname "bond0" oifname "vlan20" log-prefix "DROP MGMT->LAN: " drop
|
||||
iifname "vlan20" oifname "bond0" drop
|
||||
iifname "bond0" oifname "vlan20" drop
|
||||
|
||||
# Explicitly allow LAN and Management to go to the WAN
|
||||
oifname "vlan10" accept
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue