config 923 B

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263
  1. # vim: syntax=sh
  2. eth0=enp5s0
  3. wan=enp1s0
  4. locnet=192.168.1.0/24
  5. lanip=192.168.1.1
  6. lanbro=192.168.1.255
  7. ## badips.com ##
  8. # ipset name
  9. banset=badips
  10. # set size, default 65536
  11. badmaxelems=131072
  12. # 0 - 5 , 0 will ban max
  13. banlevel=0
  14. # ban time in seconds, 1 week = 604800, 1 day = 86400
  15. banttl=604800
  16. # h,d,w,m,y
  17. rangecheck=1h
  18. # ssh,http... or any
  19. banservice=any
  20. ## whitenets ##
  21. #ipset name
  22. whiteset=goodips
  23. # set size, default 65536
  24. whitemaxelems=65536
  25. # default ttl
  26. whitettl=172800
  27. ## scannets ##
  28. #ipset name
  29. scanset=scanips
  30. # set size, default 65536
  31. scanmaxelems=65536
  32. # default ttl
  33. scanttl=172800
  34. ## DEBUG ##
  35. loginput=true
  36. logforward=true
  37. debugtcp=true
  38. debugudp=true
  39. debugicmp=true
  40. ## default hook order ##
  41. hooks=(
  42. base
  43. lan
  44. setup_wandroplog
  45. setup_fordroplog
  46. setup_whitenets
  47. setup_forward
  48. setup_badips
  49. setup_white
  50. setup_public
  51. setup_scanips
  52. setup_cast
  53. final
  54. )
  55. ## iptables invocation command ##
  56. iptables="iptables -w"