config 885 B

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364
  1. # vim: syntax=sh
  2. eth0=enp5s0
  3. wan=enp1s0
  4. locnet=192.168.1.0/24
  5. lanip=192.168.1.1
  6. lanbro=192.168.1.255
  7. ## badips.com ##
  8. # ipset name
  9. banset=badips
  10. # set size, default 65536
  11. badmaxelems=131072
  12. # 0 - 5 , 0 will ban max
  13. banlevel=0
  14. # ban time in seconds, 1 week = 604800, 1 day = 86400
  15. banttl=604800
  16. # h,d,w,m,y
  17. rangecheck=2h
  18. # ssh,http... or any
  19. banservice=any
  20. ## whitenets ##
  21. #ipset name
  22. whiteset=goodips
  23. # set size, default 65536
  24. whitemaxelems=65536
  25. # default ttl
  26. whitettl=172800
  27. ## scannets ##
  28. #ipset name
  29. scanset=scanips
  30. # set size, default 65536
  31. scanmaxelems=65536
  32. # default ttl
  33. scanttl=172800
  34. ## DEBUG ##
  35. loginput=true
  36. logforward=true
  37. logbad=true
  38. logscan=true
  39. logcast=true
  40. debugtcp=true
  41. debugudp=true
  42. debugicmp=true
  43. ## default hook order ##
  44. hooks=(
  45. base
  46. cast
  47. lan
  48. whitenets
  49. forward
  50. public
  51. badips
  52. white
  53. scanips
  54. final
  55. )
  56. ## iptables invocation command ##
  57. iptables="iptables -w"