config 932 B

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950
  1. # vim: syntax=sh
  2. eth0=enp5s0
  3. wan=enp1s0
  4. locnet=192.168.1.0/24
  5. lanip=192.168.1.1
  6. lanbro=192.168.1.255
  7. ## badips.com ##
  8. # ipset name
  9. banset=badips
  10. # set size, default 65536
  11. badmaxelems=131072
  12. # 0 - 5 , 0 will ban max
  13. banlevel=0
  14. # ban time in seconds, 1 week = 604800, 1 day = 86400
  15. banttl=604800
  16. # h,d,w,m,y
  17. rangecheck=1h
  18. # ssh,http... or any
  19. banservice=any
  20. ## whitenets ##
  21. #ipset name
  22. whiteset=goodips
  23. # set size, default 65536
  24. whitemaxelems=65536
  25. # default ttl
  26. whitettl=172800
  27. ## scannets ##
  28. #ipset name
  29. scanset=scanips
  30. # set size, default 65536
  31. scanmaxelems=65536
  32. # default ttl
  33. scanttl=172800
  34. ## DEBUG ##
  35. loginput=true
  36. logforward=true
  37. debugtcp=true
  38. debugudp=true
  39. debugicmp=true
  40. ## default hook order ##
  41. # hooks="set_defaults setup_whitenets setup_nat setup_forward setup_base setup_badips setup_white setup_public setup_scanips setup_cast setup_final"
  42. ## Default iptables invocation command ##
  43. #IPTABLESCMD="iptables -w"