config 914 B

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748
  1. eth0=enp5s0
  2. wan=enp1s0
  3. locnet=192.168.1.0/24
  4. lanip=192.168.1.1
  5. lanbro=192.168.1.255
  6. ## badips.com ##
  7. # ipset name
  8. banset=badips
  9. # set size, default 65536
  10. badmaxelems=131072
  11. # 0 - 5 , 0 will ban max
  12. banlevel=0
  13. # ban time in seconds, 1 week = 604800, 1 day = 86400
  14. banttl=604800
  15. # h,d,w,m,y
  16. rangecheck=1h
  17. # ssh,http... or any
  18. banservice=any
  19. ## whitenets ##
  20. #ipset name
  21. whiteset=goodips
  22. # set size, default 65536
  23. whitemaxelems=65536
  24. # default ttl
  25. whitettl=172800
  26. ## scannets ##
  27. #ipset name
  28. scanset=scanips
  29. # set size, default 65536
  30. scanmaxelems=65536
  31. # default ttl
  32. scanttl=172800
  33. ## DEBUG ##
  34. loginput=true
  35. logforward=true
  36. debugtcp=true
  37. debugudp=true
  38. debugicmp=true
  39. ## default hook order ##
  40. # hooks="set_defaults setup_whitenets setup_nat setup_forward setup_base setup_badips setup_white setup_public setup_scanips setup_cast setup_final"
  41. ## Default iptables invocation command ##
  42. #IPTABLESCMD="iptables -w"