config 1.2 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283
  1. # vim: syntax=sh
  2. eth0=enp5s0
  3. wan=enp1s0
  4. locnet=192.168.1.0/24
  5. lanip=192.168.1.1
  6. lanbro=192.168.1.255
  7. ## badips.com ##
  8. blockbad=true
  9. logbad=true
  10. # ipset name
  11. badset=badips
  12. # set size, default 65536
  13. badmax=131072
  14. # 0 - 5 , 0 will ban max
  15. badlevel=0
  16. # ban time in seconds, 1 week = 604800, 1 day = 86400
  17. badttl=604800
  18. # h,d,w,m,y
  19. badrange=2h
  20. # ssh,http... or any
  21. badservice=any
  22. ## whitenets ##
  23. whitenets=true
  24. #ipset name
  25. whitenetset=whitenets
  26. # set size, default 65536
  27. whitenetmax=65536
  28. # default ttl
  29. whitenetttl=172800
  30. ## scannets ##
  31. blockscan=true
  32. logscan=true
  33. #ipset name
  34. scanset=scanips
  35. # set size, default 65536
  36. scanmax=65536
  37. # default ttl
  38. scanttl=172800
  39. ## whitelistip ##
  40. whiteip=true
  41. unblockscan=true
  42. unblockbad=true
  43. #ipset name
  44. whiteipset=whiteips
  45. # set size, default 65536
  46. whiteipmax=65536
  47. # default ttl
  48. whiteipttl=172800
  49. ## Multicast and broadcast ##
  50. cast=true
  51. blockcast=false
  52. logcast=true
  53. ## DEBUG ##
  54. loginput=true
  55. logstrange=true
  56. logbroken=true
  57. loginvalid=true
  58. logforward=true
  59. debugtcp=true
  60. debugudp=true
  61. debugicmp=true
  62. ## default hook order ##
  63. hooks=(
  64. base
  65. cast
  66. lan
  67. public
  68. badips
  69. whitenets
  70. scanips
  71. final
  72. )
  73. ## iptables invocation command ##
  74. iptables="iptables -w"