mirror of
https://github.com/fwbuilder/fwbuilder
synced 2025-10-16 15:38:43 +02:00
compiler for PF does not need to generate protocol match "proto {tcp udp icmp}" when service object used in the NAT rule is "any". The reason this was done this way is lost in the mist of time; it's been like this since very early versions of fwbuilder.
37 lines
822 B
Plaintext
Executable File
37 lines
822 B
Plaintext
Executable File
#
|
|
# This is automatically generated file. DO NOT MODIFY !
|
|
#
|
|
# Firewall Builder fwb_pf v5.0.0.3551
|
|
#
|
|
# Generated Wed Jun 22 10:50:27 2011 PDT by vadim
|
|
#
|
|
# files: * pf_cluster_4_rc.conf.local /etc/pf_cluster_4_rc.conf.local
|
|
# files: pf_cluster_4_pf.conf /etc/pf_cluster_4_pf.conf
|
|
#
|
|
# Compiled for pf
|
|
#
|
|
|
|
|
|
|
|
gateway_enable="YES"
|
|
|
|
|
|
|
|
cloned_interfaces="carp0 carp1"
|
|
network_interfaces="carp0 carp1 en0 en1"
|
|
pfsync_syncdev="en0"
|
|
pfsync_syncpeer="172.24.0.2"
|
|
ifconfig_en0="172.24.0.3 netmask 0xffffff00"
|
|
ifconfig_en1="192.168.1.3 netmask 0xffffff00"
|
|
ifconfig_carp0="vhid 101 pass secret advskew 10"
|
|
ifconfig_carp0="172.24.0.1 netmask 0xffffff00"
|
|
ifconfig_carp1="vhid 100 pass secret advskew 10"
|
|
ifconfig_carp1="192.168.1.1 netmask 0xffffff00"
|
|
pfsync_enable="YES"
|
|
|
|
pf_enable="YES"
|
|
pf_rules="/etc/pf_cluster_4_pf.conf"
|
|
|
|
|
|
|