# $OpenBSD: pf.conf,v 1.38 2009/02/23 01:18:36 deraadt Exp $
#
# See pf.conf(5) for syntax and examples; this sample ruleset uses
# require-order to permit mixing of NAT/RDR and filter rules.
# Remember to set net.inet.ip.forwarding=1 and/or net.inet6.ip6.forwarding=1
# in /etc/sysctl.conf if packets are to be forwarded between interfaces.
#======================================================================
# MACROS
#======================================================================
# macros for interfaces
ext_if="fxp0"
lan_if="re0"
darknet_if="tun0"
# netowrks
lan_net="re0:network"
# macros for ips
moria="10.0.1.100"
isengard="10.0.1.175"
mordor="10.0.1.170"
pinhole="10.0.1.20"
# macros for ports
#======================================================================
# OPTIONS
#======================================================================
# skip loopback
set skip on { lo }
#set require-order no
#set block-policy return
#======================================================================
# SCRUB/NAT/RDR
#======================================================================
#scrub in all
nat on $ext_if inet from ($lan_net) to ! 50.0.0.0/8 -> ($ext_if:0)
nat on $darknet_if inet from ($lan_net) to 50.0.0.0/8 -> ($darknet_if:0)
# fix for reflection
#no nat on $lan_if proto tcp from $lan_if to $lan_net
# Squid transparent proxy
rdr on $lan_if inet proto tcp from any to any port www -> $lan_if port 3128
# HOST isengard
# utorrent, battle.net, hamachi
isengard_ports="{ 51222, 6112, 51333 }"
rdr pass on $ext_if proto { tcp, udp } from any to $ext_if port $isengard_ports -> $isengard
#wtf am i forwarding icmp for
#rdr pass on $ext_if proto { icmp } from any to $ext_if -> $isengard
# vnc
rdr pass on $ext_if proto tcp from any to $ext_if port { 5800, 5900 } -> $isengard
# HOST mordor
# apache, ssh
mordor_ports="{ 22, 80, 8080 }"
rdr pass on $ext_if proto tcp from any to $ext_if port $mordor_ports -> $mordor
# HOST moria
# ftp
moria_ports="{ ftp, 60400:60410 }"
rdr pass on $ext_if proto tcp from any to any port $moria_ports -> $moria
#======================================================================
# RULES
#======================================================================
# basic stuff
# allow all lan traffic.
pass quick on $lan_if inet from $lan_net to $lan_net
# block multicast packets and dont log it so pflog isnt full of this shit
block drop quick to 224.0.0.0/4
block drop in log on $ext_if
block drop in on $darknet_if
# enable this rule if we need logging
#block in log on $ext_if
pass out on $ext_if all
pass in inet proto icmp icmp-type echoreq