update default firewalls to support ipv6 by default

This commit is contained in:
Christer Edwards
2025-07-20 18:39:17 -06:00
parent bdcf921c1d
commit 5e79dcb1d2
3 changed files with 3 additions and 3 deletions

View File

@@ -69,7 +69,7 @@ them through the external interface:
pass out
pass in proto tcp to port {22}
pass in inet proto icmp icmp-type { echoreq }
pass in proto icmp icmp-type { echoreq }
pass in on $bridge_if
Restart the host and make sure everything comes up correctly. You should see the

View File

@@ -469,7 +469,7 @@ Create the firewall rules:
block in all
pass out quick keep state
antispoof for $ext_if inet
pass in inet proto tcp from any to any port ssh flags S/SA modulate state
pass in proto tcp from any to any port ssh flags S/SA modulate state
- Make sure to change the ``ext_if`` variable to match your host system
interface.

View File

@@ -277,7 +277,7 @@ rdr-anchor "rdr/*"
block in all
pass out quick keep state
antispoof for \$ext_if inet
pass in inet proto tcp from any to any port ssh flags S/SA keep state
pass in proto tcp from any to any port ssh flags S/SA keep state
EOF
sysrc pf_enable=YES
warn "pf ruleset created, please review ${bastille_pf_conf} and enable it using 'service pf start'."