vyos:firewall
Различия
Показаны различия между двумя версиями страницы.
Предыдущая версия справа и слеваПредыдущая версияСледующая версия | Предыдущая версия | ||
vyos:firewall [2025/03/09 20:19] – admin | vyos:firewall [2025/03/13 20:04] (текущий) – admin | ||
---|---|---|---|
Строка 1: | Строка 1: | ||
+ | ===== Общие сведения о FW ===== | ||
**Для нормального функционирования системы, | **Для нормального функционирования системы, | ||
- | *Минимальный набор правил для работы нормально закрытого FW: | ||
- | |||
- | < | ||
- | set firewall group address-group trust address ' | ||
- | set firewall group address-group localnet include ' | ||
- | set firewall group address-group trust include ' | ||
- | set firewall ipv4 input filter default-action ' | ||
- | set firewall ipv4 input filter rule 1 action ' | ||
- | set firewall ipv4 input filter rule 1 state ' | ||
- | set firewall ipv4 input filter rule 1 state ' | ||
- | set firewall ipv4 input filter rule 2 action ' | ||
- | set firewall ipv4 input filter rule 2 source group address-group ' | ||
- | set firewall ipv4 input filter rule 1000 action ' | ||
- | set firewall ipv4 input filter rule 1000 destination address ' | ||
- | set firewall ipv4 input filter rule 1000 protocol ' | ||
- | set firewall ipv4 input filter rule 1000 source address ' | ||
- | set firewall ipv4 input filter default-action ' | ||
- | </ | ||
===== Пример настройки FW ===== | ===== Пример настройки FW ===== | ||
< | < | ||
+ | #### Input #### | ||
# | # | ||
set firewall group address-group localnet address ' | set firewall group address-group localnet address ' | ||
Строка 31: | Строка 15: | ||
set firewall ipv4 input filter default-action ' | set firewall ipv4 input filter default-action ' | ||
- | # | + | # |
set firewall ipv4 input filter rule 1 action ' | set firewall ipv4 input filter rule 1 action ' | ||
set firewall ipv4 input filter rule 1 state ' | set firewall ipv4 input filter rule 1 state ' | ||
Строка 40: | Строка 24: | ||
set firewall ipv4 input filter rule 2 source group address-group ' | set firewall ipv4 input filter rule 2 source group address-group ' | ||
- | # | + | # |
set firewall ipv4 input filter rule 3 action ' | set firewall ipv4 input filter rule 3 action ' | ||
set firewall ipv4 input filter rule 3 destination port ' | set firewall ipv4 input filter rule 3 destination port ' | ||
Строка 49: | Строка 33: | ||
set firewall ipv4 input filter rule 4 destination port ' | set firewall ipv4 input filter rule 4 destination port ' | ||
set firewall ipv4 input filter rule 4 protocol ' | set firewall ipv4 input filter rule 4 protocol ' | ||
- | |||
- | # | ||
- | set firewall ipv4 input filter rule 5 action ' | ||
- | set firewall ipv4 input filter rule 5 destination port ' | ||
- | set firewall ipv4 input filter rule 5 protocol ' | ||
- | set firewall ipv4 input filter rule 5 source group address-group ' | ||
# | # | ||
Строка 61: | Строка 39: | ||
set firewall ipv4 input filter rule 1000 protocol ' | set firewall ipv4 input filter rule 1000 protocol ' | ||
set firewall ipv4 input filter rule 1000 source address ' | set firewall ipv4 input filter rule 1000 source address ' | ||
+ | |||
+ | #### Forward #### | ||
+ | # | ||
+ | set firewall ipv4 forward filter default-action ' | ||
+ | |||
+ | # | ||
+ | set firewall ipv4 forward filter rule 1 action ' | ||
+ | set firewall ipv4 forward filter rule 1 state ' | ||
+ | set firewall ipv4 forward filter rule 1 state ' | ||
+ | |||
+ | # | ||
+ | set firewall ipv4 forward filter rule 10 action ' | ||
+ | set firewall ipv4 forward filter rule 10 source group address-group ' | ||
</ | </ |
vyos/firewall.1741551569.txt.gz · Последнее изменение: 2025/03/09 20:19 — admin