aboutsummaryrefslogtreecommitdiffstats
path: root/dmvpn-hub.awall
diff options
context:
space:
mode:
authorKaarle Ritvanen <kaarle.ritvanen@datakunkku.fi>2018-09-05 16:43:10 +0300
committerKaarle Ritvanen <kaarle.ritvanen@datakunkku.fi>2018-09-05 17:33:42 +0300
commit866b4ac69bca08d8b1fd0f1970933ce6e240d29b (patch)
treed340d2f10cfd4e228ba9a91b90a0010c469cefc0 /dmvpn-hub.awall
parent265aaf936458d4732e0fc10ba558a36129239a9a (diff)
downloaddmvpn-tools-866b4ac69bca08d8b1fd0f1970933ce6e240d29b.tar.bz2
dmvpn-tools-866b4ac69bca08d8b1fd0f1970933ce6e240d29b.tar.xz
setup-dmvpn: configure spoke firewall if active
Diffstat (limited to 'dmvpn-hub.awall')
-rw-r--r--dmvpn-hub.awall25
1 files changed, 3 insertions, 22 deletions
diff --git a/dmvpn-hub.awall b/dmvpn-hub.awall
index 067230e..7d9f8ef 100644
--- a/dmvpn-hub.awall
+++ b/dmvpn-hub.awall
@@ -1,12 +1,6 @@
{
- "zone": {
- "dmvpn-ipsec": { "addr": "0.0.0.0/0" },
- "dmvpn-gre": { "addr": "0.0.0.0/0", "ipsec": true },
- "dmvpn-bgp": {
- "iface": "$dmvpn_gre_iface", "addr": "0.0.0.0/0"
- },
- "dmvpn": { "iface": "$dmvpn_gre_iface", "route-back": true }
- },
+ "description": "DMVPN hub",
+ "import": "dmvpn",
"log": {
"dmvpn": {
"mode": "nflog",
@@ -19,18 +13,5 @@
}
}
},
- "packet-log": [ { "in": "dmvpn", "out": "dmvpn", "log": "dmvpn" } ],
- "filter": [
- {
- "in": "_fw",
- "service": [ "dns", "http", "https", "ldap", "ldaps" ]
- },
- { "in": "dmvpn-ipsec", "out": "_fw", "service": "ipsec" },
- { "in": "_fw", "out": "dmvpn-ipsec", "service": "ipsec" },
- { "in": "dmvpn-gre", "out": "_fw", "service": "gre" },
- { "in": "_fw", "out": "dmvpn-gre", "service": "gre" },
- { "in": "dmvpn-bgp", "out": "_fw", "service": "bgp" },
- { "in": "_fw", "out": "dmvpn-bgp", "service": "bgp" },
- { "in": "dmvpn", "out": "dmvpn" }
- ]
+ "packet-log": [ { "in": "dmvpn", "out": "dmvpn", "log": "dmvpn" } ]
}