Код: Выделить всё
# Описываем интерфейсы
ext_if="re0"
int_if="vr0"
match out on $ext_if from 192.168.1.0/24 nat-to ($ext_if)
match in on $ext_if to ($ext_if) rdr-to 192.168.0.1
#block in on $int_if
# Прокидываем 25 порт снаружи на сервер внутри сети
#match in on $ext_if proto tcp to port 25 rdr-to 192.168.1.11 port 25
# Прокидываем 80 порт снаружи на сервер внутри сети
match in on $ext_if proto tcp to port 80 rdr-to 192.168.1.11 port 80
# Разрешаем машине с адресом 192.168.64.250 любые соединения
#pass in quick on $int_if from 192.168.1.11 to any
# Разрешаем любые соединения по 53 порту для подсети 192.168.64.0/24
#pass in quick on $int_if proto tcp from 192.168.1.0/24 to any port 53 keep state
#pass in quick on $int_if proto udp from 192.168.1.0/24 to any port 53 keep state
# Разрешаем компам внутри "широкой" 192.168.0.0/16 подсети обмениваться любыми пакетами
#pass in quick on $int_if from 192.168.1.0/16 to 192.168.1.0/16 keep state
#pass out quick on $int_if from 192.168.1.0/16 to 192.168.1.0/16 keep state
Код: Выделить всё
Routing tables
Internet:
Destination Gateway Flags Refs Use Mtu Prio Iface
default 84.253.86.153 GS 8 4179 - 8 re0
84.253.86.152/30 link#1 C 2 0 - 4 re0
84.253.86.153 00:0f:23:93:0f:1b HLc 1 0 - 4 re0
84.253.86.155 link#1 HLc 1 48 - 4 re0
127/8 127.0.0.1 UGRS 0 0 33200 8 lo0
127.0.0.1 127.0.0.1 UH 2 165 33200 4 lo0
192.168.1/24 link#2 UC 3 0 - 4 vr0
192.168.1.1 00:26:5a:06:2f:65 UHLc 1 56 - 4 lo0
192.168.1.11 00:1f:d0:c9:02:8f UHLc 2 238 - 4 vr0
192.168.1.255 link#2 UHLc 2 47 - 4 vr0
192.168.2/24 link#3 C 1 0 - 4 vr1
192.168.2.255 link#3 HLc 2 47 - 4 vr1
224/4 127.0.0.1 URS 0 0 33200 8 lo0
Internet6:
Destination Gateway Flags Refs Use Mtu Prio Iface
::/104 ::1 UGRS 0 0 - 8 lo0
::/96 ::1 UGRS 0 0 - 8 lo0
::1 ::1 UH 14 0 33200 4 lo0
::127.0.0.0/104 ::1 UGRS 0 0 - 8 lo0
::224.0.0.0/100 ::1 UGRS 0 0 - 8 lo0
::255.0.0.0/104 ::1 UGRS 0 0 - 8 lo0
::ffff:0.0.0.0/96 ::1 UGRS 0 0 - 8 lo0
2002::/24 ::1 UGRS 0 0 - 8 lo0
2002:7f00::/24 ::1 UGRS 0 0 - 8 lo0
2002:e000::/20 ::1 UGRS 0 0 - 8 lo0
2002:ff00::/24 ::1 UGRS 0 0 - 8 lo0
fe80::/10 ::1 UGRS 0 0 - 8 lo0
fe80::%re0/64 link#1 C 0 0 - 4 re0
fe80::226:18ff:fed3:9c1a%re0 00:26:18:d3:9c:1a UHL 0 0 - 4 lo0
fe80::%vr0/64 link#2 UC 0 0 - 4 vr0
fe80::226:5aff:fe06:2f65%vr0 00:26:5a:06:2f:65 UHL 0 0 - 4 lo0
fe80::%vr1/64 link#3 C 0 0 - 4 vr1
fe80::226:5aff:fe06:2dee%vr1 00:26:5a:06:2d:ee HL 0 0 - 4 lo0
fe80::%lo0/64 fe80::1%lo0 U 0 0 - 4 lo0
fe80::1%lo0 link#5 UHL 0 0 - 4 lo0
fec0::/10 ::1 UGRS 0 0 - 8 lo0
ff01::/16 ::1 UGRS 0 0 - 8 lo0
ff01::%re0/32 link#1 C 0 0 - 4 re0
ff01::%vr0/32 link#2 UC 0 0 - 4 vr0
ff01::%vr1/32 link#3 C 0 0 - 4 vr1
ff01::%lo0/32 ::1 UC 0 0 - 4 lo0
ff02::/16 ::1 UGRS 0 0 - 8 lo0
ff02::%re0/32 link#1 C 0 0 - 4 re0
ff02::%vr0/32 link#2 UC 0 0 - 4 vr0
ff02::%vr1/32 link#3 C 0 0 - 4 vr1
ff02::%lo0/32 ::1 UC 0 0 - 4 lo0