1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
|
set firewall global-options all-ping 'enable'
set firewall global-options broadcast-ping 'disable'
set firewall global-options ip-src-route 'disable'
set firewall global-options ipv6-receive-redirects 'disable'
set firewall global-options ipv6-src-route 'disable'
set firewall global-options log-martians 'enable'
set firewall global-options receive-redirects 'disable'
set firewall global-options send-redirects 'enable'
set firewall global-options source-validation 'disable'
set firewall global-options syn-cookies 'enable'
set firewall global-options timeout icmp '30'
set firewall global-options timeout other '600'
set firewall global-options timeout udp other '300'
set firewall global-options timeout udp stream '300'
set firewall global-options twa-hazards-protection 'disable'
set firewall group address-group DMZ-RDP-SERVER address '172.16.33.40'
set firewall group address-group DMZ-RDP-SERVER description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall group address-group DMZ-WEBSERVER address '172.16.36.10'
set firewall group address-group DMZ-WEBSERVER address '172.16.36.40'
set firewall group address-group DMZ-WEBSERVER address '172.16.36.20'
set firewall group address-group DMZ-WEBSERVER description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall group address-group DOMAIN-CONTROLLER address '172.16.100.10'
set firewall group address-group DOMAIN-CONTROLLER address '172.16.100.20'
set firewall group address-group DOMAIN-CONTROLLER address '172.16.110.30'
set firewall group address-group VIDEO address '172.16.33.211'
set firewall group address-group VIDEO address '172.16.33.212'
set firewall group address-group VIDEO address '172.16.33.213'
set firewall group address-group VIDEO address '172.16.33.214'
set firewall group ipv6-network-group LOCAL-ADDRESSES network 'ff02::/64'
set firewall group ipv6-network-group LOCAL-ADDRESSES network 'fe80::/10'
set firewall group network-group SSH-IN-ALLOW network '100.65.150.0/23'
set firewall group network-group SSH-IN-ALLOW network '100.64.69.205/32'
set firewall group network-group SSH-IN-ALLOW network '100.64.8.67/32'
set firewall group network-group SSH-IN-ALLOW network '100.64.55.1/32'
set firewall ipv4 name DMZ-GUEST default-action 'drop'
set firewall ipv4 name DMZ-GUEST default-log
set firewall ipv4 name DMZ-GUEST rule 1 action 'return'
set firewall ipv4 name DMZ-GUEST rule 1 state 'established'
set firewall ipv4 name DMZ-GUEST rule 1 state 'related'
set firewall ipv4 name DMZ-GUEST rule 2 action 'drop'
set firewall ipv4 name DMZ-GUEST rule 2 log
set firewall ipv4 name DMZ-GUEST rule 2 state 'invalid'
set firewall ipv4 name DMZ-LAN default-action 'drop'
set firewall ipv4 name DMZ-LAN default-log
set firewall ipv4 name DMZ-LAN description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv4 name DMZ-LAN rule 1 action 'return'
set firewall ipv4 name DMZ-LAN rule 1 description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv4 name DMZ-LAN rule 1 state 'established'
set firewall ipv4 name DMZ-LAN rule 1 state 'related'
set firewall ipv4 name DMZ-LAN rule 2 action 'drop'
set firewall ipv4 name DMZ-LAN rule 2 description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv4 name DMZ-LAN rule 2 log
set firewall ipv4 name DMZ-LAN rule 2 state 'invalid'
set firewall ipv4 name DMZ-LAN rule 100 action 'return'
set firewall ipv4 name DMZ-LAN rule 100 description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv4 name DMZ-LAN rule 100 destination group address-group 'DOMAIN-CONTROLLER'
set firewall ipv4 name DMZ-LAN rule 100 destination port '123,389,636'
set firewall ipv4 name DMZ-LAN rule 100 protocol 'tcp_udp'
set firewall ipv4 name DMZ-LAN rule 300 action 'return'
set firewall ipv4 name DMZ-LAN rule 300 description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv4 name DMZ-LAN rule 300 destination group address-group 'DMZ-RDP-SERVER'
set firewall ipv4 name DMZ-LAN rule 300 destination port '3389'
set firewall ipv4 name DMZ-LAN rule 300 protocol 'tcp_udp'
set firewall ipv4 name DMZ-LAN rule 300 source address '172.16.36.20'
set firewall ipv4 name DMZ-LOCAL default-action 'drop'
set firewall ipv4 name DMZ-LOCAL default-log
set firewall ipv4 name DMZ-LOCAL description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv4 name DMZ-LOCAL rule 1 action 'return'
set firewall ipv4 name DMZ-LOCAL rule 1 state 'established'
set firewall ipv4 name DMZ-LOCAL rule 1 state 'related'
set firewall ipv4 name DMZ-LOCAL rule 2 action 'drop'
set firewall ipv4 name DMZ-LOCAL rule 2 log
set firewall ipv4 name DMZ-LOCAL rule 2 state 'invalid'
set firewall ipv4 name DMZ-LOCAL rule 50 action 'return'
set firewall ipv4 name DMZ-LOCAL rule 50 description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv4 name DMZ-LOCAL rule 50 destination address '172.16.254.30'
set firewall ipv4 name DMZ-LOCAL rule 50 destination port '53'
set firewall ipv4 name DMZ-LOCAL rule 50 protocol 'tcp_udp'
set firewall ipv4 name DMZ-LOCAL rule 123 action 'return'
set firewall ipv4 name DMZ-LOCAL rule 123 destination port '123'
set firewall ipv4 name DMZ-LOCAL rule 123 protocol 'udp'
set firewall ipv4 name DMZ-WAN default-action 'return'
set firewall ipv4 name DMZ-WAN description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv4 name GUEST-DMZ default-action 'drop'
set firewall ipv4 name GUEST-DMZ default-log
set firewall ipv4 name GUEST-DMZ rule 1 action 'return'
set firewall ipv4 name GUEST-DMZ rule 1 state 'established'
set firewall ipv4 name GUEST-DMZ rule 1 state 'related'
set firewall ipv4 name GUEST-DMZ rule 2 action 'drop'
set firewall ipv4 name GUEST-DMZ rule 2 log
set firewall ipv4 name GUEST-DMZ rule 2 state 'invalid'
set firewall ipv4 name GUEST-LAN default-action 'drop'
set firewall ipv4 name GUEST-LAN default-log
set firewall ipv4 name GUEST-LAN rule 1 action 'return'
set firewall ipv4 name GUEST-LAN rule 1 state 'established'
set firewall ipv4 name GUEST-LAN rule 1 state 'related'
set firewall ipv4 name GUEST-LAN rule 2 action 'drop'
set firewall ipv4 name GUEST-LAN rule 2 log
set firewall ipv4 name GUEST-LAN rule 2 state 'invalid'
set firewall ipv4 name GUEST-LOCAL default-action 'drop'
set firewall ipv4 name GUEST-LOCAL default-log
set firewall ipv4 name GUEST-LOCAL rule 1 action 'return'
set firewall ipv4 name GUEST-LOCAL rule 1 state 'established'
set firewall ipv4 name GUEST-LOCAL rule 1 state 'related'
set firewall ipv4 name GUEST-LOCAL rule 2 action 'drop'
set firewall ipv4 name GUEST-LOCAL rule 2 log
set firewall ipv4 name GUEST-LOCAL rule 2 state 'invalid'
set firewall ipv4 name GUEST-LOCAL rule 10 action 'return'
set firewall ipv4 name GUEST-LOCAL rule 10 destination address '172.31.0.254'
set firewall ipv4 name GUEST-LOCAL rule 10 destination port '53'
set firewall ipv4 name GUEST-LOCAL rule 10 protocol 'tcp_udp'
set firewall ipv4 name GUEST-LOCAL rule 11 action 'return'
set firewall ipv4 name GUEST-LOCAL rule 11 destination port '67'
set firewall ipv4 name GUEST-LOCAL rule 11 protocol 'udp'
set firewall ipv4 name GUEST-LOCAL rule 15 action 'return'
set firewall ipv4 name GUEST-LOCAL rule 15 destination address '172.31.0.254'
set firewall ipv4 name GUEST-LOCAL rule 15 protocol 'icmp'
set firewall ipv4 name GUEST-LOCAL rule 100 action 'return'
set firewall ipv4 name GUEST-LOCAL rule 100 destination address '172.31.0.254'
set firewall ipv4 name GUEST-LOCAL rule 100 destination port '80,443'
set firewall ipv4 name GUEST-LOCAL rule 100 protocol 'tcp'
set firewall ipv4 name GUEST-WAN default-action 'drop'
set firewall ipv4 name GUEST-WAN default-log
set firewall ipv4 name GUEST-WAN rule 1 action 'return'
set firewall ipv4 name GUEST-WAN rule 1 state 'established'
set firewall ipv4 name GUEST-WAN rule 1 state 'related'
set firewall ipv4 name GUEST-WAN rule 2 action 'drop'
set firewall ipv4 name GUEST-WAN rule 2 log
set firewall ipv4 name GUEST-WAN rule 2 state 'invalid'
set firewall ipv4 name GUEST-WAN rule 25 action 'return'
set firewall ipv4 name GUEST-WAN rule 25 destination port '25,587'
set firewall ipv4 name GUEST-WAN rule 25 protocol 'tcp'
set firewall ipv4 name GUEST-WAN rule 53 action 'return'
set firewall ipv4 name GUEST-WAN rule 53 destination port '53'
set firewall ipv4 name GUEST-WAN rule 53 protocol 'tcp_udp'
set firewall ipv4 name GUEST-WAN rule 60 action 'return'
set firewall ipv4 name GUEST-WAN rule 60 source address '172.31.0.200'
set firewall ipv4 name GUEST-WAN rule 80 action 'return'
set firewall ipv4 name GUEST-WAN rule 80 source address '172.31.0.200'
set firewall ipv4 name GUEST-WAN rule 100 action 'return'
set firewall ipv4 name GUEST-WAN rule 100 protocol 'icmp'
set firewall ipv4 name GUEST-WAN rule 110 action 'return'
set firewall ipv4 name GUEST-WAN rule 110 destination port '110,995'
set firewall ipv4 name GUEST-WAN rule 110 protocol 'tcp'
set firewall ipv4 name GUEST-WAN rule 123 action 'return'
set firewall ipv4 name GUEST-WAN rule 123 destination port '123'
set firewall ipv4 name GUEST-WAN rule 123 protocol 'udp'
set firewall ipv4 name GUEST-WAN rule 143 action 'return'
set firewall ipv4 name GUEST-WAN rule 143 destination port '143,993'
set firewall ipv4 name GUEST-WAN rule 143 protocol 'tcp'
set firewall ipv4 name GUEST-WAN rule 200 action 'return'
set firewall ipv4 name GUEST-WAN rule 200 destination port '80,443'
set firewall ipv4 name GUEST-WAN rule 200 protocol 'tcp'
set firewall ipv4 name GUEST-WAN rule 500 action 'return'
set firewall ipv4 name GUEST-WAN rule 500 destination port '500,4500'
set firewall ipv4 name GUEST-WAN rule 500 protocol 'udp'
set firewall ipv4 name GUEST-WAN rule 600 action 'return'
set firewall ipv4 name GUEST-WAN rule 600 destination port '5222-5224'
set firewall ipv4 name GUEST-WAN rule 600 protocol 'tcp'
set firewall ipv4 name GUEST-WAN rule 601 action 'return'
set firewall ipv4 name GUEST-WAN rule 601 destination port '3478-3497,4500,16384-16387,16393-16402'
set firewall ipv4 name GUEST-WAN rule 601 protocol 'udp'
set firewall ipv4 name GUEST-WAN rule 1000 action 'return'
set firewall ipv4 name GUEST-WAN rule 1000 source address '172.31.0.184'
set firewall ipv4 name LAN-DMZ default-action 'drop'
set firewall ipv4 name LAN-DMZ default-log
set firewall ipv4 name LAN-DMZ rule 1 action 'return'
set firewall ipv4 name LAN-DMZ rule 1 state 'established'
set firewall ipv4 name LAN-DMZ rule 1 state 'related'
set firewall ipv4 name LAN-DMZ rule 2 action 'drop'
set firewall ipv4 name LAN-DMZ rule 2 log
set firewall ipv4 name LAN-DMZ rule 2 state 'invalid'
set firewall ipv4 name LAN-DMZ rule 22 action 'return'
set firewall ipv4 name LAN-DMZ rule 22 destination port '22'
set firewall ipv4 name LAN-DMZ rule 22 protocol 'tcp'
set firewall ipv4 name LAN-DMZ rule 100 action 'return'
set firewall ipv4 name LAN-DMZ rule 100 destination group address-group 'DMZ-WEBSERVER'
set firewall ipv4 name LAN-DMZ rule 100 destination port '22'
set firewall ipv4 name LAN-DMZ rule 100 protocol 'tcp'
set firewall ipv4 name LAN-GUEST default-action 'drop'
set firewall ipv4 name LAN-GUEST default-log
set firewall ipv4 name LAN-GUEST rule 1 action 'return'
set firewall ipv4 name LAN-GUEST rule 1 state 'established'
set firewall ipv4 name LAN-GUEST rule 1 state 'related'
set firewall ipv4 name LAN-GUEST rule 2 action 'drop'
set firewall ipv4 name LAN-GUEST rule 2 log
set firewall ipv4 name LAN-GUEST rule 2 state 'invalid'
set firewall ipv4 name LAN-LOCAL default-action 'return'
set firewall ipv4 name LAN-WAN default-action 'return'
set firewall ipv4 name LAN-WAN rule 90 action 'return'
set firewall ipv4 name LAN-WAN rule 90 destination address '100.65.150.0/23'
set firewall ipv4 name LAN-WAN rule 90 destination port '25'
set firewall ipv4 name LAN-WAN rule 90 protocol 'tcp_udp'
set firewall ipv4 name LAN-WAN rule 90 source group address-group 'VIDEO'
set firewall ipv4 name LAN-WAN rule 100 action 'drop'
set firewall ipv4 name LAN-WAN rule 100 source group address-group 'VIDEO'
set firewall ipv4 name LOCAL-DMZ default-action 'drop'
set firewall ipv4 name LOCAL-DMZ default-log
set firewall ipv4 name LOCAL-DMZ rule 1 action 'return'
set firewall ipv4 name LOCAL-DMZ rule 1 state 'established'
set firewall ipv4 name LOCAL-DMZ rule 1 state 'related'
set firewall ipv4 name LOCAL-DMZ rule 2 action 'drop'
set firewall ipv4 name LOCAL-DMZ rule 2 log
set firewall ipv4 name LOCAL-DMZ rule 2 state 'invalid'
set firewall ipv4 name LOCAL-DMZ rule 100 action 'return'
set firewall ipv4 name LOCAL-DMZ rule 100 destination address '172.16.36.40'
set firewall ipv4 name LOCAL-DMZ rule 100 destination port '80,443'
set firewall ipv4 name LOCAL-DMZ rule 100 protocol 'tcp'
set firewall ipv4 name LOCAL-GUEST default-action 'drop'
set firewall ipv4 name LOCAL-GUEST default-log
set firewall ipv4 name LOCAL-GUEST rule 1 action 'return'
set firewall ipv4 name LOCAL-GUEST rule 1 state 'established'
set firewall ipv4 name LOCAL-GUEST rule 1 state 'related'
set firewall ipv4 name LOCAL-GUEST rule 2 action 'drop'
set firewall ipv4 name LOCAL-GUEST rule 2 log
set firewall ipv4 name LOCAL-GUEST rule 2 state 'invalid'
set firewall ipv4 name LOCAL-GUEST rule 5 action 'return'
set firewall ipv4 name LOCAL-GUEST rule 5 protocol 'icmp'
set firewall ipv4 name LOCAL-GUEST rule 300 action 'return'
set firewall ipv4 name LOCAL-GUEST rule 300 destination port '1900'
set firewall ipv4 name LOCAL-GUEST rule 300 protocol 'udp'
set firewall ipv4 name LOCAL-LAN default-action 'return'
set firewall ipv4 name LOCAL-WAN default-action 'drop'
set firewall ipv4 name LOCAL-WAN default-log
set firewall ipv4 name LOCAL-WAN rule 1 action 'return'
set firewall ipv4 name LOCAL-WAN rule 1 state 'established'
set firewall ipv4 name LOCAL-WAN rule 1 state 'related'
set firewall ipv4 name LOCAL-WAN rule 2 action 'drop'
set firewall ipv4 name LOCAL-WAN rule 2 log
set firewall ipv4 name LOCAL-WAN rule 2 state 'invalid'
set firewall ipv4 name LOCAL-WAN rule 10 action 'return'
set firewall ipv4 name LOCAL-WAN rule 10 protocol 'icmp'
set firewall ipv4 name LOCAL-WAN rule 50 action 'return'
set firewall ipv4 name LOCAL-WAN rule 50 destination port '53'
set firewall ipv4 name LOCAL-WAN rule 50 protocol 'tcp_udp'
set firewall ipv4 name LOCAL-WAN rule 80 action 'return'
set firewall ipv4 name LOCAL-WAN rule 80 destination port '80,443'
set firewall ipv4 name LOCAL-WAN rule 80 protocol 'tcp'
set firewall ipv4 name LOCAL-WAN rule 123 action 'return'
set firewall ipv4 name LOCAL-WAN rule 123 destination port '123'
set firewall ipv4 name LOCAL-WAN rule 123 protocol 'udp'
set firewall ipv4 name LOCAL-WAN rule 800 action 'return'
set firewall ipv4 name LOCAL-WAN rule 800 destination address '100.65.151.213'
set firewall ipv4 name LOCAL-WAN rule 800 protocol 'udp'
set firewall ipv4 name LOCAL-WAN rule 805 action 'return'
set firewall ipv4 name LOCAL-WAN rule 805 destination address '100.65.151.2'
set firewall ipv4 name LOCAL-WAN rule 805 protocol 'all'
set firewall ipv4 name LOCAL-WAN rule 1010 action 'return'
set firewall ipv4 name LOCAL-WAN rule 1010 destination address '100.64.69.205'
set firewall ipv4 name LOCAL-WAN rule 1010 destination port '7705'
set firewall ipv4 name LOCAL-WAN rule 1010 protocol 'udp'
set firewall ipv4 name LOCAL-WAN rule 1010 source port '7705'
set firewall ipv4 name LOCAL-WAN rule 1990 action 'return'
set firewall ipv4 name LOCAL-WAN rule 1990 destination address '100.64.55.1'
set firewall ipv4 name LOCAL-WAN rule 1990 destination port '10666'
set firewall ipv4 name LOCAL-WAN rule 1990 protocol 'udp'
set firewall ipv4 name LOCAL-WAN rule 2000 action 'return'
set firewall ipv4 name LOCAL-WAN rule 2000 destination address '100.64.39.249'
set firewall ipv4 name LOCAL-WAN rule 10200 action 'return'
set firewall ipv4 name LOCAL-WAN rule 10200 destination address '100.64.89.98'
set firewall ipv4 name LOCAL-WAN rule 10200 destination port '10200'
set firewall ipv4 name LOCAL-WAN rule 10200 protocol 'udp'
set firewall ipv4 name LOCAL-WAN rule 10200 source port '10200'
set firewall ipv4 name WAN-DMZ default-action 'drop'
set firewall ipv4 name WAN-DMZ default-log
set firewall ipv4 name WAN-DMZ rule 1 action 'return'
set firewall ipv4 name WAN-DMZ rule 1 state 'established'
set firewall ipv4 name WAN-DMZ rule 1 state 'related'
set firewall ipv4 name WAN-DMZ rule 2 action 'drop'
set firewall ipv4 name WAN-DMZ rule 2 log
set firewall ipv4 name WAN-DMZ rule 2 state 'invalid'
set firewall ipv4 name WAN-DMZ rule 100 action 'return'
set firewall ipv4 name WAN-DMZ rule 100 destination address '172.16.36.10'
set firewall ipv4 name WAN-DMZ rule 100 destination port '80,443'
set firewall ipv4 name WAN-DMZ rule 100 protocol 'tcp'
set firewall ipv4 name WAN-GUEST default-action 'drop'
set firewall ipv4 name WAN-GUEST default-log
set firewall ipv4 name WAN-GUEST rule 1 action 'return'
set firewall ipv4 name WAN-GUEST rule 1 state 'established'
set firewall ipv4 name WAN-GUEST rule 1 state 'related'
set firewall ipv4 name WAN-GUEST rule 2 action 'drop'
set firewall ipv4 name WAN-GUEST rule 2 log
set firewall ipv4 name WAN-GUEST rule 2 state 'invalid'
set firewall ipv4 name WAN-GUEST rule 1000 action 'return'
set firewall ipv4 name WAN-GUEST rule 1000 destination address '172.31.0.184'
set firewall ipv4 name WAN-GUEST rule 8000 action 'return'
set firewall ipv4 name WAN-GUEST rule 8000 destination address '172.31.0.200'
set firewall ipv4 name WAN-GUEST rule 8000 destination port '10000'
set firewall ipv4 name WAN-GUEST rule 8000 protocol 'udp'
set firewall ipv4 name WAN-LAN default-action 'drop'
set firewall ipv4 name WAN-LAN default-log
set firewall ipv4 name WAN-LAN description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv4 name WAN-LAN rule 1 action 'return'
set firewall ipv4 name WAN-LAN rule 1 description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv4 name WAN-LAN rule 1 state 'established'
set firewall ipv4 name WAN-LAN rule 1 state 'related'
set firewall ipv4 name WAN-LAN rule 2 action 'drop'
set firewall ipv4 name WAN-LAN rule 2 log
set firewall ipv4 name WAN-LAN rule 2 state 'invalid'
set firewall ipv4 name WAN-LAN rule 1000 action 'return'
set firewall ipv4 name WAN-LAN rule 1000 destination address '172.16.33.40'
set firewall ipv4 name WAN-LAN rule 1000 destination port '3389'
set firewall ipv4 name WAN-LAN rule 1000 protocol 'tcp'
set firewall ipv4 name WAN-LAN rule 1000 source group network-group 'SSH-IN-ALLOW'
set firewall ipv4 name WAN-LOCAL default-action 'drop'
set firewall ipv4 name WAN-LOCAL rule 1 action 'return'
set firewall ipv4 name WAN-LOCAL rule 1 state 'established'
set firewall ipv4 name WAN-LOCAL rule 1 state 'related'
set firewall ipv4 name WAN-LOCAL rule 2 action 'drop'
set firewall ipv4 name WAN-LOCAL rule 2 log
set firewall ipv4 name WAN-LOCAL rule 2 state 'invalid'
set firewall ipv4 name WAN-LOCAL rule 22 action 'return'
set firewall ipv4 name WAN-LOCAL rule 22 destination port '22'
set firewall ipv4 name WAN-LOCAL rule 22 protocol 'tcp'
set firewall ipv4 name WAN-LOCAL rule 22 source group network-group 'SSH-IN-ALLOW'
set firewall ipv4 name WAN-LOCAL rule 1990 action 'return'
set firewall ipv4 name WAN-LOCAL rule 1990 destination port '10666'
set firewall ipv4 name WAN-LOCAL rule 1990 protocol 'udp'
set firewall ipv4 name WAN-LOCAL rule 1990 source address '100.64.55.1'
set firewall ipv4 name WAN-LOCAL rule 10000 action 'return'
set firewall ipv4 name WAN-LOCAL rule 10000 destination port '80,443'
set firewall ipv4 name WAN-LOCAL rule 10000 protocol 'tcp'
set firewall ipv4 name WAN-LOCAL rule 10100 action 'return'
set firewall ipv4 name WAN-LOCAL rule 10100 destination port '10100'
set firewall ipv4 name WAN-LOCAL rule 10100 protocol 'udp'
set firewall ipv4 name WAN-LOCAL rule 10100 source port '10100'
set firewall ipv4 name WAN-LOCAL rule 10200 action 'return'
set firewall ipv4 name WAN-LOCAL rule 10200 destination port '10200'
set firewall ipv4 name WAN-LOCAL rule 10200 protocol 'udp'
set firewall ipv4 name WAN-LOCAL rule 10200 source address '100.64.89.98'
set firewall ipv4 name WAN-LOCAL rule 10200 source port '10200'
set firewall ipv6 name ALLOW-ALL-6 default-action 'return'
set firewall ipv6 name ALLOW-ALL-6 description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv6 name ALLOW-BASIC-6 default-action 'drop'
set firewall ipv6 name ALLOW-BASIC-6 default-log
set firewall ipv6 name ALLOW-BASIC-6 description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv6 name ALLOW-BASIC-6 rule 1 action 'return'
set firewall ipv6 name ALLOW-BASIC-6 rule 1 description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv6 name ALLOW-BASIC-6 rule 1 state 'established'
set firewall ipv6 name ALLOW-BASIC-6 rule 1 state 'related'
set firewall ipv6 name ALLOW-BASIC-6 rule 2 action 'drop'
set firewall ipv6 name ALLOW-BASIC-6 rule 2 description 'Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata'
set firewall ipv6 name ALLOW-BASIC-6 rule 2 state 'invalid'
set firewall ipv6 name ALLOW-BASIC-6 rule 10 action 'return'
set firewall ipv6 name ALLOW-BASIC-6 rule 10 protocol 'ipv6-icmp'
set firewall ipv6 name ALLOW-ESTABLISHED-6 default-action 'drop'
set firewall ipv6 name ALLOW-ESTABLISHED-6 default-log
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 1 action 'return'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 1 state 'established'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 1 state 'related'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 2 action 'drop'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 2 state 'invalid'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 10 action 'return'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 10 destination group network-group 'LOCAL-ADDRESSES'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 10 protocol 'ipv6-icmp'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 10 source address 'fe80::/10'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 20 action 'return'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 20 icmpv6 type-name 'echo-request'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 20 protocol 'ipv6-icmp'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 21 action 'return'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 21 icmpv6 type-name 'destination-unreachable'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 21 protocol 'ipv6-icmp'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 22 action 'return'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 22 icmpv6 type-name 'packet-too-big'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 22 protocol 'ipv6-icmp'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 23 action 'return'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 23 icmpv6 type-name 'time-exceeded'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 23 protocol 'ipv6-icmp'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 24 action 'return'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 24 icmpv6 type-name 'parameter-problem'
set firewall ipv6 name ALLOW-ESTABLISHED-6 rule 24 protocol 'ipv6-icmp'
set firewall ipv6 name WAN-LOCAL-6 default-action 'drop'
set firewall ipv6 name WAN-LOCAL-6 default-log
set firewall ipv6 name WAN-LOCAL-6 rule 1 action 'return'
set firewall ipv6 name WAN-LOCAL-6 rule 1 state 'established'
set firewall ipv6 name WAN-LOCAL-6 rule 1 state 'related'
set firewall ipv6 name WAN-LOCAL-6 rule 2 action 'drop'
set firewall ipv6 name WAN-LOCAL-6 rule 2 state 'invalid'
set firewall ipv6 name WAN-LOCAL-6 rule 10 action 'return'
set firewall ipv6 name WAN-LOCAL-6 rule 10 destination address 'ff02::/64'
set firewall ipv6 name WAN-LOCAL-6 rule 10 protocol 'ipv6-icmp'
set firewall ipv6 name WAN-LOCAL-6 rule 10 source address 'fe80::/10'
set firewall ipv6 name WAN-LOCAL-6 rule 50 action 'return'
set firewall ipv6 name WAN-LOCAL-6 rule 50 destination address 'fe80::/10'
set firewall ipv6 name WAN-LOCAL-6 rule 50 destination port '546'
set firewall ipv6 name WAN-LOCAL-6 rule 50 protocol 'udp'
set firewall ipv6 name WAN-LOCAL-6 rule 50 source address 'fe80::/10'
set firewall ipv6 name WAN-LOCAL-6 rule 50 source port '547'
set firewall zone DMZ default-action 'drop'
set firewall zone DMZ from GUEST firewall name 'GUEST-DMZ'
set firewall zone DMZ from LAN firewall name 'LAN-DMZ'
set firewall zone DMZ from LOCAL firewall name 'LOCAL-DMZ'
set firewall zone DMZ from WAN firewall name 'WAN-DMZ'
set firewall zone DMZ interface 'eth0.50'
set firewall zone GUEST default-action 'drop'
set firewall zone GUEST from DMZ firewall name 'DMZ-GUEST'
set firewall zone GUEST from LAN firewall name 'LAN-GUEST'
set firewall zone GUEST from LOCAL firewall ipv6-name 'ALLOW-ALL-6'
set firewall zone GUEST from LOCAL firewall name 'LOCAL-GUEST'
set firewall zone GUEST from WAN firewall ipv6-name 'ALLOW-ESTABLISHED-6'
set firewall zone GUEST from WAN firewall name 'WAN-GUEST'
set firewall zone GUEST interface 'eth1.20'
set firewall zone LAN default-action 'drop'
set firewall zone LAN from DMZ firewall name 'DMZ-LAN'
set firewall zone LAN from GUEST firewall name 'GUEST-LAN'
set firewall zone LAN from LOCAL firewall ipv6-name 'ALLOW-ALL-6'
set firewall zone LAN from LOCAL firewall name 'LOCAL-LAN'
set firewall zone LAN from WAN firewall ipv6-name 'ALLOW-ESTABLISHED-6'
set firewall zone LAN from WAN firewall name 'WAN-LAN'
set firewall zone LAN interface 'eth0.5'
set firewall zone LAN interface 'eth0.10'
set firewall zone LAN interface 'wg100'
set firewall zone LAN interface 'wg200'
set firewall zone LOCAL default-action 'drop'
set firewall zone LOCAL from DMZ firewall name 'DMZ-LOCAL'
set firewall zone LOCAL from GUEST firewall ipv6-name 'ALLOW-ESTABLISHED-6'
set firewall zone LOCAL from GUEST firewall name 'GUEST-LOCAL'
set firewall zone LOCAL from LAN firewall ipv6-name 'ALLOW-ALL-6'
set firewall zone LOCAL from LAN firewall name 'LAN-LOCAL'
set firewall zone LOCAL from WAN firewall ipv6-name 'WAN-LOCAL-6'
set firewall zone LOCAL from WAN firewall name 'WAN-LOCAL'
set firewall zone LOCAL local-zone
set firewall zone WAN default-action 'drop'
set firewall zone WAN from DMZ firewall name 'DMZ-WAN'
set firewall zone WAN from GUEST firewall ipv6-name 'ALLOW-ALL-6'
set firewall zone WAN from GUEST firewall name 'GUEST-WAN'
set firewall zone WAN from LAN firewall ipv6-name 'ALLOW-ALL-6'
set firewall zone WAN from LAN firewall name 'LAN-WAN'
set firewall zone WAN from LOCAL firewall ipv6-name 'ALLOW-ALL-6'
set firewall zone WAN from LOCAL firewall name 'LOCAL-WAN'
set firewall zone WAN interface 'pppoe0'
set firewall zone WAN interface 'wg666'
set interfaces dummy dum0 address '172.16.254.30/32'
set interfaces ethernet eth0 duplex 'auto'
set interfaces ethernet eth0 offload gro
set interfaces ethernet eth0 ring-buffer rx '256'
set interfaces ethernet eth0 ring-buffer tx '256'
set interfaces ethernet eth0 speed 'auto'
set interfaces ethernet eth0 vif 5 address '172.16.37.254/24'
set interfaces ethernet eth0 vif 10 address '172.16.33.254/24'
set interfaces ethernet eth0 vif 10 address '172.16.40.254/24'
set interfaces ethernet eth0 vif 50 address '172.16.36.254/24'
set interfaces ethernet eth1 duplex 'auto'
set interfaces ethernet eth1 offload gro
set interfaces ethernet eth1 speed 'auto'
set interfaces ethernet eth1 vif 20 address '172.31.0.254/24'
set interfaces ethernet eth2 disable
set interfaces ethernet eth2 duplex 'auto'
set interfaces ethernet eth2 offload gro
set interfaces ethernet eth2 speed 'auto'
set interfaces ethernet eth3 duplex 'auto'
set interfaces ethernet eth3 offload gro
set interfaces ethernet eth3 ring-buffer rx '256'
set interfaces ethernet eth3 ring-buffer tx '256'
set interfaces ethernet eth3 speed 'auto'
set interfaces ethernet eth3 vif 7
set interfaces loopback lo address '172.16.254.30/32'
set interfaces pppoe pppoe0 authentication password 'vyos'
set interfaces pppoe pppoe0 authentication username 'vyos'
set interfaces pppoe pppoe0 dhcpv6-options pd 0 interface eth0.10 address '1'
set interfaces pppoe pppoe0 dhcpv6-options pd 0 interface eth0.10 sla-id '10'
set interfaces pppoe pppoe0 dhcpv6-options pd 0 interface eth1.20 address '1'
set interfaces pppoe pppoe0 dhcpv6-options pd 0 interface eth1.20 sla-id '20'
set interfaces pppoe pppoe0 dhcpv6-options pd 0 length '56'
set interfaces pppoe pppoe0 ip adjust-mss '1452'
set interfaces pppoe pppoe0 ipv6 address autoconf
set interfaces pppoe pppoe0 ipv6 adjust-mss '1432'
set interfaces pppoe pppoe0 no-peer-dns
set interfaces pppoe pppoe0 source-interface 'eth3.7'
set interfaces wireguard wg100 address '172.16.252.128/31'
set interfaces wireguard wg100 mtu '1500'
set interfaces wireguard wg100 peer HR6 address '100.65.151.213'
set interfaces wireguard wg100 peer HR6 allowed-ips '0.0.0.0/0'
set interfaces wireguard wg100 peer HR6 port '10100'
set interfaces wireguard wg100 peer HR6 public-key 'yLpi+UZuI019bmWH2h5fX3gStbpPPPLgEoYMyrdkOnQ='
set interfaces wireguard wg100 port '10100'
set interfaces wireguard wg100 private-key 'aGx+fvW916Ej7QRnBbW3QMoldhNv1u95/WHz45zDmF0='
set interfaces wireguard wg200 address '172.16.252.130/31'
set interfaces wireguard wg200 mtu '1500'
set interfaces wireguard wg200 peer WH56 address '80.151.69.205'
set interfaces wireguard wg200 peer WH56 allowed-ips '0.0.0.0/0'
set interfaces wireguard wg200 peer WH56 port '10200'
set interfaces wireguard wg200 peer WH56 public-key 'XQbkj6vnKKBJfJQyThXysU0iGxCvEOEb31kpaZgkrD8='
set interfaces wireguard wg200 port '10200'
set interfaces wireguard wg200 private-key 'aGx+fvW916Ej7QRnBbW3QMoldhNv1u95/WHz45zDmF0='
set interfaces wireguard wg666 address '172.29.0.1/31'
set interfaces wireguard wg666 mtu '1500'
set interfaces wireguard wg666 peer WH34 address '100.65.55.1'
set interfaces wireguard wg666 peer WH34 allowed-ips '0.0.0.0/0'
set interfaces wireguard wg666 peer WH34 port '10666'
set interfaces wireguard wg666 peer WH34 public-key 'yaTN4+xAafKM04D+Baeg5GWfbdaw35TE9HQivwRgAk0='
set interfaces wireguard wg666 port '10666'
set interfaces wireguard wg666 private-key 'aGx+fvW916Ej7QRnBbW3QMoldhNv1u95/WHz45zDmF0='
set nat destination rule 8000 destination port '10000'
set nat destination rule 8000 inbound-interface name 'pppoe0'
set nat destination rule 8000 protocol 'udp'
set nat destination rule 8000 translation address '172.31.0.200'
set nat source rule 50 outbound-interface name 'pppoe0'
set nat source rule 50 source address '100.64.0.0/24'
set nat source rule 50 translation address 'masquerade'
set nat source rule 100 outbound-interface name 'pppoe0'
set nat source rule 100 source address '172.16.32.0/21'
set nat source rule 100 translation address 'masquerade'
set nat source rule 200 outbound-interface name 'pppoe0'
set nat source rule 200 source address '172.16.100.0/24'
set nat source rule 200 translation address 'masquerade'
set nat source rule 300 outbound-interface name 'pppoe0'
set nat source rule 300 source address '172.31.0.0/24'
set nat source rule 300 translation address 'masquerade'
set nat source rule 400 outbound-interface name 'pppoe0'
set nat source rule 400 source address '172.18.200.0/21'
set nat source rule 400 translation address 'masquerade'
set nat source rule 1000 destination address '192.168.189.0/24'
set nat source rule 1000 outbound-interface name 'wg666'
set nat source rule 1000 source address '172.16.32.0/21'
set nat source rule 1000 translation address '172.29.0.1'
set nat source rule 1001 destination address '192.168.189.0/24'
set nat source rule 1001 outbound-interface name 'wg666'
set nat source rule 1001 source address '172.16.100.0/24'
set nat source rule 1001 translation address '172.29.0.1'
set policy route-map MAP-OSPF-CONNECTED rule 1 action 'deny'
set policy route-map MAP-OSPF-CONNECTED rule 1 match interface 'eth1.20'
set policy route-map MAP-OSPF-CONNECTED rule 20 action 'permit'
set policy route-map MAP-OSPF-CONNECTED rule 20 match interface 'eth0.10'
set policy route-map MAP-OSPF-CONNECTED rule 40 action 'permit'
set policy route-map MAP-OSPF-CONNECTED rule 40 match interface 'eth0.50'
set protocols bfd peer 172.16.252.129
set protocols bfd peer 172.16.252.131
set protocols bfd peer 172.18.254.201
set protocols bgp address-family ipv4-unicast network 172.16.32.0/21
set protocols bgp address-family ipv4-unicast network 172.16.100.0/24
set protocols bgp address-family ipv4-unicast network 172.16.252.128/31
set protocols bgp address-family ipv4-unicast network 172.16.252.130/31
set protocols bgp address-family ipv4-unicast network 172.16.254.30/32
set protocols bgp address-family ipv4-unicast network 172.18.0.0/16
set protocols bgp neighbor 172.16.252.129 peer-group 'WIREGUARD'
set protocols bgp neighbor 172.16.252.131 peer-group 'WIREGUARD'
set protocols bgp neighbor 172.18.254.201 address-family ipv4-unicast nexthop-self
set protocols bgp neighbor 172.18.254.201 bfd
set protocols bgp neighbor 172.18.254.201 remote-as '64503'
set protocols bgp neighbor 172.18.254.201 update-source 'dum0'
set protocols bgp parameters log-neighbor-changes
set protocols bgp peer-group WIREGUARD address-family ipv4-unicast soft-reconfiguration inbound
set protocols bgp peer-group WIREGUARD bfd
set protocols bgp peer-group WIREGUARD remote-as 'external'
set protocols bgp system-as '64503'
set protocols bgp timers holdtime '30'
set protocols bgp timers keepalive '10'
set protocols ospf area 0 network '172.16.254.30/32'
set protocols ospf area 0 network '172.16.37.0/24'
set protocols ospf area 0 network '172.18.201.0/24'
set protocols ospf area 0 network '172.18.202.0/24'
set protocols ospf area 0 network '172.18.203.0/24'
set protocols ospf area 0 network '172.18.204.0/24'
set protocols ospf default-information originate always
set protocols ospf default-information originate metric-type '2'
set protocols ospf interface eth0.5 authentication md5 key-id 10 md5-key 'ospf'
set protocols ospf interface eth0.5 dead-interval '40'
set protocols ospf interface eth0.5 hello-interval '10'
set protocols ospf interface eth0.5 passive disable
set protocols ospf interface eth0.5 priority '1'
set protocols ospf interface eth0.5 retransmit-interval '5'
set protocols ospf interface eth0.5 transmit-delay '1'
set protocols ospf log-adjacency-changes detail
set protocols ospf parameters abr-type 'cisco'
set protocols ospf parameters router-id '172.16.254.30'
set protocols ospf passive-interface 'default'
set protocols ospf redistribute connected metric-type '2'
set protocols ospf redistribute connected route-map 'MAP-OSPF-CONNECTED'
set protocols static route 10.0.0.0/8 blackhole distance '254'
set protocols static route 169.254.0.0/16 blackhole distance '254'
set protocols static route 172.16.0.0/12 blackhole distance '254'
set protocols static route 172.16.32.0/21 blackhole
set protocols static route 172.18.0.0/16 blackhole
set protocols static route 172.29.0.2/31 next-hop 172.29.0.0
set protocols static route 192.168.0.0/16 blackhole distance '254'
set protocols static route 192.168.189.0/24 next-hop 172.29.0.0
set protocols static route6 2000::/3 interface pppoe0
set qos policy shaper QoS bandwidth '50mbit'
set qos policy shaper QoS default bandwidth '100%'
set qos policy shaper QoS default burst '15k'
set qos policy shaper QoS default queue-limit '1000'
set qos policy shaper QoS default queue-type 'fq-codel'
set service dhcp-server shared-network-name BACKBONE authoritative
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 lease '86400'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 option default-router '172.16.37.254'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 option domain-name 'vyos.net'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 option domain-search 'vyos.net'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 option name-server '172.16.254.30'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 option ntp-server '172.16.254.30'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 range 0 start '172.16.37.120'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 range 0 stop '172.16.37.149'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 static-mapping AP1 ip-address '172.16.37.231'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 static-mapping AP1 mac '02:00:00:00:ee:18'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 static-mapping AP2 ip-address '172.16.37.232'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 static-mapping AP2 mac '02:00:00:00:52:84'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 static-mapping AP3 ip-address '172.16.37.233'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 static-mapping AP3 mac '02:00:00:00:51:c0'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 static-mapping AP4 ip-address '172.16.37.234'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 static-mapping AP4 mac '02:00:00:00:e6:fc'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 static-mapping AP5 ip-address '172.16.37.235'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 static-mapping AP5 mac '02:00:00:00:c3:50'
set service dhcp-server shared-network-name BACKBONE subnet 172.16.37.0/24 subnet-id '1'
set service dhcp-server shared-network-name GUEST authoritative
set service dhcp-server shared-network-name GUEST subnet 172.31.0.0/24 lease '86400'
set service dhcp-server shared-network-name GUEST subnet 172.31.0.0/24 option default-router '172.31.0.254'
set service dhcp-server shared-network-name GUEST subnet 172.31.0.0/24 option domain-name 'vyos.net'
set service dhcp-server shared-network-name GUEST subnet 172.31.0.0/24 option domain-search 'vyos.net'
set service dhcp-server shared-network-name GUEST subnet 172.31.0.0/24 option name-server '172.31.0.254'
set service dhcp-server shared-network-name GUEST subnet 172.31.0.0/24 range 0 start '172.31.0.101'
set service dhcp-server shared-network-name GUEST subnet 172.31.0.0/24 range 0 stop '172.31.0.199'
set service dhcp-server shared-network-name GUEST subnet 172.31.0.0/24 subnet-id '2'
set service dhcp-server shared-network-name LAN authoritative
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 lease '86400'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 option default-router '172.16.33.254'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 option domain-name 'vyos.net'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 option domain-search 'vyos.net'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 option name-server '172.16.254.30'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 option ntp-server '172.16.254.30'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 range 0 start '172.16.33.100'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 range 0 stop '172.16.33.189'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 static-mapping four ip-address '172.16.33.214'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 static-mapping four mac '02:00:00:00:c4:33'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 static-mapping one ip-address '172.16.33.221'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 static-mapping one mac '02:00:00:00:eb:a6'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 static-mapping three ip-address '172.16.33.212'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 static-mapping three mac '02:00:00:00:12:c7'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 static-mapping two ip-address '172.16.33.211'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 static-mapping two mac '02:00:00:00:58:90'
set service dhcp-server shared-network-name LAN subnet 172.16.33.0/24 subnet-id '3'
set service dns dynamic name service-vyos-pppoe0 address interface 'pppoe0'
set service dns dynamic name service-vyos-pppoe0 host-name 'r1.vyos.net'
set service dns dynamic name service-vyos-pppoe0 password 'vyos'
set service dns dynamic name service-vyos-pppoe0 protocol 'dyndns2'
set service dns dynamic name service-vyos-pppoe0 server 'dyndns.vyos.io'
set service dns dynamic name service-vyos-pppoe0 username 'vyos-vyos'
set service dns forwarding allow-from '172.16.0.0/12'
set service dns forwarding domain 16.172.in-addr.arpa addnta
set service dns forwarding domain 16.172.in-addr.arpa name-server 172.16.100.10
set service dns forwarding domain 16.172.in-addr.arpa name-server 172.16.100.20
set service dns forwarding domain 16.172.in-addr.arpa recursion-desired
set service dns forwarding domain 18.172.in-addr.arpa addnta
set service dns forwarding domain 18.172.in-addr.arpa name-server 172.16.100.10
set service dns forwarding domain 18.172.in-addr.arpa name-server 172.16.100.20
set service dns forwarding domain 18.172.in-addr.arpa recursion-desired
set service dns forwarding domain vyos.net addnta
set service dns forwarding domain vyos.net name-server 172.16.100.10
set service dns forwarding domain vyos.net name-server 172.16.100.20
set service dns forwarding domain vyos.net recursion-desired
set service dns forwarding ignore-hosts-file
set service dns forwarding listen-address '172.16.254.30'
set service dns forwarding listen-address '172.31.0.254'
set service dns forwarding negative-ttl '60'
set service lldp legacy-protocols cdp
set service lldp legacy-protocols edp
set service lldp legacy-protocols fdp
set service lldp legacy-protocols sonmp
set service lldp snmp
set service ntp allow-client address '172.16.0.0/12'
set service ntp server time1.vyos.net
set service ntp server time2.vyos.net
set service router-advert interface eth0.10 prefix ::/64 preferred-lifetime '2700'
set service router-advert interface eth0.10 prefix ::/64 valid-lifetime '5400'
set service router-advert interface eth1.20 prefix ::/64 preferred-lifetime '2700'
set service router-advert interface eth1.20 prefix ::/64 valid-lifetime '5400'
set service snmp community ro-community authorization 'ro'
set service snmp community ro-community network '172.16.100.0/24'
set service snmp contact 'VyOS'
set service snmp listen-address 172.16.254.30 port '161'
set service snmp location 'CLOUD'
set service ssh disable-host-validation
set service ssh port '22'
set system config-management commit-revisions '200'
set system conntrack expect-table-size '2048'
set system conntrack hash-size '32768'
set system conntrack modules ftp
set system conntrack modules h323
set system conntrack modules nfs
set system conntrack modules pptp
set system conntrack modules sqlnet
set system conntrack modules tftp
set system conntrack table-size '262144'
set system conntrack timeout
set system console device ttyS0 speed '115200'
set system domain-name 'vyos.net'
set system host-name 'r1'
set system login user vyos authentication encrypted-password '$6$2Ta6TWHd/U$NmrX0x9kexCimeOcYK1MfhMpITF9ELxHcaBU/znBq.X2ukQOj61fVI2UYP/xBzP4QtiTcdkgs7WOQMHWsRymO/'
set system login user vyos authentication plaintext-password ''
set system name-server '172.16.254.30'
set system option ctrl-alt-delete 'ignore'
set system option performance 'network-latency'
set system option reboot-on-panic
set system option startup-beep
set system syslog global facility all level 'debug'
set system syslog global facility local7 level 'debug'
set system syslog host 172.16.100.1 facility all level 'warning'
set system time-zone 'Europe/Berlin'
|