defnetclass trusted untrusted trusted safe noloop
defnetclass safe trusted safe noloop
defnetclass noloop trusted safe
-m4_divert(-1)m4_dnl
+m4_divert(-1)
+m4_divert(26)m4_dnl
###--------------------------------------------------------------------------
### Network layout.
-m4_divert(46)m4_dnl
-## Networks and routing.
-
+m4_divert(44)m4_dnl
+## Network definitions.
defiface $if_dmz \
trusted:62.49.204.144/28 \
trusted:172.29.199.0/25 \
## Default NTP servers.
ntp_servers="158.152.1.76 158.152.1.204 194.159.253.2 195.173.57.232"
-m4_divert(60)m4_dnl
+m4_divert(80)m4_dnl
###--------------------------------------------------------------------------
### Special forwarding exemptions.
-m state --state ESTABLISHED
m4_divert(60)m4_dnl
+m4_divert(80)m4_dnl
###--------------------------------------------------------------------------
### Kill things we don't understand properly.
###
run ip6tables -A FORWARD -g poorly-understood \
-d ff::/8
-m4_divert(80)m4_dnl
+m4_divert(84)m4_dnl
###--------------------------------------------------------------------------
### Locally-bound packet inspection.