## top nibble of the network number classifies the network, as follows.
##
## 8xxx Untrusted
-## 6xxx Virtual
+## 6xxx Virtual, safe
## 4xxx Safe
## 0xxx Unsafe, trusted
##
defhost stratocaster
iface eth0 jump colo
iface eth1 jump colo
+defhost jaguar
+ iface eth0 jump
defhost jazz
hosttype router
iface eth0 jump colo vpn
defnet vpn safe
addr 172.29.199.128/27 2001:ba8:1d9:6000::/64
via househub colohub
- host crybaby 1
- host terror 2
- host orange 3
+ host crybaby 1 ::1:1
+ host terror 2 ::2:1
+ host orange 3 ::3:1
defnet anycast trusted
addr 172.29.199.224/27 2001:ba8:1d9:0::/64
via dmz unsafe safe untrusted jump colo vpn
addr 10.165.27.0/24
via colohub
+defhost mango
+ hosttype router
+ iface eth0 binswood default
+ iface vpn-precision colo
+
+m4_divert(80)m4_dnl
+###--------------------------------------------------------------------------
+### Connection tracking helper modules.
+
+for i in ftp; do
+ modprobe nf_conntrack_$i
+done
+
m4_divert(80)m4_dnl
###--------------------------------------------------------------------------
### Special forwarding exemptions.