{
"access" : [
{
"enabled" : true,
"protocol" : [ "tcp" ],
"src_dev" : [ "br0" ],
"dst_dev" : [ "fw" ],
"dst_port" : [ "22" ],
"remark" : "Allow SSH from LAN",
"filter_target" : "ACCEPT",
"log" : false
},
{
"enabled" : true,
"protocol" : [ "tcp" ],
"src_dev" : [ "br0" ],
"dst_dev" : [ "fw" ],
"dst_port" : [ "443" ],
"remark" : "Allow HTTPS from LAN",
"filter_target" : "ACCEPT",
"log" : false
},
{
"enabled" : true,
"protocol" : [ "tcp" ],
"src_dev" : [ "br0" ],
"dst_dev" : [ "fw" ],
"dst_port" : [ "80" ],
"remark" : "Allow HTTP from LAN",
"filter_target" : "ACCEPT",
"log" : false
},
{
"enabled" : true,
"protocol" : [ "udp" ],
"src_dev" : [ "br0" ],
"dst_dev" : [ "fw" ],
"dst_port" : [ "67","68" ],
"remark" : "Allow DHCP on LAN",
"filter_target" : "ACCEPT",
"log" : false
},
{
"enabled" : true,
"protocol" : [ "udp","tcp" ],
"src_dev" : [ "br0" ],
"dst_dev" : [ "fw" ],
"dst_port" : [ "53" ],
"remark" : "Allow DNS on LAN",
"filter_target" : "ACCEPT",
"log" : false
},
{
"enabled" : true,
"protocol" : [ "udp" ],
"src_dev" : [ "eth1" ],
"dst_dev" : [ "fw" ],
"dst_port" : [ "1194" ],
"remark" : "Allow OpenVPN on WAN",
"filter_target" : "ACCEPT",
"log" : false
}
],
"bridges" : {
"br0" : { "interfaces" : [ "eth0" ] }
},
"dhcp" : [],
"dnat" : [
{
"enabled" : true,
"protocol" : [ "tcp" ],
"src_dev" : [ "eth1" ],
"dst_ip" : [ "X.X.X.X" ],
"dst_port" : [ "80" ],
"target_ip" : [ "192.168.19.87" ],
"target_port" : [ "80" ],
"remark" : "WAN HTTP to internal webserver",
"filter_target" : "ACCEPT",
"nat_target" : "DNAT",
"log" : false
},
{
"enabled" : true,
"protocol" : [ "tcp" ],
"src_dev" : [ "eth1" ],
"dst_ip" : [ "X.X.X.X" ],
"dst_port" : [ "443" ],
"target_ip" : [ "192.168.19.87" ],
"target_port" : [ "443" ],
"remark" : "WAN HTTPS to internal webserver",
"filter_target" : "ACCEPT",
"nat_target" : "DNAT",
"log" : false
}
],
"hosts" : [],
"interfaces" : {
"physical" : [ "eth0","eth1","lo" ],
"virtual" : []
},
"out" : [
{
"enabled" : true,
"protocol" : [ "tcp" ],
"src_dev" : [ "br0" ],
"dst_dev" : [ "eth1" ],
"dst_port" : [ "80","443" ],
"remark" : "Allow LAN outbound web",
"filter_target" : "ACCEPT",
"log" : false
},
{
"enabled" : true,
"protocol" : [ "all" ],
"src_dev" : [ "br0" ],
"dst_dev" : [ "eth1" ],
"remark" : "Block all other outbound from LAN",
"filter_target" : "DROP",
"log" : false
}
],
"routing" : [
{
"type" : "default",
"via" : "<GW1 IP>",
"dev" : "eth1",
"remark" : "Default WAN route"
}
],
"snat" : [
{
"enabled" : true,
"src_dev" : [ "br0" ],
"dst_dev" : [ "eth1" ],
"nat_target" : "SNAT",
"remark" : "MASQUERADE LAN1 to WAN1"
},
{
"enabled" : true,
"src_dev" : [ "br0" ],
"dst_dev" : [ "eth2" ],
"nat_target" : "SNAT",
"remark" : "MASQUERADE LAN1 to WAN2"
}
],
"users" : {
"Admin" : "admin:$apr1$qci0smug$50y/xw0j8s7vsUmW421Zi."
},
"vpnfw" : [
{
"enabled" : true,
"protocol" : [ "tcp" ],
"src_dev" : [ "tun0" ],
"dst_dev" : [ "br0" ],
"dst_port" : [ "3389" ],
"remark" : "VPN to LAN1 RDP",
"filter_target" : "ACCEPT",
"log" : false
},
{
"enabled" : true,
"protocol" : [ "tcp" ],
"src_dev" : [ "tun0" ],
"dst_dev" : [ "br1" ],
"dst_port" : [ "445" ],
"remark" : "VPN to LAN2 SMB",
"filter_target" : "ACCEPT",
"log" : false
},
{
"enabled" : true,
"protocol" : [ "all" ],
"src_dev" : [ "tun0" ],
"dst_dev" : [ "br0" ],
"remark" : "Block VPN to LAN1",
"filter_target" : "DROP",
"log" : false
},
{
"enabled" : true,
"protocol" : [ "all" ],
"src_dev" : [ "tun0" ],
"dst_dev" : [ "br1" ],
"remark" : "Block VPN to LAN2",
"filter_target" : "DROP",
"log" : false
}
],
"vpns" : [],
"vusers" : [],
"zfw" : [
{
"enabled" : true,
"protocol" : [ "tcp" ],
"src_dev" : [ "br0" ],
"dst_dev" : [ "br1" ],
"dst_port" : [ "3389" ],
"remark" : "LAN1 to LAN2 RDP",
"filter_target" : "ACCEPT",
"log" : false
}
],
"zones" : {
"LAN" : {
"ZADDITIONAL" : "",
"ZADDRESS" : "192.168.55.1",
"ZCOLOR" : "#00ff00",
"ZDESC" : "Primary Network",
"ZDHCP" : "off",
"ZIFACE" : "eth0",
"ZNETMASK" : "/24",
"ZSTRING" : "LAN",
"ZTYPE" : "LAN"
},
"LOCAL" : {
"ZADDITIONAL" : "",
"ZADDRESS" : "",
"ZCOLOR" : "black",
"ZDESC" : "Local Loopback Adapter",
"ZDHCP" : "off",
"ZIFACE" : "lo",
"ZNETMASK" : "",
"ZSTRING" : "loopback",
"ZTYPE" : "LOOPBACK"
},
"WAN" : {
"ZADDITIONAL" : "",
"ZADDRESS" : "",
"ZCOLOR" : "red",
"ZDESC" : "Primary Internet Connection",
"ZDHCP" : "on",
"ZIFACE" : "eth1",
"ZNETMASK" : "",
"ZSTRING" : "WAN",
"ZTYPE" : "WAN"
}
}
}