LINUX.ORG.RU
ФорумAdmin

ошибка pf.conf


0

0

Народ помогите плз админ ушел и оставил мне гейт на фре.. пока усиленно читаю не могу добавить удаленный комп... при выполнении make.sh выдает ошибку в 69 строке

ext_if="rl0" int_if="fxp0" atm_if="vr0" internal_net="192.168.76.0/24" external_addr="213.234.26.8/248" icmp_types = "echoreq"

set loginterface $ext_if set loginterface $int_if scrub in all

table <natusers> file "/etc/allowed/nat.users" table <atm> file "/etc/allowed/atm" table <processing> { 172.17.130.5, 172.17.130.7 } table <bb_net> {172.0.0.0/24, 192.168.0.0/24, 192.168.7.0/24, 128.0.0.0/24, 217.148.213.21}

allowed_ports = "{ ftp-data, ftp, ssh, domain, pop3, auth, nntp, https, 446, 2628, 31337 }"

nat on $atm_if from <natusers> to any -> ($atm_if) rdr on $int_if inet proto tcp from any to any port { 80, 81, 8000, 8001, 8080 } -> 127.0.0.1 port 3128

################################################################################ ##################

nat on $int_if from 213.234.26.50 to any -> 192.168.76.125 # Sovetskya 5, OblSovProf

#тут идет список удаленных компов

rdr on $atm_if proto udp from <atm> to 213.234.26.13 -> 172.17.33.58 rdr on $atm_if proto tcp from <atm> to 213.234.26.13 -> 172.17.33.58

################################################################################ ##################

#block log all block log inet proto { tcp, udp } from any to any port { 137, 138, 139 } block log inet proto { tcp, udp } from any to $atm_if port { 137, 138, 139, 80, 8080, 3306, >100 }

#block log on $atm_if proto tcp from any to $atm_if

# Allow NFS server for local network pass in on $int_if inet proto udp from any to $int_if port > 10000 user root

# Allow SSH and FTP for local admins and users pass in inet proto tcp from $internal_net to $int_if port ssh pass in inet proto tcp from $internal_net to $int_if port { http, https } # ОШИБКИ!!!! pass on $int_if from $internal_net to <bb_net> flags S/SA keep stat pass on $int_if from <bb_net> to $internal_net flags S/SA keep state

pass inet proto icmp all icmp-type $icmp_types keep state

pass in on $int_if inet proto { tcp, udp } from any to any flags S/SA keep state pass out on $int_if inet proto { tcp, udp } from any to any flags S/SA keep state pass out on $atm_if inet proto { tcp, udp } from any to any flags S/SA keep state pass out on $int_if from 127.0.0.1 to $internal_net pass quick on lo0 all

anonymous

отформатируй нормально

пока видно только keep stat вместо keep statE

phoenix ★★★★
()
Вы не можете добавлять комментарии в эту тему. Тема перемещена в архив.