firewall.yml 1.6 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162
  1. ---
  2. firewall:
  3. tailscale: true
  4. bgp:
  5. - interface: lab
  6. addresses:
  7. - fd00:8e13:ce5e:b9af:3e5b:098f:a1bd:1
  8. bfd:
  9. - interface: lab
  10. prefix: fd00:8e13:ce5e:b9af:3e5b:98f:a1bd:0/127
  11. rules:
  12. # I2P
  13. - !vault |
  14. $ANSIBLE_VAULT;1.1;AES256
  15. 36626666643365343333383831626531636633346536343862353738323135396161636163373730
  16. 6663326331326661383963353664346439356361626238310a313133666666326163316537393839
  17. 64353638353335326330336364363164353935366136376433643038316531653963616665343237
  18. 3865666230306137300a376435646466303437373638386531346163316133306139663865396432
  19. 61623533356634613531616263646134373635313362333066643434313661353039393534316437
  20. 34326464666333623131363239616439353862646461626663656437643533613133353163366538
  21. 346631316636643766386238306162373063
  22. # wireguard and fastd ports are automatically opened
  23. rc:
  24. own_interfaces:
  25. - routercity
  26. interfaces:
  27. - p2pnode
  28. - p2prouter
  29. - herzstein
  30. - stricker
  31. - trolljaeger
  32. - silvermoon
  33. - frostwood
  34. - beastwarden
  35. dnet:
  36. own_interfaces:
  37. - crxn
  38. - dn42
  39. - neo
  40. interfaces:
  41. - p2pnode
  42. - p2prouter
  43. - herzstein
  44. - stricker
  45. - trolljaeger
  46. - silvermoon
  47. - crxn_grisha
  48. - crxn_home
  49. - frostwood
  50. - lab
  51. - beastwarden
  52. clients:
  53. - interface: client13
  54. firewall: true
  55. allowed_ips:
  56. dnet_ipv4:
  57. - 172.22.149.117/32
  58. dnet_ipv6:
  59. - fd92:58b6:2b2:e::12/128