set firewall global-options apply-to-bridged-traffic accept-invalid ethernet-type 'arp' set firewall global-options apply-to-bridged-traffic accept-invalid ethernet-type '802.1q' set firewall global-options apply-to-bridged-traffic accept-invalid ethernet-type 'dhcp' set firewall global-options apply-to-bridged-traffic accept-invalid ethernet-type 'wol' set firewall global-options apply-to-bridged-traffic accept-invalid ethernet-type 'pppoe' set firewall global-options apply-to-bridged-traffic accept-invalid ethernet-type 'pppoe-discovery' set firewall global-options state-policy established action 'accept' set firewall global-options state-policy invalid action 'drop' set firewall global-options state-policy invalid log set firewall global-options state-policy related action 'accept' set firewall group interface-group INSIDE description 'interfaces attached to internal networks' set firewall group interface-group INSIDE interface 'eth0' set firewall group interface-group INSIDE interface 'lo' set firewall group interface-group INSIDE interface 'br0' set firewall group interface-group INSIDE interface 'br0.3000' set firewall group interface-group INSIDE interface 'br0.3010' set firewall group interface-group INSIDE interface 'br0.3110' set firewall group interface-group INSIDE interface 'br0.3128' set firewall group interface-group INSIDE interface 'br0.3144' set firewall group interface-group INSIDE interface 'br0.3210' set firewall group interface-group INSIDE interface 'wg0' set firewall group interface-group INSIDE interface 'eth2' set firewall group interface-group INSIDE interface 'eth3' set firewall group interface-group MGMT description 'interfaces attached to management networks' set firewall group interface-group MGMT include 'MGMT-HOME' set firewall group interface-group MGMT include 'MGMT-CLOUD' set firewall group interface-group MGMT-CLOUD description 'interfaces attached to the CLOUD management network' set firewall group interface-group MGMT-CLOUD interface 'wg0' set firewall group interface-group MGMT-HOME description 'interfaces attached to the HOME management network' set firewall group interface-group MGMT-HOME interface 'br0.3110' set firewall group interface-group OUTSIDE description 'interfaces attached to external networks' set firewall group interface-group OUTSIDE include 'WAN' set firewall group interface-group OUTSIDE interface 'eth5' set firewall group interface-group OUTSIDE interface 'eth5.7' set firewall group interface-group WAN description 'WAN' set firewall group interface-group WAN interface 'pppoe0' set firewall group network-group MGMT-CLIENT-4 description 'IPv4 addresses of devices allowed to connect to management interfaces of other machines' set firewall group network-group MGMT-CLIENT-4 network '192.168.211.3/32' set firewall group network-group MGMT-CLIENT-4 network '192.168.211.4/32' set firewall group network-group NET-DMZ-4 description 'DMZ' set firewall group network-group NET-DMZ-4 network '192.168.144.0/20' set firewall group network-group NET-GUEST-4 description 'GUEST' set firewall group network-group NET-GUEST-4 network '192.168.10.0/23' set firewall group network-group NET-IOT-4 description 'IOT' set firewall group network-group NET-IOT-4 network '192.168.0.0/23' set firewall group network-group NET-LAN-4 description 'LAN' set firewall group network-group NET-LAN-4 network '192.168.210.0/23' set firewall group network-group NET-MGMT-4 description 'MGMT' set firewall group network-group NET-MGMT-4 include 'NET-MGMT-CLOUD-4' set firewall group network-group NET-MGMT-4 include 'NET-MGMT-HOME-4' set firewall group network-group NET-MGMT-4 network '192.168.104.0/21' set firewall group network-group NET-MGMT-CLOUD-4 description 'MGMT (Cloud)' set firewall group network-group NET-MGMT-CLOUD-4 network '192.168.104.0/22' set firewall group network-group NET-MGMT-HOME-4 description 'MGMT (Home)' set firewall group network-group NET-MGMT-HOME-4 network '192.168.110.0/23' set firewall group network-group NET-SVC-4 description 'SVC' set firewall group network-group NET-SVC-4 network '192.168.128.0/20' set firewall group network-group PRIVATE-4 description 'internal IPv4 address space' set firewall group network-group PRIVATE-4 network '10.0.0.0/8' set firewall group network-group PRIVATE-4 network '172.16.0.0/12' set firewall group network-group PRIVATE-4 network '192.168.0.0/16' set firewall group network-group PRIVATE-4 network '192.0.0.0/24' set firewall group network-group PRIVATE-4 network '192.0.2.0/24' set firewall group network-group PRIVATE-4 network '198.18.0.0/15' set firewall group network-group PRIVATE-4 network '198.51.100.0/24' set firewall group network-group PRIVATE-4 network '203.0.113.0/24' set firewall group port-group LOCAL-SERVICES description 'Destination ports of services provided for local networks by this router' set firewall group port-group LOCAL-SERVICES port '53' set firewall group port-group LOCAL-SERVICES port '123' set firewall group port-group LOCAL-SERVICES port '67' set firewall group port-group WIREGUARD description 'WireGuard ports' set firewall group port-group WIREGUARD port '32524' set firewall ipv4 name DMZ-LOCAL default-action 'drop' set firewall ipv4 name DMZ-LOCAL default-log set firewall ipv4 name DMZ-LOCAL description 'DMZ -> LOCAL' set firewall ipv4 name DMZ-LOCAL rule 20 action 'jump' set firewall ipv4 name DMZ-LOCAL rule 20 jump-target 'J-ICMP-IN' set firewall ipv4 name DMZ-LOCAL rule 20 protocol 'icmp' set firewall ipv4 name DMZ-LOCAL rule 30 action 'jump' set firewall ipv4 name DMZ-LOCAL rule 30 destination group port-group 'LOCAL-SERVICES' set firewall ipv4 name DMZ-LOCAL rule 30 jump-target 'J-LOCAL-SERVICES-IN' set firewall ipv4 name DMZ-LOCAL rule 30 protocol 'tcp_udp' set firewall ipv4 name DMZ-WAN default-action 'drop' set firewall ipv4 name DMZ-WAN default-log set firewall ipv4 name DMZ-WAN description 'DMZ -> WAN' set firewall ipv4 name DMZ-WAN rule 30 action 'accept' set firewall ipv4 name DMZ-WAN rule 30 description 'temp rule to allow all outbound traffic' set firewall ipv4 name GUEST-LOCAL default-action 'drop' set firewall ipv4 name GUEST-LOCAL default-log set firewall ipv4 name GUEST-LOCAL description 'GUEST -> LOCAL' set firewall ipv4 name GUEST-LOCAL rule 20 action 'jump' set firewall ipv4 name GUEST-LOCAL rule 20 jump-target 'J-ICMP-IN' set firewall ipv4 name GUEST-LOCAL rule 20 protocol 'icmp' set firewall ipv4 name GUEST-LOCAL rule 30 action 'jump' set firewall ipv4 name GUEST-LOCAL rule 30 destination group port-group 'LOCAL-SERVICES' set firewall ipv4 name GUEST-LOCAL rule 30 jump-target 'J-LOCAL-SERVICES-IN' set firewall ipv4 name GUEST-LOCAL rule 30 protocol 'tcp_udp' set firewall ipv4 name GUEST-WAN default-action 'drop' set firewall ipv4 name GUEST-WAN default-log set firewall ipv4 name GUEST-WAN description 'GUEST -> WAN' set firewall ipv4 name GUEST-WAN rule 30 action 'accept' set firewall ipv4 name GUEST-WAN rule 30 description 'temp rule to allow all outbound traffic' set firewall ipv4 name IOT-LOCAL default-action 'drop' set firewall ipv4 name IOT-LOCAL default-log set firewall ipv4 name IOT-LOCAL description 'IOT -> LOCAL' set firewall ipv4 name IOT-LOCAL rule 20 action 'jump' set firewall ipv4 name IOT-LOCAL rule 20 jump-target 'J-ICMP-IN' set firewall ipv4 name IOT-LOCAL rule 20 protocol 'icmp' set firewall ipv4 name IOT-LOCAL rule 30 action 'jump' set firewall ipv4 name IOT-LOCAL rule 30 destination group port-group 'LOCAL-SERVICES' set firewall ipv4 name IOT-LOCAL rule 30 jump-target 'J-LOCAL-SERVICES-IN' set firewall ipv4 name IOT-LOCAL rule 30 protocol 'tcp_udp' set firewall ipv4 name IOT-WAN default-action 'drop' set firewall ipv4 name IOT-WAN default-log set firewall ipv4 name IOT-WAN description 'IOT -> WAN' set firewall ipv4 name J-ICMP-IN default-action 'drop' set firewall ipv4 name J-ICMP-IN default-log set firewall ipv4 name J-ICMP-IN description 'handle ICMP (ingress)' set firewall ipv4 name J-ICMP-IN rule 10 action 'drop' set firewall ipv4 name J-ICMP-IN rule 10 description 'drop fragmented ICMP packets' set firewall ipv4 name J-ICMP-IN rule 10 fragment match-frag set firewall ipv4 name J-ICMP-IN rule 20 action 'accept' set firewall ipv4 name J-ICMP-IN rule 20 icmp type-name 'destination-unreachable' set firewall ipv4 name J-ICMP-IN rule 22 action 'accept' set firewall ipv4 name J-ICMP-IN rule 22 icmp code '0' set firewall ipv4 name J-ICMP-IN rule 22 icmp type-name 'time-exceeded' set firewall ipv4 name J-ICMP-IN rule 23 action 'accept' set firewall ipv4 name J-ICMP-IN rule 23 icmp type-name 'parameter-problem' set firewall ipv4 name J-ICMP-IN rule 30 action 'accept' set firewall ipv4 name J-ICMP-IN rule 30 icmp type-name 'echo-reply' set firewall ipv4 name J-ICMP-IN rule 40 action 'drop' set firewall ipv4 name J-ICMP-IN rule 40 description 'block pings on OUTSIDE interfaces' set firewall ipv4 name J-ICMP-IN rule 40 icmp type-name 'echo-request' set firewall ipv4 name J-ICMP-IN rule 40 inbound-interface group 'OUTSIDE' set firewall ipv4 name J-ICMP-IN rule 41 action 'accept' set firewall ipv4 name J-ICMP-IN rule 41 icmp type-name 'echo-request' set firewall ipv4 name J-ICMP-IN rule 41 inbound-interface group 'UNTRUSTED' set firewall ipv4 name J-ICMP-IN rule 41 limit rate '10/second' set firewall ipv4 name J-ICMP-IN rule 42 action 'accept' set firewall ipv4 name J-ICMP-IN rule 42 icmp type-name 'echo-request' set firewall ipv4 name J-ICMP-OUT default-action 'reject' set firewall ipv4 name J-ICMP-OUT default-log set firewall ipv4 name J-ICMP-OUT description 'handle ICMP (egress)' set firewall ipv4 name J-ICMP-OUT rule 10 action 'reject' set firewall ipv4 name J-ICMP-OUT rule 10 description 'do not send fragmented ICMP packets' set firewall ipv4 name J-ICMP-OUT rule 10 fragment match-frag set firewall ipv4 name J-ICMP-OUT rule 10 log set firewall ipv4 name J-ICMP-OUT rule 20 action 'accept' set firewall ipv4 name J-ICMP-OUT rule 20 icmp type-name 'destination-unreachable' set firewall ipv4 name J-ICMP-OUT rule 22 action 'accept' set firewall ipv4 name J-ICMP-OUT rule 22 icmp code '0' set firewall ipv4 name J-ICMP-OUT rule 22 icmp type-name 'time-exceeded' set firewall ipv4 name J-ICMP-OUT rule 23 action 'accept' set firewall ipv4 name J-ICMP-OUT rule 23 icmp type-name 'parameter-problem' set firewall ipv4 name J-ICMP-OUT rule 30 action 'reject' set firewall ipv4 name J-ICMP-OUT rule 30 description 'do not reply to pings on OUTSIDE interfaces' set firewall ipv4 name J-ICMP-OUT rule 30 icmp type-name 'echo-reply' set firewall ipv4 name J-ICMP-OUT rule 30 log set firewall ipv4 name J-ICMP-OUT rule 30 outbound-interface group 'OUTSIDE' set firewall ipv4 name J-ICMP-OUT rule 31 action 'accept' set firewall ipv4 name J-ICMP-OUT rule 31 icmp type-name 'echo-reply' set firewall ipv4 name J-ICMP-OUT rule 40 action 'accept' set firewall ipv4 name J-ICMP-OUT rule 40 icmp type-name 'echo-request' set firewall ipv4 name J-ICMP-OUT rule 50 action 'accept' set firewall ipv4 name J-ICMP-OUT rule 50 description 'allow sending ICMP redirects on INSIDE interfaces' set firewall ipv4 name J-ICMP-OUT rule 50 icmp type-name 'redirect' set firewall ipv4 name J-ICMP-OUT rule 50 log set firewall ipv4 name J-ICMP-OUT rule 50 outbound-interface group 'INSIDE' set firewall ipv4 name J-LOCAL-SERVICES-IN default-action 'return' set firewall ipv4 name J-LOCAL-SERVICES-IN description 'handle basic services provided for local networks by this router (ingress)' set firewall ipv4 name J-LOCAL-SERVICES-IN rule 110 action 'accept' set firewall ipv4 name J-LOCAL-SERVICES-IN rule 110 description 'allow DHCP' set firewall ipv4 name J-LOCAL-SERVICES-IN rule 110 destination port '67' set firewall ipv4 name J-LOCAL-SERVICES-IN rule 110 protocol 'udp' set firewall ipv4 name J-LOCAL-SERVICES-IN rule 110 source port '68' set firewall ipv4 name J-LOCAL-SERVICES-IN rule 120 action 'accept' set firewall ipv4 name J-LOCAL-SERVICES-IN rule 120 description 'allow NTP' set firewall ipv4 name J-LOCAL-SERVICES-IN rule 120 destination port '123' set firewall ipv4 name J-LOCAL-SERVICES-IN rule 120 protocol 'udp' set firewall ipv4 name J-LOCAL-SERVICES-IN rule 130 action 'accept' set firewall ipv4 name J-LOCAL-SERVICES-IN rule 130 description 'allow DNS' set firewall ipv4 name J-LOCAL-SERVICES-IN rule 130 destination port '53' set firewall ipv4 name J-LOCAL-SERVICES-IN rule 130 protocol 'tcp_udp' set firewall ipv4 name LAN-LOCAL default-action 'drop' set firewall ipv4 name LAN-LOCAL default-log set firewall ipv4 name LAN-LOCAL description 'LAN -> LOCAL' set firewall ipv4 name LAN-LOCAL rule 20 action 'jump' set firewall ipv4 name LAN-LOCAL rule 20 jump-target 'J-ICMP-IN' set firewall ipv4 name LAN-LOCAL rule 20 protocol 'icmp' set firewall ipv4 name LAN-LOCAL rule 30 action 'jump' set firewall ipv4 name LAN-LOCAL rule 30 destination group port-group 'LOCAL-SERVICES' set firewall ipv4 name LAN-LOCAL rule 30 jump-target 'J-LOCAL-SERVICES-IN' set firewall ipv4 name LAN-LOCAL rule 30 protocol 'tcp_udp' set firewall ipv4 name LAN-LOCAL rule 1010 action 'accept' set firewall ipv4 name LAN-LOCAL rule 1010 description 'allow SSH from MGMT clients' set firewall ipv4 name LAN-LOCAL rule 1010 destination port '22' set firewall ipv4 name LAN-LOCAL rule 1010 protocol 'tcp' set firewall ipv4 name LAN-LOCAL rule 1010 source group network-group 'MGMT-CLIENT-4' set firewall ipv4 name LAN-MGMT default-action 'drop' set firewall ipv4 name LAN-MGMT default-log set firewall ipv4 name LAN-MGMT description 'LAN -> MGMT' set firewall ipv4 name LAN-MGMT rule 15 action 'drop' set firewall ipv4 name LAN-MGMT rule 15 description 'drop LAN->MGMT traffic from sources without whitelist' set firewall ipv4 name LAN-MGMT rule 15 log set firewall ipv4 name LAN-MGMT rule 15 source group network-group '!MGMT-CLIENT-4' set firewall ipv4 name LAN-MGMT rule 20 action 'accept' set firewall ipv4 name LAN-MGMT rule 20 protocol 'icmp' set firewall ipv4 name LAN-MGMT rule 1010 action 'accept' set firewall ipv4 name LAN-MGMT rule 1010 description 'allow SSH' set firewall ipv4 name LAN-MGMT rule 1010 destination port '22' set firewall ipv4 name LAN-MGMT rule 1010 protocol 'tcp' set firewall ipv4 name LAN-MGMT rule 1020 action 'accept' set firewall ipv4 name LAN-MGMT rule 1020 description 'allow HTTP(S)' set firewall ipv4 name LAN-MGMT rule 1020 destination port '80,443' set firewall ipv4 name LAN-MGMT rule 1020 protocol 'tcp' set firewall ipv4 name LAN-WAN default-action 'drop' set firewall ipv4 name LAN-WAN default-log set firewall ipv4 name LAN-WAN description 'LAN -> WAN' set firewall ipv4 name LAN-WAN rule 30 action 'accept' set firewall ipv4 name LAN-WAN rule 30 description 'temp rule to allow all outbound traffic' set firewall ipv4 name LOCAL-DMZ default-action 'reject' set firewall ipv4 name LOCAL-DMZ default-log set firewall ipv4 name LOCAL-DMZ description 'LOCAL -> DMZ' set firewall ipv4 name LOCAL-DMZ rule 20 action 'jump' set firewall ipv4 name LOCAL-DMZ rule 20 jump-target 'J-ICMP-OUT' set firewall ipv4 name LOCAL-DMZ rule 20 protocol 'icmp' set firewall ipv4 name LOCAL-DMZ rule 30 action 'accept' set firewall ipv4 name LOCAL-DMZ rule 30 description 'temp rule to allow all outbound traffic' set firewall ipv4 name LOCAL-GUEST default-action 'reject' set firewall ipv4 name LOCAL-GUEST default-log set firewall ipv4 name LOCAL-GUEST description 'LOCAL -> GUEST' set firewall ipv4 name LOCAL-GUEST rule 20 action 'jump' set firewall ipv4 name LOCAL-GUEST rule 20 jump-target 'J-ICMP-OUT' set firewall ipv4 name LOCAL-GUEST rule 20 protocol 'icmp' set firewall ipv4 name LOCAL-GUEST rule 30 action 'accept' set firewall ipv4 name LOCAL-GUEST rule 30 description 'temp rule to allow all outbound traffic' set firewall ipv4 name LOCAL-IOT default-action 'reject' set firewall ipv4 name LOCAL-IOT default-log set firewall ipv4 name LOCAL-IOT description 'LOCAL -> IOT' set firewall ipv4 name LOCAL-IOT rule 20 action 'jump' set firewall ipv4 name LOCAL-IOT rule 20 jump-target 'J-ICMP-OUT' set firewall ipv4 name LOCAL-IOT rule 20 protocol 'icmp' set firewall ipv4 name LOCAL-IOT rule 30 action 'accept' set firewall ipv4 name LOCAL-IOT rule 30 description 'temp rule to allow all outbound traffic' set firewall ipv4 name LOCAL-LAN default-action 'reject' set firewall ipv4 name LOCAL-LAN default-log set firewall ipv4 name LOCAL-LAN description 'LOCAL -> LAN' set firewall ipv4 name LOCAL-LAN rule 20 action 'jump' set firewall ipv4 name LOCAL-LAN rule 20 jump-target 'J-ICMP-OUT' set firewall ipv4 name LOCAL-LAN rule 20 protocol 'icmp' set firewall ipv4 name LOCAL-LAN rule 30 action 'accept' set firewall ipv4 name LOCAL-LAN rule 30 description 'temp rule to allow all outbound traffic' set firewall ipv4 name LOCAL-MGMT default-action 'reject' set firewall ipv4 name LOCAL-MGMT default-log set firewall ipv4 name LOCAL-MGMT description 'LOCAL -> MGMT' set firewall ipv4 name LOCAL-MGMT rule 20 action 'jump' set firewall ipv4 name LOCAL-MGMT rule 20 jump-target 'J-ICMP-OUT' set firewall ipv4 name LOCAL-MGMT rule 20 protocol 'icmp' set firewall ipv4 name LOCAL-MGMT rule 30 action 'accept' set firewall ipv4 name LOCAL-MGMT rule 30 description 'temp rule to allow all outbound traffic' set firewall ipv4 name LOCAL-SVC default-action 'reject' set firewall ipv4 name LOCAL-SVC default-log set firewall ipv4 name LOCAL-SVC description 'LOCAL -> SVC' set firewall ipv4 name LOCAL-SVC rule 20 action 'jump' set firewall ipv4 name LOCAL-SVC rule 20 jump-target 'J-ICMP-OUT' set firewall ipv4 name LOCAL-SVC rule 20 protocol 'icmp' set firewall ipv4 name LOCAL-SVC rule 30 action 'accept' set firewall ipv4 name LOCAL-SVC rule 30 description 'temp rule to allow all outbound traffic' set firewall ipv4 name LOCAL-WAN default-action 'reject' set firewall ipv4 name LOCAL-WAN default-log set firewall ipv4 name LOCAL-WAN description 'LOCAL -> WAN' set firewall ipv4 name LOCAL-WAN rule 15 action 'accept' set firewall ipv4 name LOCAL-WAN rule 15 description 'allow WireGuard' set firewall ipv4 name LOCAL-WAN rule 15 destination group port-group 'WIREGUARD' set firewall ipv4 name LOCAL-WAN rule 15 log set firewall ipv4 name LOCAL-WAN rule 15 protocol 'udp' set firewall ipv4 name LOCAL-WAN rule 15 source group port-group 'WIREGUARD' set firewall ipv4 name LOCAL-WAN rule 20 action 'jump' set firewall ipv4 name LOCAL-WAN rule 20 jump-target 'J-ICMP-OUT' set firewall ipv4 name LOCAL-WAN rule 20 protocol 'icmp' set firewall ipv4 name LOCAL-WAN rule 30 action 'accept' set firewall ipv4 name LOCAL-WAN rule 30 description 'temp rule to allow all outbound traffic' set firewall ipv4 name MGMT-LAN default-action 'drop' set firewall ipv4 name MGMT-LAN default-log set firewall ipv4 name MGMT-LAN description 'MGMT -> LAN' set firewall ipv4 name MGMT-LAN rule 15 action 'drop' set firewall ipv4 name MGMT-LAN rule 15 description 'drop MGMT->LAN traffic to destinations without whitelist' set firewall ipv4 name MGMT-LAN rule 15 destination group network-group '!MGMT-CLIENT-4' set firewall ipv4 name MGMT-LAN rule 15 log set firewall ipv4 name MGMT-LAN rule 30 action 'accept' set firewall ipv4 name MGMT-LAN rule 30 description 'temp rule to allow all traffic' set firewall ipv4 name MGMT-LOCAL default-action 'drop' set firewall ipv4 name MGMT-LOCAL default-log set firewall ipv4 name MGMT-LOCAL description 'MGMT -> LOCAL' set firewall ipv4 name MGMT-LOCAL rule 20 action 'jump' set firewall ipv4 name MGMT-LOCAL rule 20 jump-target 'J-ICMP-IN' set firewall ipv4 name MGMT-LOCAL rule 20 protocol 'icmp' set firewall ipv4 name MGMT-LOCAL rule 110 action 'accept' set firewall ipv4 name MGMT-LOCAL rule 110 description 'allow DHCP in MGMT-HOME' set firewall ipv4 name MGMT-LOCAL rule 110 destination port '67' set firewall ipv4 name MGMT-LOCAL rule 110 inbound-interface group 'MGMT-HOME' set firewall ipv4 name MGMT-LOCAL rule 110 protocol 'udp' set firewall ipv4 name MGMT-LOCAL rule 110 source port '68' set firewall ipv4 name MGMT-LOCAL rule 120 action 'accept' set firewall ipv4 name MGMT-LOCAL rule 120 description 'allow NTP' set firewall ipv4 name MGMT-LOCAL rule 120 destination port '123' set firewall ipv4 name MGMT-LOCAL rule 120 protocol 'udp' set firewall ipv4 name MGMT-LOCAL rule 130 action 'accept' set firewall ipv4 name MGMT-LOCAL rule 130 description 'allow DNS' set firewall ipv4 name MGMT-LOCAL rule 130 destination port '53' set firewall ipv4 name MGMT-LOCAL rule 130 protocol 'tcp_udp' set firewall ipv4 name MGMT-WAN default-action 'reject' set firewall ipv4 name MGMT-WAN default-log set firewall ipv4 name MGMT-WAN description 'MGMT -> WAN' set firewall ipv4 name MGMT-WAN rule 30 action 'accept' set firewall ipv4 name MGMT-WAN rule 30 description 'temp rule to allow all outbound traffic' set firewall ipv4 name SVC-LOCAL default-action 'drop' set firewall ipv4 name SVC-LOCAL default-log set firewall ipv4 name SVC-LOCAL description 'SVC -> LOCAL' set firewall ipv4 name SVC-LOCAL rule 20 action 'jump' set firewall ipv4 name SVC-LOCAL rule 20 jump-target 'J-ICMP-IN' set firewall ipv4 name SVC-LOCAL rule 20 protocol 'icmp' set firewall ipv4 name SVC-LOCAL rule 30 action 'jump' set firewall ipv4 name SVC-LOCAL rule 30 destination group port-group 'LOCAL-SERVICES' set firewall ipv4 name SVC-LOCAL rule 30 jump-target 'J-LOCAL-SERVICES-IN' set firewall ipv4 name SVC-LOCAL rule 30 protocol 'tcp_udp' set firewall ipv4 name SVC-WAN default-action 'drop' set firewall ipv4 name SVC-WAN default-log set firewall ipv4 name SVC-WAN description 'SVC -> WAN' set firewall ipv4 name SVC-WAN rule 30 action 'accept' set firewall ipv4 name SVC-WAN rule 30 description 'temp rule to allow all outbound traffic' set firewall ipv4 name WAN-LOCAL default-action 'drop' set firewall ipv4 name WAN-LOCAL description 'WAN -> LOCAL' set firewall ipv4 name WAN-LOCAL rule 15 action 'accept' set firewall ipv4 name WAN-LOCAL rule 15 description 'allow WireGuard' set firewall ipv4 name WAN-LOCAL rule 15 destination group port-group 'WIREGUARD' set firewall ipv4 name WAN-LOCAL rule 15 log set firewall ipv4 name WAN-LOCAL rule 15 protocol 'udp' set firewall ipv4 name WAN-LOCAL rule 15 source group port-group 'WIREGUARD' set firewall ipv4 name WAN-LOCAL rule 20 action 'jump' set firewall ipv4 name WAN-LOCAL rule 20 jump-target 'J-ICMP-IN' set firewall ipv4 name WAN-LOCAL rule 20 protocol 'icmp' set firewall zone DMZ default-action 'drop' set firewall zone DMZ default-log set firewall zone DMZ from LOCAL firewall name 'LOCAL-DMZ' set firewall zone DMZ member interface 'br0.3144' set firewall zone GUEST default-action 'drop' set firewall zone GUEST default-log set firewall zone GUEST from LOCAL firewall name 'LOCAL-GUEST' set firewall zone GUEST member interface 'br0.3010' set firewall zone IOT default-action 'drop' set firewall zone IOT default-log set firewall zone IOT from LOCAL firewall name 'LOCAL-IOT' set firewall zone IOT member interface 'br0.3000' set firewall zone LAN default-action 'drop' set firewall zone LAN default-log set firewall zone LAN from LOCAL firewall name 'LOCAL-LAN' set firewall zone LAN from MGMT firewall name 'MGMT-LAN' set firewall zone LAN member interface 'br0.3210' set firewall zone LOCAL default-action 'drop' set firewall zone LOCAL default-log set firewall zone LOCAL from DMZ firewall name 'DMZ-LOCAL' set firewall zone LOCAL from GUEST firewall name 'GUEST-LOCAL' set firewall zone LOCAL from IOT firewall name 'IOT-LOCAL' set firewall zone LOCAL from LAN firewall name 'LAN-LOCAL' set firewall zone LOCAL from MGMT firewall name 'MGMT-LOCAL' set firewall zone LOCAL from SVC firewall name 'SVC-LOCAL' set firewall zone LOCAL from WAN firewall name 'WAN-LOCAL' set firewall zone LOCAL local-zone set firewall zone MGMT default-action 'drop' set firewall zone MGMT default-log set firewall zone MGMT from LAN firewall name 'LAN-MGMT' set firewall zone MGMT from LOCAL firewall name 'LOCAL-MGMT' set firewall zone MGMT member interface 'br0.3110' set firewall zone MGMT member interface 'wg0' set firewall zone SVC default-action 'drop' set firewall zone SVC default-log set firewall zone SVC from LOCAL firewall name 'LOCAL-SVC' set firewall zone SVC member interface 'br0.3128' set firewall zone WAN default-action 'drop' set firewall zone WAN from DMZ firewall name 'DMZ-WAN' set firewall zone WAN from GUEST firewall name 'GUEST-WAN' set firewall zone WAN from IOT firewall name 'IOT-WAN' set firewall zone WAN from LAN firewall name 'LAN-WAN' set firewall zone WAN from LOCAL firewall name 'LOCAL-WAN' set firewall zone WAN from MGMT firewall name 'MGMT-WAN' set firewall zone WAN from SVC firewall name 'SVC-WAN' set firewall zone WAN member interface 'pppoe0' set interfaces bridge br0 enable-vlan set interfaces bridge br0 ip disable-forwarding set interfaces bridge br0 ipv6 accept-dad '0' set interfaces bridge br0 ipv6 address no-default-link-local set interfaces bridge br0 ipv6 disable-forwarding set interfaces bridge br0 ipv6 dup-addr-detect-transmits '0' set interfaces bridge br0 member interface eth0 allowed-vlan '3000' set interfaces bridge br0 member interface eth0 allowed-vlan '3010' set interfaces bridge br0 member interface eth0 allowed-vlan '3110' set interfaces bridge br0 member interface eth0 allowed-vlan '3210' set interfaces bridge br0 member interface eth0 cost '1000' set interfaces bridge br0 member interface eth0 priority '32' set interfaces bridge br0 member interface eth2 allowed-vlan '3000' set interfaces bridge br0 member interface eth2 allowed-vlan '3010' set interfaces bridge br0 member interface eth2 allowed-vlan '3110' set interfaces bridge br0 member interface eth2 allowed-vlan '3210' set interfaces bridge br0 member interface eth2 allowed-vlan '3128' set interfaces bridge br0 member interface eth2 allowed-vlan '3144' set interfaces bridge br0 member interface eth2 priority '2' set interfaces bridge br0 member interface eth3 allowed-vlan '3110' set interfaces bridge br0 member interface eth3 allowed-vlan '3128' set interfaces bridge br0 member interface eth3 priority '4' set interfaces bridge br0 priority '128' set interfaces bridge br0 stp set interfaces bridge br0 vif 3000 address '192.168.0.1/23' set interfaces bridge br0 vif 3000 description 'IOT' set interfaces bridge br0 vif 3000 ip adjust-mss 'clamp-mss-to-pmtu' set interfaces bridge br0 vif 3000 ipv6 accept-dad '0' set interfaces bridge br0 vif 3000 ipv6 address no-default-link-local set interfaces bridge br0 vif 3000 ipv6 disable-forwarding set interfaces bridge br0 vif 3000 ipv6 dup-addr-detect-transmits '0' set interfaces bridge br0 vif 3010 address '192.168.10.1/23' set interfaces bridge br0 vif 3010 description 'GUEST' set interfaces bridge br0 vif 3010 ip adjust-mss 'clamp-mss-to-pmtu' set interfaces bridge br0 vif 3010 ipv6 accept-dad '0' set interfaces bridge br0 vif 3010 ipv6 address no-default-link-local set interfaces bridge br0 vif 3010 ipv6 disable-forwarding set interfaces bridge br0 vif 3010 ipv6 dup-addr-detect-transmits '0' set interfaces bridge br0 vif 3110 address '192.168.110.1/23' set interfaces bridge br0 vif 3110 description 'MGMT-HOME' set interfaces bridge br0 vif 3110 ip adjust-mss 'clamp-mss-to-pmtu' set interfaces bridge br0 vif 3110 ipv6 accept-dad '0' set interfaces bridge br0 vif 3110 ipv6 address no-default-link-local set interfaces bridge br0 vif 3110 ipv6 disable-forwarding set interfaces bridge br0 vif 3110 ipv6 dup-addr-detect-transmits '0' set interfaces bridge br0 vif 3128 address '192.168.128.1/20' set interfaces bridge br0 vif 3128 description 'SVC' set interfaces bridge br0 vif 3128 ip adjust-mss 'clamp-mss-to-pmtu' set interfaces bridge br0 vif 3128 ipv6 accept-dad '0' set interfaces bridge br0 vif 3128 ipv6 address no-default-link-local set interfaces bridge br0 vif 3128 ipv6 disable-forwarding set interfaces bridge br0 vif 3128 ipv6 dup-addr-detect-transmits '0' set interfaces bridge br0 vif 3144 address '192.168.144.1/20' set interfaces bridge br0 vif 3144 description 'DMZ' set interfaces bridge br0 vif 3144 ip adjust-mss 'clamp-mss-to-pmtu' set interfaces bridge br0 vif 3144 ipv6 accept-dad '0' set interfaces bridge br0 vif 3144 ipv6 address no-default-link-local set interfaces bridge br0 vif 3144 ipv6 disable-forwarding set interfaces bridge br0 vif 3144 ipv6 dup-addr-detect-transmits '0' set interfaces bridge br0 vif 3210 address '192.168.210.1/23' set interfaces bridge br0 vif 3210 description 'LAN' set interfaces bridge br0 vif 3210 ip adjust-mss 'clamp-mss-to-pmtu' set interfaces bridge br0 vif 3210 ipv6 accept-dad '0' set interfaces bridge br0 vif 3210 ipv6 address no-default-link-local set interfaces bridge br0 vif 3210 ipv6 disable-forwarding set interfaces bridge br0 vif 3210 ipv6 dup-addr-detect-transmits '0' set interfaces ethernet eth0 description 'GbE Port 1' set interfaces ethernet eth0 hw-id '00:60:e0:96:6d:65' set interfaces ethernet eth0 ip disable-forwarding set interfaces ethernet eth0 ipv6 accept-dad '0' set interfaces ethernet eth0 ipv6 address no-default-link-local set interfaces ethernet eth0 ipv6 disable-forwarding set interfaces ethernet eth0 ipv6 dup-addr-detect-transmits '0' set interfaces ethernet eth1 description 'GbE Port 2' set interfaces ethernet eth1 hw-id '00:60:e0:96:6d:66' set interfaces ethernet eth2 description 'SFP+ Port 3' set interfaces ethernet eth2 hw-id '00:60:e0:96:6d:63' set interfaces ethernet eth2 mirror egress 'eth1' set interfaces ethernet eth2 mirror ingress 'eth1' set interfaces ethernet eth3 description 'Bridge attached from hv0-br0' set interfaces ethernet eth3 hw-id '52:54:00:08:0c:f8' set interfaces ethernet eth3 ip disable-forwarding set interfaces ethernet eth3 ipv6 accept-dad '0' set interfaces ethernet eth3 ipv6 address no-default-link-local set interfaces ethernet eth3 ipv6 disable-forwarding set interfaces ethernet eth3 ipv6 dup-addr-detect-transmits '0' set interfaces ethernet eth4 description 'GbE Port 5' set interfaces ethernet eth4 disable set interfaces ethernet eth4 hw-id '00:60:e0:96:6d:69' set interfaces ethernet eth5 description 'GbE Port 6' set interfaces ethernet eth5 hw-id '00:60:e0:96:6d:6a' set interfaces ethernet eth5 ip disable-forwarding set interfaces ethernet eth5 ipv6 accept-dad '0' set interfaces ethernet eth5 ipv6 address no-default-link-local set interfaces ethernet eth5 ipv6 disable-forwarding set interfaces ethernet eth5 ipv6 dup-addr-detect-transmits '0' set interfaces ethernet eth5 vif 7 description 'source interface of pppoe0' set interfaces ethernet eth5 vif 7 ip disable-forwarding set interfaces ethernet eth5 vif 7 ipv6 accept-dad '0' set interfaces ethernet eth5 vif 7 ipv6 address no-default-link-local set interfaces ethernet eth5 vif 7 ipv6 disable-forwarding set interfaces ethernet eth5 vif 7 ipv6 dup-addr-detect-transmits '0' set interfaces loopback lo set interfaces pppoe pppoe0 authentication password 'XXX' set interfaces pppoe pppoe0 authentication username 'XXX' set interfaces pppoe pppoe0 description 'WAN (DSL)' set interfaces pppoe pppoe0 ip adjust-mss '1452' set interfaces pppoe pppoe0 ipv6 disable-forwarding set interfaces pppoe pppoe0 mtu '1492' set interfaces pppoe pppoe0 no-peer-dns set interfaces pppoe pppoe0 source-interface 'eth5.7' set interfaces wireguard wg0 address '192.168.104.1/22' set interfaces wireguard wg0 description 'MGMT (Cloud)' set interfaces wireguard wg0 ip adjust-mss 'clamp-mss-to-pmtu' set interfaces wireguard wg0 ipv6 accept-dad '0' set interfaces wireguard wg0 ipv6 address no-default-link-local set interfaces wireguard wg0 ipv6 disable-forwarding set interfaces wireguard wg0 ipv6 dup-addr-detect-transmits '0' set interfaces wireguard wg0 mtu '1412' set interfaces wireguard wg0 port '32524' set nat source rule 210 description 'MGMT client SNAT (MGMT-CLOUD)' set nat source rule 210 destination group network-group 'NET-MGMT-CLOUD-4' set nat source rule 210 outbound-interface name 'wg0' set nat source rule 210 source group network-group 'MGMT-CLIENT-4' set nat source rule 210 translation address 'masquerade' set nat source rule 9000 description 'default gateway SNAT (WAN/DSL)' set nat source rule 9000 outbound-interface name 'pppoe0' set nat source rule 9000 source group network-group 'PRIVATE-4-ALLOW-WAN-DIRECT' set nat source rule 9000 translation address 'masquerade' set system conntrack modules nfs set system conntrack modules tftp set system host-name 'r0' set system ipv6 disable-forwarding set system ipv6 strict-dad