xref: /freebsd-13.1/share/examples/pf/faq-example2 (revision 42a227f8)
19d7ccc0fSMax Laier# $FreeBSD$
2*42a227f8SMax Laier# $OpenBSD: faq-example2,v 1.4 2006/10/07 04:48:01 mcbride Exp $
39d7ccc0fSMax Laier
49d7ccc0fSMax Laier#
59d7ccc0fSMax Laier# Small, Home Network
69d7ccc0fSMax Laier# http://www.openbsd.org/faq/pf/queueing.html#example1
79d7ccc0fSMax Laier#
89d7ccc0fSMax Laier
99d7ccc0fSMax Laier
109d7ccc0fSMax Laier# enable queueing on the external interface to control traffic going to
119d7ccc0fSMax Laier# the Internet. use the priq scheduler to control only priorities. set
129d7ccc0fSMax Laier# the bandwidth to 610Kbps to get the best performance out of the TCP
139d7ccc0fSMax Laier# ACK queue.
149d7ccc0fSMax Laier
159d7ccc0fSMax Laieraltq on fxp0 priq bandwidth 610Kb queue { std_out, ssh_im_out, dns_out, \
169d7ccc0fSMax Laier        tcp_ack_out }
179d7ccc0fSMax Laier
189d7ccc0fSMax Laier# define the parameters for the child queues.
199d7ccc0fSMax Laier# std_out      - the standard queue. any filter rule below that does not
209d7ccc0fSMax Laier#                explicitly specify a queue will have its traffic added
219d7ccc0fSMax Laier#                to this queue.
229d7ccc0fSMax Laier# ssh_im_out   - interactive SSH and various instant message traffic.
239d7ccc0fSMax Laier# dns_out      - DNS queries.
249d7ccc0fSMax Laier# tcp_ack_out  - TCP ACK packets with no data payload.
259d7ccc0fSMax Laier
269d7ccc0fSMax Laierqueue std_out     priq(default)
279d7ccc0fSMax Laierqueue ssh_im_out  priority 4 priq(red)
289d7ccc0fSMax Laierqueue dns_out     priority 5
299d7ccc0fSMax Laierqueue tcp_ack_out priority 6
309d7ccc0fSMax Laier
319d7ccc0fSMax Laier# enable queueing on the internal interface to control traffic coming in
329d7ccc0fSMax Laier# from the Internet. use the cbq scheduler to control bandwidth. max
339d7ccc0fSMax Laier# bandwidth is 2Mbps.
349d7ccc0fSMax Laier
359d7ccc0fSMax Laieraltq on dc0 cbq bandwidth 2Mb queue { std_in, ssh_im_in, dns_in, bob_in }
369d7ccc0fSMax Laier
379d7ccc0fSMax Laier# define the parameters for the child queues.
389d7ccc0fSMax Laier# std_in      - the standard queue. any filter rule below that does not
399d7ccc0fSMax Laier#               explicitly specify a queue will have its traffic added
409d7ccc0fSMax Laier#               to this queue.
419d7ccc0fSMax Laier# ssh_im_in   - interactive SSH and various instant message traffic.
429d7ccc0fSMax Laier# dns_in      - DNS replies.
439d7ccc0fSMax Laier# bob_in      - bandwidth reserved for Bob's workstation. allow him to
449d7ccc0fSMax Laier#               borrow.
459d7ccc0fSMax Laier
46*42a227f8SMax Laierqueue std_in    bandwidth 1.6Mb cbq(default)
47*42a227f8SMax Laierqueue ssh_im_in bandwidth 200Kb priority 4
48*42a227f8SMax Laierqueue dns_in    bandwidth 120Kb priority 5
499d7ccc0fSMax Laierqueue bob_in    bandwidth 80Kb cbq(borrow)
509d7ccc0fSMax Laier
519d7ccc0fSMax Laier
529d7ccc0fSMax Laier# ... in the filtering section of pf.conf ...
539d7ccc0fSMax Laier
549d7ccc0fSMax Laieralice         = "192.168.0.2"
559d7ccc0fSMax Laierbob           = "192.168.0.3"
569d7ccc0fSMax Laiercharlie       = "192.168.0.4"
579d7ccc0fSMax Laierlocal_net     = "192.168.0.0/24"
589d7ccc0fSMax Laierssh_ports     = "{ 22 2022 }"
599d7ccc0fSMax Laierim_ports      = "{ 1863 5190 5222 }"
609d7ccc0fSMax Laier
619d7ccc0fSMax Laier# filter rules for fxp0 inbound
629d7ccc0fSMax Laierblock in on fxp0 all
639d7ccc0fSMax Laier
649d7ccc0fSMax Laier# filter rules for fxp0 outbound
659d7ccc0fSMax Laierblock out on fxp0 all
66*42a227f8SMax Laierpass  out on fxp0 inet proto tcp from (fxp0) to any \
67*42a227f8SMax Laier        queue(std_out, tcp_ack_out)
68*42a227f8SMax Laierpass  out on fxp0 inet proto { udp icmp } from (fxp0) to any
699d7ccc0fSMax Laierpass  out on fxp0 inet proto { tcp udp } from (fxp0) to any port domain \
70*42a227f8SMax Laier        queue dns_out
719d7ccc0fSMax Laierpass  out on fxp0 inet proto tcp from (fxp0) to any port $ssh_ports \
72*42a227f8SMax Laier        queue(std_out, ssh_im_out)
739d7ccc0fSMax Laierpass  out on fxp0 inet proto tcp from (fxp0) to any port $im_ports \
74*42a227f8SMax Laier        queue(ssh_im_out, tcp_ack_out)
759d7ccc0fSMax Laier
769d7ccc0fSMax Laier# filter rules for dc0 inbound
779d7ccc0fSMax Laierblock in on dc0 all
789d7ccc0fSMax Laierpass  in on dc0 from $local_net
799d7ccc0fSMax Laier
809d7ccc0fSMax Laier# filter rules for dc0 outbound
819d7ccc0fSMax Laierblock out on dc0 all
829d7ccc0fSMax Laierpass  out on dc0 from any to $local_net
839d7ccc0fSMax Laierpass  out on dc0 proto { tcp udp } from any port domain to $local_net \
849d7ccc0fSMax Laier        queue dns_in
859d7ccc0fSMax Laierpass  out on dc0 proto tcp from any port $ssh_ports to $local_net \
869d7ccc0fSMax Laier        queue(std_in, ssh_im_in)
879d7ccc0fSMax Laierpass  out on dc0 proto tcp from any port $im_ports to $local_net \
889d7ccc0fSMax Laier        queue ssh_im_in
899d7ccc0fSMax Laierpass  out on dc0 from any to $bob queue bob_in
90