From 3adf2a2806a69709515f9b6155c786f398b308fb Mon Sep 17 00:00:00 2001 From: bol-van Date: Mon, 24 Jan 2022 14:28:56 +0300 Subject: [PATCH] bsd readme: filter.inc ........ --- docs/bsd.eng.md | 2 ++ docs/bsd.txt | 2 ++ 2 files changed, 4 insertions(+) diff --git a/docs/bsd.eng.md b/docs/bsd.eng.md index 04ea3e2..3baa62f 100644 --- a/docs/bsd.eng.md +++ b/docs/bsd.eng.md @@ -206,12 +206,14 @@ Only PF redirection works. PF does not allow to freely add and delete rules. Onl To make an anchor work it must be referred from the main ruleset. But its managed by pfsense scripts. One possible solution would be to modify '/etc/inc/filter.inc' as follows : ``` + ................. /* MOD */ $natrules .= "# ZAPRET redirection\n"; $natrules .= "rdr-anchor \"zapret/*\"\n"; $natrules .= "# TFTP proxy\n"; $natrules .= "rdr-anchor \"tftp-proxy/*\"\n"; + ................. ``` Write the anchor code to '/etc/zapret.anchor': diff --git a/docs/bsd.txt b/docs/bsd.txt index 29b3408..6f7557d 100644 --- a/docs/bsd.txt +++ b/docs/bsd.txt @@ -207,12 +207,14 @@ dvtws --daemon --port 989 --dpi-desync=split2 Его трогать нельзя, иначе порушится весь фаервол. Поэтому придется править код скриптов pfsense. Поправьте /etc/inc/filter.inc следующим образом : ----------- + ................. /* MOD */ $natrules .= "# ZAPRET redirection\n"; $natrules .= "rdr-anchor \"zapret/*\"\n"; $natrules .= "# TFTP proxy\n"; $natrules .= "rdr-anchor \"tftp-proxy/*\"\n"; + ................. ----------- Напишите файл с содержимым anchor-а (например, /etc/zapret.anchor):