|
@ -8,10 +8,18 @@ config network |
|
|
|
|
|
|
|
|
config access |
|
|
config access |
|
|
option SOURCE 'ANY' |
|
|
option SOURCE 'ANY' |
|
|
option HMAC_KEY 'CHANGEME' |
|
|
|
|
|
option KEY 'CHANGEME' |
|
|
|
|
|
|
|
|
option HMAC_KEY '__CHANGEME__' |
|
|
|
|
|
option KEY '__CHANGEME__' |
|
|
|
|
|
|
|
|
config config |
|
|
config config |
|
|
# Alternative direct physical interface definition, but untracked - you |
|
|
# Alternative direct physical interface definition, but untracked - you |
|
|
# are on your own to correctly start/stop the service when needed |
|
|
# are on your own to correctly start/stop the service when needed |
|
|
# option PCAP_INTF 'eth0' |
|
|
# option PCAP_INTF 'eth0' |
|
|
|
|
|
|
|
|
|
|
|
# Allow SPA clients to request access to services through an iptables |
|
|
|
|
|
# firewall instead of just to it (i.e. access through the FWKNOP_FORWARD |
|
|
|
|
|
# chain instead of the INPUT chain |
|
|
|
|
|
option ENABLE_IPT_FORWARDING 'Y' |
|
|
|
|
|
|
|
|
|
|
|
# Allow fwknopd to resolve hostnames in NAT access messages |
|
|
|
|
|
option ENABLE_NAT_DNS 'Y' |