From a053c81939792582636a131c7640cf954b7638fd Mon Sep 17 00:00:00 2001 From: "Kali Kaneko (leap communications)" Date: Wed, 22 Feb 2017 01:42:50 +0100 Subject: [pkg] add osx helpers --- src/leap/bitmask/vpn/fw/osx/bitmask.pf.conf | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 src/leap/bitmask/vpn/fw/osx/bitmask.pf.conf (limited to 'src/leap/bitmask/vpn/fw/osx/bitmask.pf.conf') diff --git a/src/leap/bitmask/vpn/fw/osx/bitmask.pf.conf b/src/leap/bitmask/vpn/fw/osx/bitmask.pf.conf new file mode 100644 index 00000000..eb0e858f --- /dev/null +++ b/src/leap/bitmask/vpn/fw/osx/bitmask.pf.conf @@ -0,0 +1,17 @@ +default_device = "en99" + +set block-policy drop +set skip on lo0 + +# block all traffic on default device +block out on $default_device all + +# allow traffic to gateways +pass out on $default_device to + +# allow traffic to local networks over the default device +pass out on $default_device to $default_device:network + +# block all DNS, except to the gateways +block out proto udp to any port 53 +pass out proto udp to port 53 -- cgit v1.2.3