set ip-blocklist {
type ipv4_addr
- flags dynamic
+ flags interval
}
set ip6-blocklist {
type ipv6_addr
- flags dynamic
+ flags interval
}
set ratelimit-icmp-echo-ip {
<%- end %>
}
+<%- end %>
+
+<%- node[:networking][:firewall][:helpers].each do |helper| %>
+ ct helper <%= helper[:name] %> {
+ type "<%= helper[:helper] %>" protocol <%= helper[:protocol] %>
+ }
+
<%- end %>
chain log-and-drop {
limit rate 1/second log