# filter what we send upstream domain-needed bogus-priv filterwin2k # allow /etc/hosts and dhcp lookups via *.lan local=/lan/ domain=lan # no dhcp / dns queries from the wan except-interface=vlan1 # enable dhcp (start,end,netmask,leasetime) dhcp-authoritative dhcp-range=192.168.1.100,192.168.1.250,255.255.255.0,12h dhcp-leasefile=/tmp/dhcp.leases # allow a /etc/ethers for static hosts read-ethers # other useful options: # default route(s): dhcp-option=3,192.168.1.1,192.168.1.2 # dns server(s): dhcp-option=6,192.168.1.1,192.168.1.2