亚洲av成人无遮挡网站在线观看,少妇性bbb搡bbb爽爽爽,亚洲av日韩精品久久久久久,兔费看少妇性l交大片免费,无码少妇一区二区三区

  免費注冊 查看新帖 |

Chinaunix

  平臺 論壇 博客 文庫
最近訪問板塊 發(fā)新帖
查看: 2226 | 回復: 0
打印 上一主題 下一主題

[OpenBSD] OpenBSD 端口重定向中pf.conf setting [復制鏈接]

論壇徽章:
0
跳轉(zhuǎn)到指定樓層
1 [收藏(0)] [報告]
發(fā)表于 2004-04-11 13:03 |只看該作者 |倒序瀏覽
Ext = "ne3" # Ó&Í&½&ÏàÁ&&ÄÉè±&Ã&
Int = "rl0" # Ó&¾ÖÓòÍ&ÏàÁ&&ÄÉè±&Ã&
IntNet = "192.168.0.0/24" # ¾ÖÓòÍ&&ÄÍ&&Î
RouterIP = "192.168.0.1" # ·ÓÉÆ÷&ÄIP&ØÖ·
Loop = "lo0" # Loopback ±¾&Ø&·&ØÉè±&Ã&
ftp_server = "192.168.0.8"
www_server = "192.168.0.8"

# ²&±&·ÓÉ&Ä&ØÖ·
NoRoute = "{ 127.0.0.1/8, 192.168.0.0/16, 172.16.0.0/12, 10.0.0.0/8, 255.255.255.255/32 }"

# ½&±&&ò&&&Ä&Ë&Ú
LocalServicesTCP = "{ ssh, auth }"
OtherServicesTCP = "{ ftp, www, 700 }"


### Ñ&Ï& ###

# DSLÁ&½Ó&Äͳ¼ÆÊ&¾Ý&¨pfctl -s info&&
set loginterface $Ext

# &ìËÙ&Ï&&·Ç&&&&×&Ì&&ÄÁ&½Ó - ¼&ÉÙÄÚ&&Ï&&Ä
set optimization aggressive

# IPËéÆ&ÖØ×é
scrub in on $Ext all fragment reassemble


### NAT &Í×&·& ###

# ¼¤&&NAT
nat on $Ext from $IntNet to any ->; $Ext

# ¼¤&& FTP - ×&·&&½ÎÒÃÇ&Ä ftp-proxy &úÀíÉÏ
#:rdr on $Int proto tcp from !$RouterIP to !$IntNet port 21 ->; 127.0.0.1 port 8081

rdr on $Ext proto tcp from !$IntNet to $Ext port ftp ->; $ftp_server port 21
#rdr on $Ext proto tcp from any to any port 49152:65535 ->; $ftp_server port 49152:65535
rdr on $Ext proto tcp from !$IntNet to $Ext port www ->; $www_server port 80
rdr on $Ext proto tcp from !$IntNet to $Ext port 700 ->; 192.168.0.3 port 700
rdr on $Ext proto udp from !$IntNet to $Ext port 700 ->; 192.168.0.3 port 700### ¹&Â˹&Ôò ###

# Ö&ÊÇÓÃÀ&&÷ÊÔÓÃ....
#pass in quick all # ²&ÊÔÒ&ÏÂÔÊÐíËùÓн&È&&İü
#pass out quick all # &Í·&³&&İü

# ÏÈÊÇ×Ü&ÄÔ&Ôò&&&²×&ËùÓн&³&&ÄÊ&¾Ý°ü
block out on $Ext all
block in on $Ext all

# ÎÒÃÇÄ&Ô&Ò&Éù²&&Ô×°Á&×÷ÑÆ&&&&&&
block return-rst out log on $Ext proto tcp all
block return-rst in log on $Ext proto tcp all
block return-icmp out log on $Ext proto udp all
block return-icmp in log on $Ext proto udp all

# ²&ÐèÒ& IPv6.0
block in quick inet6 all
block out quick inet6 all

# ±¾&Ø&·&ØÔÊÐíͨ¹&
pass in quick on $Loop all
pass out quick on $Loop all

# &&nmap&ÈɨÃèÆ÷À&&&ÄÑ&È
block in log quick on $Ext inet proto tcp from any to any flags FUP/FUP
block in log quick on $Ext inet proto tcp from any to any flags SF/SFRA
block in log quick on $Ext inet proto tcp from any to any flags /SFRA

# &ÔÍ&½&&&·Å&Ä&Ë&Ú
#pass in quick on $Ext inet proto tcp from any to $ftp_server port 21 flags S/SAFR keep state
#pass in quick on $Ext inet proto tcp from any to $ftp_server port >; 49151 flags S/SAFR keep state

#pass in quick on $Int inet proto tcp from any to $ftp_server port 21 flags S/SAFR keep state
#pass in quick on $Int inet proto tcp from any to $ftp_server port >; 49151 flags S/SAFR keep state

pass in quick on $Ext inet proto tcp from !$IntNet to $Ext port $LocalServicesTCP flags S/SAFR keep state
pass in quick on $Ext inet proto tcp from !$IntNet to $IntNet port $OtherServicesTCP flags S/SAFR keep state

# ·ÀÖ¹IPÆÛÆ&
block in log quick on $Ext inet from $NoRoute to any
block in log quick on $Ext inet from any to $NoRoute

# ÔÊÐí FTP Ö÷&&Ä&ʽ
#pass in quick on $Ext inet proto tcp from any to any port >; 49151 user proxy flags S/SAFR keep state

# ÔÊÐí±&ping&¨½&Ö¹Æ&Ê&Ò²Ã&&à&óÒ&Ò&&&
pass in quick on $Ext inet proto icmp all icmp-type 8 code 0 keep state

# &ÔÍ&½&&&·Å&Ä&Ë&Ú
#pass in quick on $Ext inet proto tcp from any to any port $InServicesTCP flags S/SAFR keep state

# ÔÊÐíͨ¹&ÓÉÄÚÏòÍ&&İü
pass out quick on $Ext all keep state
您需要登錄后才可以回帖 登錄 | 注冊

本版積分規(guī)則 發(fā)表回復

  

北京盛拓優(yōu)訊信息技術有限公司. 版權(quán)所有 京ICP備16024965號-6 北京市公安局海淀分局網(wǎng)監(jiān)中心備案編號:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年舉報專區(qū)
中國互聯(lián)網(wǎng)協(xié)會會員  聯(lián)系我們:huangweiwei@itpub.net
感謝所有關心和支持過ChinaUnix的朋友們 轉(zhuǎn)載本站內(nèi)容請注明原作者名及出處

清除 Cookies - ChinaUnix - Archiver - WAP - TOP