pass in quick on $ext_if_cnc inet proto tcp from any to $ext_if_cnc port $open_services flags S/SA keep state
pass in quick on $ext_if_cnc inet proto tcp from any to $ext_if_cnc port 45000:45100 flags S/SA keep state
table <auto_block> persist
block in quick from <auto_block>
pass in on $ext_if_cnc proto tcp from any to $ext_if_cnc port 80 flags S/SA keep state (source-track rule, max-src-conn-rate 30/5, max-src-states 10, overload <auto_block> flush, src.track 1)
复制代码
帮忙看下上述规则什么地方出错了 老是把我挡到防火墙外边
[ 本帖最后由 cnbist 于 2008-11-22 12:18 编辑 ]作者: 剑心通明 时间: 2008-11-22 14:30
block drop in quick on $ext_if_cnc all