以前是这样写的:
ext1_if="em0"
ext1_ip="211.*.*.*"
ext2_if="em1"
ext2_ip="218.*.*.*"
icmp_types=“echoreq”
set skip on lo
block in
pass out
pass in quick inet proto icmp all icmp-type $icmp_types
pass in on ext1_if proto {tcp,udp,icmp} reply-to (ext1_if $ext1_ip)
pass in on ext2_if proto {tcp,udp,icmp} reply-to (ext2_if $ext2_ip)
pass in on ext1_if proto {tcp,udp,icmp} reply-to (ext1_if $ext1_ip)
pass in on ext2_if proto {tcp,udp,icmp} reply-to (ext2_if $ext2_ip)
这写法有问题吧?
pass in quick on $ext1_if reply-to ($ext1_if $ext1_ip) proto {tcp,udp,icmp} from any to any keep state
pass in quick on $ext2_if reply-to ($ext2_if $ext2_ip) proto {tcp,udp,icmp} from any to any keep state作者: qinjuan710 时间: 2011-03-04 08:28 回复 5#congli