- 论坛徽章:
- 0
|
这是我全部的规则:- 00001 deny ip from any to any dst-port 5801 via sk0
- 00002 deny ip from any to any dst-port 5901 via sk0
- 00003 deny ip from any to any dst-port 6001 via sk0
- 00004 deny ip from any to any dst-port 199 via sk0
- 00049 divert 8668 ip4 from any to any via sk0
- 00050 divert 8668 ip4 from 172.16.100.0/24 to any via sk0
- 00051 divert 8668 ip4 from 192.168.0.0/24 to any via sk0
- 00100 allow ip from any to any via lo0
- 00200 deny ip from any to 127.0.0.0/8
- 00300 deny ip from 127.0.0.0/8 to any
- 00400 deny ip from any to ::1
- 00500 deny ip from ::1 to any
- 00600 allow ipv6-icmp from :: to ff02::/16
- 00700 allow ipv6-icmp from fe80::/10 to fe80::/10
- 00800 allow ipv6-icmp from fe80::/10 to ff02::/16
- 00900 allow ipv6-icmp from any to any ip6 icmp6types 1
- 01000 allow ipv6-icmp from any to any ip6 icmp6types 2,135,136
- 65000 allow ip from any to any
- 65535 allow ip from any to any
复制代码 1~4是关闭指定端口,50和51号本意是想只给某些段过但做不通。
|
|