- 论坛徽章:
- 0
|
- ext_if_cnc="bge0"
- cnc_ip="218.61.201.98/32"
- open_services = "{80 21 22}"
- scrub in all
- pass quick on lo0 all keep state
- block drop in quick on $ext_if_cnc all
- pass in quick on $ext_if_cnc inet proto tcp from any to $ext_if_cnc port $open_services flags S/SA keep state
- pass in quick on $ext_if_cnc inet proto tcp from any to $ext_if_cnc port 45000:45100 flags S/SA keep state
- table <auto_block> persist
- block in quick from <auto_block>
- pass in on $ext_if_cnc proto tcp from any to $ext_if_cnc port 80 flags S/SA keep state (source-track rule, max-src-conn-rate 30/5, max-src-states 10, overload <auto_block> flush, src.track 1)
复制代码 帮忙看下上述规则什么地方出错了 老是把我挡到防火墙外边
[ 本帖最后由 cnbist 于 2008-11-22 12:18 编辑 ] |
|