- 论坛徽章:
- 0
|
本帖最后由 zhucy_ares 于 2010-06-01 13:55 编辑
scrub in all fragment reassemble
anchor "ftp-proxy/*" all
pass out on bce0 proto tcp from any to any port = http flags S/SA keep state queue ext_http
pass out on bce0 proto udp from any to any port = http keep state queue ext_http
pass out on bce0 proto tcp all flags S/SA keep state queue ext_base
pass out on bce0 proto udp all keep state queue ext_base
block drop in on bce1 proto tcp from any to any port = loc-srv
block drop in on bce1 proto tcp from any to any port = netbios-ssn
block drop in on bce1 proto tcp from any to any port = krb524
block drop in on bce1 proto tcp from any to any port = microsoft-ds
block drop in on bce1 proto tcp from any to any port = bootps
block drop in on bce1 proto tcp from any to any port = finger
block drop in on bce1 proto tcp from any to any port = 16881
block drop in on bce1 proto udp from any to any port = loc-srv
block drop in on bce1 proto udp from any to any port = netbios-ssn
block drop in on bce1 proto udp from any to any port = krb524
block drop in on bce1 proto udp from any to any port = microsoft-ds
block drop in on bce1 proto udp from any to any port = bootps
block drop in quick on bce1 from any os "NMAP" to any
block drop in quick on bce0 from any os "NMAP" to any
block drop in quick on bce0 proto tcp all flags FS/FSRA
block drop in quick on bce0 proto tcp all flags FPU/FSRPAU
block drop in quick on bce0 proto tcp all flags /FSRA
block drop in quick on bce0 proto tcp all flags F/FSRA
block drop in quick on bce0 proto tcp all flags U/FSRAU
block drop in quick on bce1 proto tcp all flags FS/FSRA
block drop in quick on bce1 proto tcp all flags FPU/FSRPAU
block drop in quick on bce1 proto tcp all flags /FSRA
block drop in quick on bce1 proto tcp all flags F/FSRA
block drop in quick on bce1 proto tcp all flags U/FSRAU
pass in quick from <vip> to any flags S/SA keep state
pass in on bce1 route-to (bce2 60.248.34.65) inet from 192.168.27.115 to any flags S/SA keep state
pass out on bce0 route-to (bce2 60.248.34.65) inet from 60.248.34.66 to any flags S/SA keep state
block drop in quick from <blockbrute> to any
pass in on bce1 all flags S/SA keep state (source-track rule, max-src-conn 300, overload <blockbrute> flush global)
大概就这些,一共四块网卡。bce0是xx通,bce1是内网,bce2是x信线路,bce3是x通线路。
默认网关在bce0对应的网关上。
我只是想让192.168.27.115这个地址。通过x信线路上网而已。 |
|