- 论坛徽章:
- 0
|
pf.conf的配置
Lan="em1"
Wan="em0"
# Options: tune the behavior of pf, default values are given.
#set timeout { interval 10, frag 30 }
set timeout { tcp.first 120, tcp.opening 30, tcp.established 86400 }
set timeout { tcp.first 120, tcp.opening 30, tcp.established 3600 }
set timeout { tcp.closing 240, tcp.finwait 45, tcp.closed 90 }
set timeout { udp.first 60, udp.single 30, udp.multiple 60 }
set timeout { icmp.first 20, icmp.error 10 }
set timeout { other.first 60, other.single 30, other.multiple 60 }
#set timeout { adaptive.start 0, adaptive.end 0 }
set limit { states 1000000, frags 150000 }
#set loginterface none
set optimization normal
set block-policy drop
#set require-order yes
scrub in all
private_nets = "{ 127.0.0.0/8, 192.168.0.0/16, 172.16.0.0/12, 10.0.0.0/8 }"
Lan_nets="{202.x.x.0/20,222.x.x.0/20}"
nat on $Wan from $Lan_nets to any -> ($Wan)
block in quick proto tcp all flags SF/SFRA
block in quick proto tcp all flags SFUP/SFRAU
block in quick proto tcp all flags FPU/SFRAUP
block in quick proto tcp all flags /SFRA
block in quick proto tcp all flags F/SFRA
block in quick proto tcp all flags U/SFRAU
block in quick proto {tcp,udp} from any to any port 134 >< 140
block in quick proto {tcp,udp} from any to any port = 445
block in quick proto {tcp,udp} from any to any port = 593
block in quick proto {tcp,udp} from any to any port = 333
block in quick proto {tcp,udp} from any to any port = 5554
block in quick proto {tcp,udp} from any to any port = 9995
block in quick proto {tcp,udp} from any to any port = 9996
block in quick proto {tcp,udp} from any to any port = tftp
block in quick proto {tcp,udp} from any to any port = 554
block in quick proto {tcp,udp} from any to any port = 1434
block in quick proto {tcp,udp} from any to any port = 4444
antispoof quick for $Wan inet
block all
pass quick on lo0 all
##############################################
#Wan Interface
#############################################
block drop in quick on $Wan from $private_nets to any
block drop out quick on $Wan from any to $private_nets
pass quick on $Wan all
################################################
#Lan Interface
################################################
pass quick on $Lan all
xeon 2.4GX2,cpu利用率最高到35%,1G ECC DDR 533 RAM,空闲为720M
[ 本帖最后由 wxw2004gl 于 2006-10-11 18:44 编辑 ] |
|