summaryrefslogtreecommitdiff
path: root/regress/sbin/pfctl/pf7.in
blob: 02514df9cddb82f157f039d70f8136e1fdd4b6b7 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
# test modulate state

block	       out log on tun1000000		 all
block	       in  log on tun1000000		 all

block return-rst  out log on tun1000000 proto tcp all
block return-rst  in  log on tun1000000 proto tcp all
block return-icmp out log on tun1000000 proto udp all
block return-icmp in  log on tun1000000 proto udp all

block out log quick on tun1000000 from ! 157.161.48.183 to any

block in quick on tun1000000 from any to 255.255.255.255

block in log quick on tun1000000 from 10.0.0.0/8		to any
block in log quick on tun1000000 from 172.16.0.0/12	to any
block in log quick on tun1000000 from 192.168.0.0/16	to any
block in log quick on tun1000000 from 255.255.255.255/32 to any

pass out on tun1000000 inet proto icmp all icmp-type 8 code 0 keep state
pass in  on tun1000000 inet proto icmp all icmp-type 8 code 0 keep state

pass out on tun1000000 proto udp all keep state

pass in on tun1000000 proto udp from any to any port = domain keep state

pass out on tun1000000 proto tcp all modulate state
pass in on tun1000000 proto { tcp udp icmp } all modulate state
pass in on tun1000000 proto { udp tcp icmp } all flags S/SA synproxy state

pass in on tun1000000 proto tcp from any to any port = ssh    modulate state
pass in on tun1000000 proto tcp from any to any port = smtp   modulate state
pass in on tun1000000 proto tcp from any to any port = domain modulate state
pass in on tun1000000 proto tcp from any to any port = auth   modulate state