My ipfilter rules.

Shaun T. Erickson ste at ste-land.com
Wed Mar 3 14:57:35 PST 2004


I wrote:

> I was wondering if some of you, who are good at, would critique my 
> rules.
> 
> Here's the file: http://www.ste-land.com/rules.html

So far, I've gotten these suggestions:

Apply the bogon list to the outbound path.
Compress my blocking of netbios junk to one rule.
Move bad options & flags check to head of list.

Any other suggestions?

Question: Is there some way I can have all outbound packets skip being 
tested by rules for inbound packets, and vice versa?

	-ste



More information about the freebsd-questions mailing list