pf rules
    Tim Judd 
    tajudd at gmail.com
       
    Fri Jan 22 13:22:56 UTC 2010
    
    
  
On 1/22/10, kalin m <kalin at el.net> wrote:
>
> hi all...
>
> doing testing with pf...
>
> how is it possible that if i have these rules below in pf.conf if i do:
> telnet that.host.org 25
>
> i get:
> Trying xx.xx.xx.xx...
> Connected to that.host.org.
> Escape character is '^]'.
> ........... etc .......
>
>
> pf.conf contetns:
>
> tcp_in = "{ www, https }"
> ftp_in = "{ ftp }"
> udp = "{ domain, ntp }"
> ping = "echoreq"
>
> set skip on lo
> scrub in
>
> antispoof for eth0 inet
>
> block in all
> pass out all keep state
> pass proto udp to any port $udp
> pass inet proto icmp all icmp-type $ping keep state
> pass in inet proto tcp to any port $tcp_in flags S/SAF synproxy state
> pass proto tcp to any port ssh
>
>
pfctl -s info
  Look for the fact it says "Enabled" (near the top of the screen)
and you're blocking inbound all, but since you're passing out all,
telnetting out will work.  You aren't very clear on which side you
have the pf loaded on, the email indicates it's the client-side you
have pf enabled.  Please clarify.
--TJ
    
    
More information about the freebsd-questions
mailing list