From: "Tue Topholm" <none@tt--device.dk.lh.bsd-dk.dk> To: <none@bsd-dk--bsd-dk.dk.lh.bsd-dk.dk> Subject: Pf igen igen Date: Fri, 5 Nov 2004 15:28:07 +0100
Jeg fulgte Michael Knudsens anbefaling, men det virker stadigvæk ik:
Her er mine regler:
#Servers ip'er
WIN = "1.2.3.4"
Linux = "2.3.4.5"
#Samling af servers ip'er i grupper
alle_ssh = "{" $Linux "}"
alle_vnc = "{" $WIN "}"
alle_www = "{" $WIN $Linux "}"
#Bloker alt
block log all
#SSH
pass in proto tcp from any to $alle_ssh port ssh flags S/SA modulate state
#VNC
pass in proto tcp from any to $alle_vnc port 5900 flags S/SA modulate state
#WWW
pass in proto tcp from any to $alle_www port http flags S/SA modulate state
Men det virker ikke hvorfor ik det.
/Tue
This archive was generated by hypermail 2b30 : Wed 15 Nov 2006 - 18:24:46 CET