Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- cat /etc/pf.conf
- set limit { frags 40000, states 100000 }
- int_if = "{" vlan10 vlan14 vlan21 "}"
- table <local_ip> const { self }
- table <admins> { $my_vpn_ip }
- mgmt_port = "{" 21 22 3389 "}"
- # Default
- set skip on lo0
- pass all
- pass in proto igmp all allow-opts
- pass out proto igmp all allow-opts
- pass in quick proto icmp from any to any
- # local IPs
- block in inet proto tcp from any to <local_ip> port 22
- pass in inet proto tcp from <admins> to <local_ip> port 22
- # Mgmt
- block out on $int_if proto tcp from any to any port $mgmt_port
- pass out on $int_if proto tcp from <admins> to any port $mgmt_port
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement