Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #scrub in all no-df random-id
- set skip on lo0
- nat-anchor "ftp-proxy/*"
- rdr-anchor "ftp-proxy/*"
- rdr pass proto tcp from any to any port 21 -> 127.0.0.1 port 8021
- anchor "ftp-proxy/*"
- pass quick proto {icmp, icmp6, ospf}
- pass out quick on {re2, re3} proto carp keep state (no-sync)
- anchor quick from any to (re0) {
- pass quick proto tcp from any to any port 22
- block return log (to pflog1)
- }
- #block in quick on re2 from urpf-failed
- #block in quick on re3 from urpf-failed
- anchor quick from any to (re2:network) {
- pass quick log proto tcp from any to any port 22 synproxy state
- #block return log (to pflog1)
- }
- anchor quick from any to (re3:network) {
- pass quick proto tcp from any to any port {20,21,22} modulate state
- #block return log (to pflog1)
- }
- pass in quick on {re2, re3} flags any keep state
- # block return in log (to pflog1)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement