Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- **sudo pfctl -vnf /etc/pf.conf**
- Password:
- pfctl: Use of -f option, could result in flushing of rules
- present in the main ruleset added by the system at startup.
- See /etc/pf.conf for further details.
- scrub-anchor "/*" all fragment reassemble
- nat-anchor "/*" all
- rdr-anchor "/*" all
- anchor "/*" all
- anchor "/*" all
- dummynet-anchor "/*" all
- Loading anchor com.apple from /etc/pf.anchors/com.apple
- anchor "/*" all
- anchor "/*" all
- anchor "/*" all
- Loading anchor com.apple.server-firewall from /etc/pf.anchors/com.apple.server-firewall
- anchor "base" all
- anchor "custom-firewall" all
- Loading anchor com.apple/400.AdaptiveFirewall from /Applications/Server.app/Contents/ServerRoot/private/etc/pf.anchors/400.AdaptiveFirewall
- table <blockedHosts> persist file "/var/db/af/blockedHosts"
- block drop in quick from <blockedHosts> to any
- Loading anchor com.apple.server-firewall/base from /Library/Server/Firewall/Anchors/default_anchor.txt
- block drop in all
- pass in quick proto udp from any port = 67 to any port = 68 keep state
- pass out all flags any keep state
- Loading anchor com.apple.server-firewall/custom-firewall from /Library/Server/Firewall/Anchors/custom_anchor.txt
- pass in inet from 10.0.0.0/8 to any no state
- pass in inet from 192.168.0.0/16 to any no state
- pass in inet from 169.254.0.0/16 to any no state
- pass in inet from 127.0.0.1 to any no state
- pass in inet from 172.16.0.0/12 to any no state
- pass in inet6 from fc00::/7 to any no state
- pass in inet6 from ::1 to any no state
- block drop in proto udp from any to any port = 1701
- block drop in proto udp from any to any port = 500
- block drop in proto udp from any to any port = 4500
- pass in inet proto tcp from 10.0.0.0/8 to any port = 22 no state
- pass in inet proto tcp from 192.168.0.0/16 to any port = 22 no state
- pass in inet proto tcp from 169.254.0.0/16 to any port = 22 no state
- pass in inet proto tcp from 127.0.0.1 to any port = 22 no state
- pass in inet proto tcp from 172.16.0.0/12 to any port = 22 no state
- pass in inet proto tcp from 10.0.0.0/8 to any port = 443 no state
- pass in inet proto tcp from 192.168.0.0/16 to any port = 443 no state
- pass in inet proto tcp from 169.254.0.0/16 to any port = 443 no state
- pass in inet proto tcp from 127.0.0.1 to any port = 443 no state
- pass in inet proto tcp from 172.16.0.0/12 to any port = 443 no state
- pass in inet proto tcp from 10.0.0.0/8 to any port = 80 no state
- pass in inet proto tcp from 192.168.0.0/16 to any port = 80 no state
- pass in inet proto tcp from 169.254.0.0/16 to any port = 80 no state
- pass in inet proto tcp from 127.0.0.1 to any port = 80 no state
- pass in inet proto tcp from 172.16.0.0/12 to any port = 80 no state
- pass in inet6 proto tcp from fc00::/7 to any port = 22 no state
- pass in inet6 proto tcp from fc00::/7 to any port = 443 no state
- pass in inet6 proto tcp from fc00::/7 to any port = 80 no state
- pass in inet6 proto tcp from ::1 to any port = 22 no state
- pass in inet6 proto tcp from ::1 to any port = 443 no state
- pass in inet6 proto tcp from ::1 to any port = 80 no state
- pass in inet proto udp from any to any port = 1701 no state
- pass in inet proto udp from any to any port = 500 no state
- pass in inet proto udp from any to any port = 4500 no state
- pass in inet6 proto udp from any to any port = 1701 no state
- pass in inet6 proto udp from any to any port = 500 no state
- pass in inet6 proto udp from any to any port = 4500 no state
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement