Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- table <blockedips> persist file "/etc/pf.blocked.ip.conf"
- set skip on lo
- match out on egress inet from !(egress) to any nat-to (egress:0)
- block in log
- pass out quick
- pass in inet proto icmp all
- pass in on fxp1
- pass in on fxp0 proto tcp from any to any port 22 rdr-to 192.168.10.200
- pass in on fxp0 proto tcp from any to any port 443 rdr-to 192.168.10.200
- block drop in log (all) quick on fxp0 from <blockedips> to any
Add Comment
Please, Sign In to add comment