Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # FreeBSD/i386 zakken.hiphop.no
- ext_if = "rl0"
- int_if = "ep0"
- set block-policy return
- set skip on { lo0 }
- scrub in
- table <bruteforce> persist
- nat on $ext_if from $int_if:network to any -> ($ext_if)
- rdr on $ext_if proto tcp from any to any port 30000 -> 192.168.187.2 port 30000
- pass out keep state
- pass quick on $int_if
- block in
- block quick from <bruteforce>
- pass in on $ext_if inet proto tcp from any to any port { 20, 21, 25, 53, 113, 49152:65535 } keep state (max-src-conn 100, max-src-conn-rate 15/5, overload <bruteforce> flush global)
- pass in on $ext_if inet proto tcp from any to any port 22 keep state (max-src-conn 15, max-src-conn-rate 5/3, overload <bruteforce> flush global)
- pass in on $ext_if inet proto udp from any to any port 53 keep state
- pass in on $ext_if inet proto icmp from any to any keep state
Add Comment
Please, Sign In to add comment