xref: /freebsd/sbin/pfctl/tests/files/pf0007.ok (revision 531c2d7af3cd2e64eec94aa1b19c4b2f16fce515)
1*4d7709ddSKristof Provostblock drop out log on tun1000000 all
2*4d7709ddSKristof Provostblock drop in log on tun1000000 all
3*4d7709ddSKristof Provostblock return-rst out log on tun1000000 proto tcp all
4*4d7709ddSKristof Provostblock return-rst in log on tun1000000 proto tcp all
5*4d7709ddSKristof Provostblock return-icmp(port-unr, port-unr) out log on tun1000000 proto udp all
6*4d7709ddSKristof Provostblock return-icmp(port-unr, port-unr) in log on tun1000000 proto udp all
7*4d7709ddSKristof Provostblock drop out log quick on tun1000000 inet from ! 157.161.48.183 to any
8*4d7709ddSKristof Provostblock drop in quick on tun1000000 inet from any to 255.255.255.255
9*4d7709ddSKristof Provostblock drop in log quick on tun1000000 inet from 10.0.0.0/8 to any
10*4d7709ddSKristof Provostblock drop in log quick on tun1000000 inet from 172.16.0.0/12 to any
11*4d7709ddSKristof Provostblock drop in log quick on tun1000000 inet from 192.168.0.0/16 to any
12*4d7709ddSKristof Provostblock drop in log quick on tun1000000 inet from 255.255.255.255 to any
13*4d7709ddSKristof Provostpass out on tun1000000 inet proto icmp all icmp-type echoreq code 0 keep state
14*4d7709ddSKristof Provostpass in on tun1000000 inet proto icmp all icmp-type echoreq code 0 keep state
15*4d7709ddSKristof Provostpass out on tun1000000 proto udp all keep state
16*4d7709ddSKristof Provostpass in on tun1000000 proto udp from any to any port = domain keep state
17*4d7709ddSKristof Provostpass out on tun1000000 proto tcp all flags S/SA modulate state
18*4d7709ddSKristof Provostpass in on tun1000000 proto tcp all flags S/SA modulate state
19*4d7709ddSKristof Provostpass in on tun1000000 proto udp all keep state
20*4d7709ddSKristof Provostpass in on tun1000000 proto icmp all keep state
21*4d7709ddSKristof Provostpass in on tun1000000 proto udp all keep state
22*4d7709ddSKristof Provostpass in on tun1000000 proto tcp all flags S/SA synproxy state
23*4d7709ddSKristof Provostpass in on tun1000000 proto icmp all keep state
24*4d7709ddSKristof Provostpass in on tun1000000 proto tcp from any to any port = ssh flags S/SA modulate state
25*4d7709ddSKristof Provostpass in on tun1000000 proto tcp from any to any port = smtp flags S/SA modulate state
26*4d7709ddSKristof Provostpass in on tun1000000 proto tcp from any to any port = domain flags S/SA modulate state
27*4d7709ddSKristof Provostpass in on tun1000000 proto tcp from any to any port = auth flags S/SA modulate state
28