用ipfilter在动态ip环境下做重定向( 三 )


pass in quick on $EXT_NIC proto tcp from any to any port = 80 keep state
pass in quick on $EXT_NIC proto tcp from any to any port = 443 keep state

#for mail
pass in quick on $EXT_NIC proto tcp from any to any port = 25 keep state
pass in quick on $EXT_NIC proto tcp from any to any port = 110 keep state

pass out quick on $EXT_NIC proto tcp/udp from any to any keep state
pass out quick on $EXT_NIC proto icmp from any to any keep state

block return-rst in log on $EXT_NIC proto tcp from any to any
block return-icmp-as-dest(port-unr) in log on $EXT_NIC proto udp from any to any
#end of /etc/ipf.rules.template

推荐阅读