freebsd-dev/sbin/pfctl/tests/files/pf0011.ok

19 lines
1.1 KiB
Plaintext
Raw Normal View History

pass in inet proto icmp all icmp-type echorep keep state
pass in inet proto icmp all icmp-type echorep code 0 keep state
pass in inet proto icmp all icmp-type 1 keep state
pass in inet proto icmp all icmp-type 1 code 1 keep state
pass in inet6 proto ipv6-icmp all icmp6-type 0 keep state
pass in inet6 proto ipv6-icmp all icmp6-type 0 code 0 keep state
pass in inet6 proto ipv6-icmp all icmp6-type unreach keep state
pass in inet6 proto ipv6-icmp all icmp6-type unreach code admin-unr keep state
block drop in inet proto icmp all icmp-type echorep
block drop in inet proto icmp all icmp-type echorep code 0
block drop in inet proto icmp all icmp-type 1
block drop in inet proto icmp all icmp-type 1 code 1
block drop in inet6 proto ipv6-icmp all icmp6-type 0
block drop in inet6 proto ipv6-icmp all icmp6-type 0 code 0
block drop in inet6 proto ipv6-icmp all icmp6-type unreach
block drop in inet6 proto ipv6-icmp all icmp6-type unreach code admin-unr
pass in inet proto icmp all icmp-type unreach code needfrag keep state
pass in inet6 proto ipv6-icmp all icmp6-type timex code reassemb keep state