Re: pf rules

看板FB_security作者時間16年前 (2010/01/23 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串10/11 (看更多)
Others have already given some good feedback (and asked some good questions), but: > pass out all keep state You're allowing out the initial TCP SYN, and creating a state entry for the connection here. You should be able to make outgoing connections anywhere with this rule. Once a state entry gets created, the state table will match on the traffic for the session, and the rules list won't have to be evaluated. J. -- Jason V. Miller _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #1BMUVZtP (FB_security)
文章代碼(AID): #1BMUVZtP (FB_security)