xref: /netbsd-src/external/bsd/ipf/dist/rules/example.10 (revision bc4097aacfdd9307c19b7947c13c6ad6982527a9)
1#	$NetBSD: example.10,v 1.1.1.1 2012/03/23 21:20:15 christos Exp $
2#
3# pass ack packets (ie established connection)
4#
5pass in proto tcp from 10.1.0.0/16 port = 23 to 10.2.0.0/16 flags A/A
6pass out proto tcp from 10.1.0.0/16 port = 23 to 10.2.0.0/16 flags A/A
7#
8# block incoming connection requests to my internal network from the big bad
9# internet.
10#
11block in on le0 proto tcp from any to 10.1.0.0/16 flags S/SA
12#  to block the replies:
13block out on le0 proto tcp from 10.1.0.0 to any flags SA/SA
14