Portál AbcLinuxu, 31. října 2025 06:26
/etc/rc.d/pf status
No ALTQ support in kernel
ALTQ related functions disabled
Status: Enabled for 0 days 00:03:47           Debug: Urgent
Interface Stats for re0               IPv4             IPv6
  Bytes In                          434781                0
  Bytes Out                          97360                0
  Packets In
    Passed                             568                0
    Blocked                           6146                0
  Packets Out
    Passed                             425                0
    Blocked                              1                0
State Table                          Total             Rate
  current entries                        3               
  searches                            7139           31.4/s
  inserts                                9            0.0/s
  removals                               9            0.0/s
Counters
  match                               6161           27.1/s
  bad-offset                             0            0.0/s
  fragment                               0            0.0/s
  short                                  0            0.0/s
  normalize                              0            0.0/s
  memory                                 0            0.0/s
  bad-timestamp                          0            0.0/s
  congestion                             0            0.0/s
  ip-option                              0            0.0/s
  proto-cksum                            1            0.0/s
  state-mismatch                         1            0.0/s
  state-insert                           0            0.0/s
  state-limit                            0            0.0/s
  src-limit                              0            0.0/s
  synproxy                               0            0.0/s
Chtěl bych se zeptat co znamená ALTQ?
Ještě bych vás chtěl poprosit, nemohl by mi někdo sem pastnout nějaký pf.conf stím co kde defaultně blokovat? Na co nezapomenout atd...
Můj pf.conf
cat /etc/pf.conf 
# $FreeBSD: src/share/examples/pf/faq-example1,v 1.2.2.1.6.1 2010/12/21 17:09:25 kensmith Exp $
# $OpenBSD: faq-example1,v 1.5 2006/10/07 04:48:01 mcbride Exp $
#
# Firewall for Home or Small Office
# http://www.openbsd.org/faq/pf/example1.html
#
# macros
ext_if="re0"
int_if="sk0"
tcp_services="{ 22, 113 }"
icmp_types="echoreq"
#comp3="192.168.0.3"
# options
set block-policy return
set loginterface $ext_if
set skip on lo
# scrub
scrub in
# nat/rdr
#nat on $ext_if from !($ext_if) -> ($ext_if:0)
#nat-anchor "ftp-proxy/*"
#rdr-anchor "ftp-proxy/*"
#rdr pass on $int_if proto tcp to port ftp -> 127.0.0.1 port 8021
#rdr on $ext_if proto tcp from any to any port 80 -> $comp3
# filter rules
block in
pass out
anchor "ftp-proxy/*"
antispoof quick for { lo $int_if }
pass in on $ext_if inet proto tcp from any to ($ext_if) port $tcp_services
#pass in on $ext_if inet proto tcp from any to $comp3 port 80 \
    synproxy state
pass in inet proto icmp all icmp-type $icmp_types
pass quick on $int_if no state
            Řešení dotazu:
pass out all ?
autor prispevku neuvadza, kde ten FW rozbehal, aky je jeho environment - mozme len hadat /sa/.
            
        Tiskni
            
                Sdílej:
                 
                 
                 
                 
                 
                 
            
    
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.