[BACK]Return to pf.conf CVS log [TXT][DIR] Up to [local] / src / etc

Annotation of src/etc/pf.conf, Revision 1.32

1.32    ! mcbride     1: #      $OpenBSD: pf.conf,v 1.31 2006/01/30 12:20:31 camield Exp $
1.1       kjell       2: #
1.12      henning     3: # See pf.conf(5) and /usr/share/pf for syntax and examples.
1.28      frantzen    4: # Remember to set net.inet.ip.forwarding=1 and/or net.inet6.ip6.forwarding=1
                      5: # in /etc/sysctl.conf if packets are to be forwarded between interfaces.
1.4       henning     6:
1.27      cedric      7: #ext_if="ext0"
                      8: #int_if="int0"
1.19      ian         9:
1.16      jason      10: #table <spamd> persist
1.27      cedric     11: #table <spamd-white> persist
1.12      henning    12:
1.30      henning    13: #set skip on lo
1.29      henning    14:
1.27      cedric     15: #scrub in
                     16:
1.31      camield    17: #nat-anchor "ftp-proxy/*"
                     18: #rdr-anchor "ftp-proxy/*"
1.27      cedric     19: #nat on $ext_if from !($ext_if) -> ($ext_if:0)
                     20: #rdr pass on $int_if proto tcp to port ftp -> 127.0.0.1 port 8021
                     21: #rdr pass on $ext_if proto tcp from <spamd> to port smtp \
                     22: #      -> 127.0.0.1 port spamd
                     23: #rdr pass on $ext_if proto tcp from !<spamd-white> to port smtp \
                     24: #      -> 127.0.0.1 port spamd
                     25:
1.31      camield    26: #anchor "ftp-proxy/*"
1.27      cedric     27: #block in
1.32    ! mcbride    28: #pass out
1.27      cedric     29:
1.32    ! mcbride    30: #pass quick on $int_if no state
1.27      cedric     31: #antispoof quick for { lo $int_if }
                     32:
1.32    ! mcbride    33: #pass in on $ext_if proto tcp to ($ext_if) port ssh
        !            34: #pass in log on $ext_if proto tcp to ($ext_if) port smtp
        !            35: #pass out log on $ext_if proto tcp from ($ext_if) to port smtp