Dear Colleagues,

A quick question about pf from an ipfw user.

Suppose I have three interfaces: $outside, $inside and $dmz. If I want
to block any traffic from $dmz to $inside, unless it is 

1. Return traffic from $inside to $dmz
2. ICMP traffic in any direction

would these rules be sufficient?

block in on $dmz
pass in on $dmz proto icmp
pass out on $inside

-- 
Victor Sudakov,  VAS4-RIPE, VAS47-RIPN
2:5005/49@fidonet http://vas.tomsk.ru/

Attachment: signature.asc
Description: PGP signature

Reply via email to