| Firewalling with OpenBSD's PF packet filter: EuroBSDCon 2007, København, September 12th 2007 | ||
|---|---|---|
| Prev | Next | |
If you write
pass in inet proto tcp on ep1 from ep1:network to ep0:network \
port $ports keep statethen you also need
pass out inet proto tcp on ep0 from ep1:network to ep0:network \
port $ports keep statebut do you actually mean
pass inet proto tcp from ep1:network to any port $ports keep state