| Firewalling with OpenBSD's PF packet filter: EuroBSDCon 2007, København, September 12th 2007 | ||
|---|---|---|
| Prev | Next | |
Suggested rule set addition:
icmp_types = "{ echoreq, unreach }"pass inet proto icmp all icmp-type $icmp_types keep state
See RFC792, RFC950, RFC1191, RFC1256, RFC2521, RFC2765 (ICMP4),
RFC1885, RFC2463, RFC2466 (ICMP6)