> /etc/ipf.rules echo "block out quick proto tcp/udp from any to 202.104.129.252 #不能連接QQ" >> /etc/ipf.rules ec。IPFILTER 使用FreeBSD配置基于ADSL的VPN防火墻網(wǎng)關(guān)( 五 )。" />

日本免费全黄少妇一区二区三区-高清无码一区二区三区四区-欧美中文字幕日韩在线观看-国产福利诱惑在线网站-国产中文字幕一区在线-亚洲欧美精品日韩一区-久久国产精品国产精品国产-国产精久久久久久一区二区三区-欧美亚洲国产精品久久久久

IPFILTER 使用FreeBSD配置基于ADSL的VPN防火墻網(wǎng)關(guān)( 五 )


echo "block out quick proto tcp/udp from any to 202.104.129.251 #不能連接QQ" >> /etc/ipf.rules
echo "block out quick proto tcp/udp from any to 202.104.129.252 #不能連接QQ" >> /etc/ipf.rules
echo "block out quick proto tcp/udp from any to 202.104.129.254 #不能連接QQ" >> /etc/ipf.rules
echo "block out quick proto tcp/udp from any to 204.134.15.1 #不能連接QQ" >> /etc/ipf.rules
echo "" >> /etc/ipf.rules
echo "#內(nèi)部網(wǎng)絡(luò)可以訪問外部網(wǎng)絡(luò)" >> /etc/ipf.rules
echo "pass out log on "$ADSLDEV" proto icmp all keep state" >> /etc/ipf.rules
echo "pass out log on "$ADSLDEV" proto tcp/udp from any to any keep state" >> /etc/ipf.rules
echo "" >> /etc/ipf.rules
echo "#阻塞外部網(wǎng)絡(luò)的其它請求" >> /etc/ipf.rules
echo "block return-rst in log on "$ADSLDEV" proto tcp from any to "$ADSLIP" flags S/SA" >> /etc/ipf.rules
echo "block return-icmp(net-unr) in log on "$ADSLDEV" proto udp from any to "$ADSLIP"" >> /etc/ipf.rules
echo "block in log on "$ADSLDEV" all" >> /etc/ipf.rules
echo "" >> /etc/ipf.rules
echo "#阻塞內(nèi)部網(wǎng)絡(luò)訪問以下指定IP地址" >> /etc/ipf.rules
echo "#block in log quick on rl1 proto tcp from any to 202.106.185.77 flags S/SA #不能連接163.com" >> /etc/ipf.rules
echo "" >> /etc/ipf.rules
echo "#內(nèi)部網(wǎng)絡(luò)的數(shù)據(jù)全部可以通過防火墻" >> /etc/ipf.rules
echo "pass in on "$INTARNDEV" all" >> /etc/ipf.rules
echo "pass out on "$INTARNDEV" all" >> /etc/ipf.rules
echo "pass in on lo0 all" >> /etc/ipf.rules
echo "pass out on lo0 all" >> /etc/ipf.rules
echo "" >> /etc/ipf.rules
echo "#讓VPN能通過防火墻" >> /etc/ipf.rules
echo "pass in quick on "$ADSLDEV" proto tcp from any to any port = 47 keep state" >> /etc/ipf.rules
echo "pass out quick on "$ADSLDEV" proto tcp from any port = 47 to any keep state" >> /etc/ipf.rules
echo "pass in quick on "$ADSLDEV" proto tcp from any to any port = 1723 keep state" >> /etc/ipf.rules
echo "pass out quick on "$ADSLDEV" proto tcp from any port = 1723 to any keep state" >> /etc/ipf.rules
echo "pass in proto gre from any to any keep state" >> /etc/ipf.rules
echo "pass out proto gre from any to any keep state" >> /etc/ipf.rules
echo "pass in on ng0 all" >> /etc/ipf.rules
echo "pass out on ng0 all" >> /etc/ipf.rules

/sbin/ipf -Fa -f /etc/ipf.rules
/sbin/ipnat -CF -f /etc/ipnat.rules

############################## END ADSLIP.SH #################################

最后我們還要在/etc/rc.conf中加入以下命令行:
gateway_enable="YES"
到這里我們就完成了基于ADSL的VPN防火墻(IPFILTER)網(wǎng)關(guān)的安裝和配置,至于如何做你的防火墻規(guī)則就看你自己了以上只是一個樣板而已 。

推薦閱讀