Voila, j'ai ecrit mes regles, le ssh marche nickel, mais quand je veux DL avec wget sur mon serveur ca passe pas.
Mes regles :
block return-rst in proto tcp all
block return-icmp-as-dest(port-unr) in proto udp all
block return-rst in on ed0 proto tcp all
block return-icmp-as-dest(port-unr) in on ed0 proto udp all
pass in quick on lo0 all
pass out quick on lo0 all
block in log quick all with ipopts
block in log quick all with frag
block in log quick on ed0 proto tcp all flags SF/SFRA
block in log quick on ed0 proto tcp all flags /SFRA
block in log quick on ed0 proto tcp all flags F/SFRA
block in log quick on ed0 proto tcp all flags U/SFRAU
block in log quick on ed0 proto tcp all flags P
block in log quick on ed0 proto tcp from any to any flags FUP
pass in quick on ed0 proto icmp from any to any icmp-type 0
pass out quick on ed0 proto icmp from any to any icmp-type 0
pass in quick on ed0 proto icmp from any to any icmp-type 3
pass out quick on ed0 proto icmp from any to any icmp-type 3
pass in quick on ed0 proto icmp from any to any icmp-type 8
pass out quick on ed0 proto icmp from any to any icmp-type 8
pass in quick on ed0 proto icmp from any to any icmp-type 11
pass out quick on ed0 proto icmp from any to any icmp-type 11
block return-icmp-as-dest(host-unr) in log quick on ed0 proto icmp from any to any
block return-rst in log quick on ed0 proto tcp from any to any port = 513
block return-icmp-as-dest(port-unr) in log quick on ed0 proto udp from any to any port = 513
block return-rst in log quick on ed0 proto tcp from any to any port = 514
block return-icmp-as-dest(port-unr) in log quick on ed0 proto udp from any to any port = 514
block return-rst in log quick on ed0 proto tcp from any to any port = 23
block return-icmp-as-dest(port-unr) in log quick on ed0 proto udp from any to any port = 23
block return-rst in log quick on ed0 proto tcp from any to any port = 111
block return-icmp-as-dest(port-unr) in log quick on ed0 proto udp from any to any port = 111
#block in log on ed0 all
pass in quick on ed0 proto tcp from any to any port = 80
pass out quick on ed0 proto tcp from any to any port = 80
pass in quick on ed0 proto udp from any to any port = 80
pass out quick on ed0 proto udp from any to any port = 80
pass in quick on ed0 proto tcp from any to any port = 22 flags S keep state
pass in quick on ed0 proto tcp from any to any port = 53
pass out quick on ed0 proto tcp from any to any port = 53
pass in quick on ed0 proto udp from any to any port = 53
pass out quick on ed0 proto udp from any to any port = 53
pass out quick on ed0 proto tcp from any to any flags S/SAFR keep state
block in log on ed0 all
|
Une idée ?
Message édité par sharlaan le 11-06-2004 à 21:11:23