Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 26 Sep 2005 19:22:06 +0200
From:      peter@bgnett.no (Peter N. M. Hansteen)
To:        freebsd-questions@freebsd.org
Subject:   Re: PF default to deny
Message-ID:  <86psqvn3r5.fsf@amidala.datadok.no>
In-Reply-To: <43381CB3.70003@atopia.net> (Matt Juszczak's message of "Mon, 26 Sep 2005 12:07:15 -0400")
References:  <43381CB3.70003@atopia.net>

next in thread | previous in thread | raw e-mail | index | archive | help
Matt Juszczak <matt@atopia.net> writes:

> 2) Is there a way to set pf to default to deny?  

"block all" as your first filtering rule, followed by explicit pass
rules for the stuff you want to pass.

I thought most of the howtoish docs out there recommended that approach,
but here at least is one that does - http://www.bgnett.no/~peter/pf/

-- 
Peter N. M. Hansteen, member of the first RFC 1149 implementation team
http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/
"First, we kill all the spammers" The Usenet Bard, "Twice-forwarded tales"




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?86psqvn3r5.fsf>