From owner-freebsd-pf@FreeBSD.ORG Tue Mar 24 16:24:17 2009 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 6BAD41065BBB for ; Tue, 24 Mar 2009 16:24:17 +0000 (UTC) (envelope-from davidfeustel@comcast.net) Received: from QMTA02.emeryville.ca.mail.comcast.net (qmta02.emeryville.ca.mail.comcast.net [76.96.30.24]) by mx1.freebsd.org (Postfix) with ESMTP id 5186D8FC16 for ; Tue, 24 Mar 2009 16:24:17 +0000 (UTC) (envelope-from davidfeustel@comcast.net) Received: from OMTA10.emeryville.ca.mail.comcast.net ([76.96.30.28]) by QMTA02.emeryville.ca.mail.comcast.net with comcast id X3Mt1b0010cQ2SLA24B8Ny; Tue, 24 Mar 2009 16:11:08 +0000 Received: from localhost ([69.245.244.28]) by OMTA10.emeryville.ca.mail.comcast.net with comcast id X4B61b00E0dV8n18W4B6Rb; Tue, 24 Mar 2009 16:11:07 +0000 From: Dave Feustel To: Eric Magutu In-Reply-To: Message-Id: <20090324162417.5186D8FC16@mx1.freebsd.org> Date: Tue, 24 Mar 2009 16:24:17 +0000 (UTC) Cc: freebsd-pf@freebsd.org Subject: Re: first firewall with pf X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: dfeustel@mindspring.com List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 24 Mar 2009 16:24:22 -0000 On Tue, Mar 24, 2009 at 06:47:40PM +0300, Eric Magutu wrote: > does the rule to block all other traffic have to be explicitly mentioned? > > On Tue, Mar 24, 2009 at 6:27 PM, Eric Magutu wrote: > > > Thanks I'll change that > > > > > > On Tue, Mar 24, 2009 at 6:20 PM, Glen Barber wrote: > > > >> On Tue, Mar 24, 2009 at 10:47 AM, Eric Magutu wrote: > >> [snip] > >> > > >> > ########################## > >> > #block all other traffic # > >> > ########################## > >> > > >> > # should be last rule > >> > > >> > block in quick on $ext_if all Change this rule to block in on $ex_if all and then make it the first rule. The word 'quick' says don't evaluate any more rules if this matches.