From owner-freebsd-questions@FreeBSD.ORG Fri Nov 23 14:46:37 2012 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 7FFB1A0A for ; Fri, 23 Nov 2012 14:46:37 +0000 (UTC) (envelope-from demelier.david@gmail.com) Received: from mail-pa0-f54.google.com (mail-pa0-f54.google.com [209.85.220.54]) by mx1.freebsd.org (Postfix) with ESMTP id 52F1C8FC13 for ; Fri, 23 Nov 2012 14:46:37 +0000 (UTC) Received: by mail-pa0-f54.google.com with SMTP id bi5so978246pad.13 for ; Fri, 23 Nov 2012 06:46:37 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:date:message-id:subject:from:to:content-type; bh=eiABcGAP5Ly76M9q4NfaYAyZsucQI6rpkP5viU6MxwI=; b=mGD3h3BD26RYIVJbnftVN08sKhy7TUmQlUuesb0qPU8Jsib3cIxxoE5viYAIoRAkrl 4wRIhdeTnFfi7v+0ve0yj4ExaggwqXnC2D4e29zhxkFuB7+IRUP7R3rb84hN49wBPbiH nICfu1EgtzecgpIi+z9s3fyNAFHaIci8B1xAAXWkU341KOCgEw7s1yPD/xBhKdCbMH0Q oCErU/kgGr3hv6KJ1eiS9lt3owHolcmsy3n75JZk+wlHNyIDXIN1XMZdXYNzwmUf96B3 BJ0QyUE9/knsnOcC4sAfDnIpjG3SZzSuuud5O0CqAKWqLLrkVotvcMJJeSEe5qGVDlcN vIkA== MIME-Version: 1.0 Received: by 10.66.9.2 with SMTP id v2mr10987156paa.18.1353681997028; Fri, 23 Nov 2012 06:46:37 -0800 (PST) Received: by 10.66.80.36 with HTTP; Fri, 23 Nov 2012 06:46:36 -0800 (PST) Date: Fri, 23 Nov 2012 15:46:36 +0100 Message-ID: Subject: PF and tables for disabling network From: David Demelier To: freebsd-questions@freebsd.org Content-Type: text/plain; charset=UTF-8 X-Content-Filtered-By: Mailman/MimeDel 2.1.14 X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 23 Nov 2012 14:46:37 -0000 Hello, I would like to disable the network traffic for specific IPs, for the moment I just add to my pf.conf a rule that will block everything for a specified table like this : table [...] others rules [...] block from Then I just need to add my IP using pfctl, it will works, no packet can be send / recv to the machine, however if that machine had some active connections, these won't be closed and they can still use them (a SSH client, game, ...) How can I disable everything then? Cheers -- Demelier David