xref: /illumos-gate/usr/src/cmd/ipf/examples/example.3 (revision 7c478bd9)
1#
2# block all inbound packets.
3#
4block in from any to any
5#
6# pass through packets to and from localhost.
7#
8pass in from 127.0.0.1/32 to 127.0.0.1/32
9#
10# allow a variety of individual hosts to send any type of IP packet to any
11# other host.
12#
13pass in from 10.1.3.1/32 to any
14pass in from 10.1.3.2/32 to any
15pass in from 10.1.3.3/32 to any
16pass in from 10.1.3.4/32 to any
17pass in from 10.1.3.5/32 to any
18pass in from 10.1.0.13/32 to any
19pass in from 10.1.1.1/32 to any
20pass in from 10.1.2.1/32 to any
21#
22#
23# block all outbound packets.
24#
25block out from any to any
26#
27# allow any packets destined for localhost out.
28#
29pass out from any to 127.0.0.1/32
30#
31# allow any host to send any IP packet out to a limited number of hosts.
32#
33pass out from any to 10.1.3.1/32
34pass out from any to 10.1.3.2/32
35pass out from any to 10.1.3.3/32
36pass out from any to 10.1.3.4/32
37pass out from any to 10.1.3.5/32
38pass out from any to 10.1.0.13/32
39pass out from any to 10.1.1.1/32
40pass out from any to 10.1.2.1/32
41