Block in all
Pass the log in the quick proto TCP from any to any port=1521
Pass the log in the quick proto TCP from XXXXXXXX to any port=SSH
Pass the log in the quick proto TCP from XXXXXXXX to any port=SSH
Pass the log in the quick proto TCP from XXXXXXXX to any port=Telnet
Pass the log in the quick proto TCP from XXXXXXXX to any port=22
After enabling rules, connect to the server is normal, but the server unable to connect to other machines, but I am out of the bag also did not limit
I do not know is what reason, hope masters directions!
CodePudding user response:
An answer noCodePudding user response:
According to my understanding, this is similar to the ACL strategy, to put the block in all the will in all strategies at the end of the lineCodePudding user response:
Man ipf. ConfThe default way in which The filter rules are applied is for The last matching rule to be 2 as The decision maker. So even if The first rule to match a packet is a pass, if there is a later matching rule that is a block, and no further rules match The packet, then it will be blocked
The default for block