Код: Выделить всё
inet# ipfw show
00010 128 12317 pipe 1 ip from not 192.168.0.0/24 to 192.168.0.114,192.168.0.100,192.168.0.24,192.168.0.223,192.168.0.151,192.168.0.240
00011 0 0 pipe 2 ip from not 192.168.0.0/24 to 192.168.0.152,192.168.0.153
00050 0 0 check-state
00100 0 0 allow ip from any to any via lo0
00110 114 7548 allow ip from any to any via tun0
00150 0 0 deny ip from table(0) to any
00200 0 0 deny ip from any to 127.0.0.0/8
00250 0 0 deny ip from 127.0.0.0/8 to any
00300 0 0 deny ip from 192.168.0.0/24 to any in via sk0
00350 0 0 deny ip from xx.xx.xx.0/30 to any in via sk1
00400 0 0 deny ip from any to 10.0.0.0/8 in via sk0
00410 0 0 deny ip from any to 172.16.0.0/12 in via sk0
00420 0 0 deny ip from any to 0.0.0.0/8 in via sk0
00430 0 0 deny ip from any to 169.254.0.0/16 in via sk0
00500 0 0 deny ip from any to 224.0.0.0/4 in via sk0
00510 0 0 deny ip from any to 240.0.0.0/4 in via sk0
00600 0 0 deny icmp from any to any frag
00610 0 0 deny icmp from any to any in icmptypes 5,9,13,14,15,16,17
00700 0 0 reject tcp from any to any tcpflags syn,fin,ack,psh,rst,urg
00710 0 0 reject tcp from any to any tcpflags !syn,!fin,!ack,!psh,!rst,!urg
00720 0 0 reject tcp from any to any not established tcpflags fin
00800 0 0 deny tcp from any to any dst-port 113 in via sk0
00900 0 0 deny tcp from any to any dst-port 137 in via sk0
00910 0 0 deny tcp from any to any dst-port 138 in via sk0
00920 0 0 deny tcp from any to any dst-port 139 in via sk0
01000 0 0 deny log logamount 100 icmp from any to 255.255.255.255 in via sk0
01010 0 0 deny log logamount 100 icmp from any to 255.255.255.255 out via sk0
01100 370 17760 fwd 127.0.0.1,3128 tcp from 192.168.0.0/24 to any dst-port 80 via sk0
01200 1373 97704 divert 8668 ip from 192.168.0.0/24 to any out via sk0
01250 2088 345537 divert 8668 ip from any to xx.xx.xx.xx in via sk0
01300 0 0 deny ip from 10.0.0.0/8 to any out via sk0
01310 0 0 deny ip from 172.16.0.0/12 to any out via sk0
01320 0 0 deny ip from 0.0.0.0/8 to any out via sk0
01330 0 0 deny ip from 169.254.0.0/16 to any out via sk0
01400 0 0 deny ip from 224.0.0.0/4 to any out via sk0
01410 0 0 deny ip from 240.0.0.0/4 to any out via sk0
01500 48 3148 allow icmp from any to any icmptypes 0,8,11
01600 1039 83795 allow ip from any to 192.168.0.0/24 in via sk1
01650 83 19142 allow ip from 192.168.0.0/24 to any out via sk1
01700 5681 857818 allow tcp from any to any established
01800 212 49575 allow udp from any to xx.xx.xx.xx dst-port 53 in via sk0
01810 213 16240 allow udp from xx.xx.xx.xx to any out via sk0
01820 17 2116 allow udp from any 53 to xx.xx.xx.xx in via sk0
01830 17 1232 allow udp from xx.xx.xx.xx to any dst-port 53 out via sk0
01900 0 0 allow tcp from any to xx.xx.xx.xx dst-port 53 in via sk0
02000 1 48 allow tcp from any to xx.xx.xx.xx dst-port 35665 in via sk0 setup
02100 0 0 allow tcp from any to xx.xx.xx.xx dst-port 8282 in via sk0 setup
02110 0 0 allow tcp from any to xx.xx.xx.xx dst-port 25017 in via sk0 setup
02111 0 0 allow tcp from any to xx.xx.xx.xx dst-port 34711 in via sk0 setup
02112 3 144 allow tcp from any to xx.xx.xx.xx dst-port 2000 in via sk0 setup
02300 46 2452 deny log logamount 100 tcp from any to xx.xx.xx.xx in via sk0 setup
02500 283 13584 allow tcp from xx.xx.xx.xx to any out via sk0 setup
02510 0 0 allow tcp from any to xx.xx.xx.xx in via sk1 setup
02600 49 2352 allow tcp from 192.168.0.0/24 to any dst-port 25,110,443,5190 in via sk1 setup
02701 0 0 allow tcp from 192.168.0.80 to any in via sk1 setup
02705 0 0 allow tcp from 192.168.0.20 to any in via sk1 setup
02710 0 0 allow tcp from 192.168.0.150 to any dst-port 20,21,80 in via sk1 setup
02715 282 13536 allow tcp from 192.168.0.5 to any in via sk1 setup
02716 0 0 allow tcp from 192.168.0.60 to any in via sk1 setup
02717 0 0 allow tcp from 192.168.0.61 to any in via sk1 setup
02718 0 0 allow tcp from 192.168.0.62 to any in via sk1 setup
02719 0 0 allow tcp from 192.168.0.63 to any in via sk1 setup
02820 0 0 allow tcp from 192.168.0.24 to any dst-port 20,21,80 in via sk1 setup
02825 0 0 allow tcp from 192.168.0.114 to any dst-port 20,21,80,8080 in via sk1 setup
02830 0 0 allow tcp from 192.168.0.100 to any dst-port 20,21,80 in via sk1 setup
02840 0 0 allow tcp from 192.168.0.123 to any in via sk1 setup
02845 0 0 allow tcp from 192.168.0.211 to any dst-port 20,21,80 in via sk1 setup
02850 0 0 allow tcp from 192.168.0.11 to any dst-port 20,21,80 in via sk1 setup
02855 0 0 allow tcp from 192.168.0.223 to any in via sk1 setup
02856 24 1152 allow tcp from 192.168.0.222 to any via sk1 setup
02857 87 4176 allow tcp from 192.168.0.218 to any in via sk1 setup
02960 0 0 allow tcp from 192.168.0.215 to any dst-port 20,21,80 in via sk1 setup
02965 24 1152 allow tcp from 192.168.0.151 to any dst-port 20,21,80-89 in via sk1 setup
02970 187 8976 allow tcp from 192.168.0.240 to any dst-port 20,21,80-89 in via sk1 setup
02975 0 0 allow tcp from 192.168.0.152 to any dst-port 20,21,80 in via sk1 setup
02980 0 0 allow tcp from 192.168.0.153 to any dst-port 20,21,80 in via sk1 setup
65534 197 10654 deny ip from any to any
65535 0 0 allow ip from any to any