|
现在是这个样子的。。。
#add 2000 allow tcp from any to me setup limit src-addr 8
add 2001 allow tcp from any to any 20,21,22,25,80,443,3306,20000-30000
add 2002 allow all from me to any keep-state
add 2030 deny log ip from any to any ipopt rr
add 2031 deny log ip from any to any ipopt ts
add 2032 deny log ip from any to any ipopt ssrr
add 2033 deny log ip from any to any ipopt lsrr
add 2034 deny tcp from any to any in tcpflags syn,fin
|
|