Цитировать
# ipfw show
00050 317 23444 allow tcp from any to me dst-port 22
00051 292 45884 allow tcp from me 22 to any
00100 0 0 deny tcp from any to any dst-port 445
00110 1160 116448 allow ip from any to any via lo0
00120 30 1957 skipto 1000 ip from me to any
00130 0 0 deny icmp from any to any in icmptypes 5,9,13,14,15,16,17
00140 0 0 deny ip from any to table(120)
00150 0 0 deny ip from table(120) to any
00160 1056 170891 skipto 2000 ip from any to me
00200 2363 881615 skipto 500 ip from any to any via re0
00300 2901 971917 skipto 4500 ip from any to any in
00400 0 0 skipto 450 ip from any to any recv re0
00420 0 0 divert 1 ip from any to any
00450 0 0 divert 2 ip from any to any
00490 0 0 allow ip from any to any
00500 7 777 skipto 32500 ip from any to any in
00510 2356 880838 divert 1 ip from any to any
00540 2343 880100 allow ip from any to any
01000 18 1186 allow udp from any 53,7723 to any
01010 0 0 allow tcp from any to any setup keep-state
01020 24 5196 allow udp from any to any keep-state
01100 0 0 allow ip from any to any
02000 0 0 check-state
02010 0 0 allow icmp from any to any
02020 0 0 allow tcp from any to any dst-port 80,443
02050 1026 165669 deny ip from any to any via re0
02060 18 797 allow udp from any to any dst-port 53,7723
02100 0 0 deny ip from any to any
05000 485 55398 deny ip from not table(0) to any
05001 0 0 skipto 5010 ip from table(127) to table(126)
05002 2335 906766 skipto 5030 ip from any to not table(2)
05003 0 0 deny ip from any to not table(1)
05004 0 0 pipe tablearg ip from table(21) to any
05005 0 0 deny ip from any to any
05010 0 0 pipe tablearg ip from table(127) to any
05030 0 0 deny tcp from table(15) to any dst-port 25
05400 2335 906766 pipe tablearg ip from table(11) to any
32000 0 0 deny ip from any to any
32490 8 731 deny ip from any to any
33000 0 0 pipe tablearg ip from table(126) to table(127)
33001 6 666 skipto 33010 ip from not table(2) to any
33002 0 0 pipe tablearg ip from any to table(20)
33003 0 0 deny ip from any to any
33400 0 0 pipe tablearg ip from any to table(10)
65535 7 777 deny ip from any to any
00050 317 23444 allow tcp from any to me dst-port 22
00051 292 45884 allow tcp from me 22 to any
00100 0 0 deny tcp from any to any dst-port 445
00110 1160 116448 allow ip from any to any via lo0
00120 30 1957 skipto 1000 ip from me to any
00130 0 0 deny icmp from any to any in icmptypes 5,9,13,14,15,16,17
00140 0 0 deny ip from any to table(120)
00150 0 0 deny ip from table(120) to any
00160 1056 170891 skipto 2000 ip from any to me
00200 2363 881615 skipto 500 ip from any to any via re0
00300 2901 971917 skipto 4500 ip from any to any in
00400 0 0 skipto 450 ip from any to any recv re0
00420 0 0 divert 1 ip from any to any
00450 0 0 divert 2 ip from any to any
00490 0 0 allow ip from any to any
00500 7 777 skipto 32500 ip from any to any in
00510 2356 880838 divert 1 ip from any to any
00540 2343 880100 allow ip from any to any
01000 18 1186 allow udp from any 53,7723 to any
01010 0 0 allow tcp from any to any setup keep-state
01020 24 5196 allow udp from any to any keep-state
01100 0 0 allow ip from any to any
02000 0 0 check-state
02010 0 0 allow icmp from any to any
02020 0 0 allow tcp from any to any dst-port 80,443
02050 1026 165669 deny ip from any to any via re0
02060 18 797 allow udp from any to any dst-port 53,7723
02100 0 0 deny ip from any to any
05000 485 55398 deny ip from not table(0) to any
05001 0 0 skipto 5010 ip from table(127) to table(126)
05002 2335 906766 skipto 5030 ip from any to not table(2)
05003 0 0 deny ip from any to not table(1)
05004 0 0 pipe tablearg ip from table(21) to any
05005 0 0 deny ip from any to any
05010 0 0 pipe tablearg ip from table(127) to any
05030 0 0 deny tcp from table(15) to any dst-port 25
05400 2335 906766 pipe tablearg ip from table(11) to any
32000 0 0 deny ip from any to any
32490 8 731 deny ip from any to any
33000 0 0 pipe tablearg ip from table(126) to table(127)
33001 6 666 skipto 33010 ip from not table(2) to any
33002 0 0 pipe tablearg ip from any to table(20)
33003 0 0 deny ip from any to any
33400 0 0 pipe tablearg ip from any to table(10)
65535 7 777 deny ip from any to any
Цитировать
# ipfw pipe show
01004: 512.000 Kbit/s 0 ms 50 sl. 0 queues (1 buckets) droptail
burst: 0 Byte
00001: unlimited 0 ms 50 sl. 0 queues (1 buckets) droptail
burst: 0 Byte
01008: 512.000 Kbit/s 0 ms 50 sl. 1 queues (1 buckets) droptail
burst: 0 Byte
mask: 0x00 0x00000000/0x0000 -> 0x00000000/0x0000
BKT Prot ___Source IP/port____ ____Dest. IP/port____ Tot_pkt/bytes Pkt/Byte Drp
0 tcp 1.2.1.2/1319 74.125.87.105/80 2754 971313 0 0 33
01004: 512.000 Kbit/s 0 ms 50 sl. 0 queues (1 buckets) droptail
burst: 0 Byte
00001: unlimited 0 ms 50 sl. 0 queues (1 buckets) droptail
burst: 0 Byte
01008: 512.000 Kbit/s 0 ms 50 sl. 1 queues (1 buckets) droptail
burst: 0 Byte
mask: 0x00 0x00000000/0x0000 -> 0x00000000/0x0000
BKT Prot ___Source IP/port____ ____Dest. IP/port____ Tot_pkt/bytes Pkt/Byte Drp
0 tcp 1.2.1.2/1319 74.125.87.105/80 2754 971313 0 0 33
Цитировать
# ipfw table 11 list
1.2.1.2/32 1008
1.2.1.15/32 1004
1.2.1.2/32 1008
1.2.1.15/32 1004
nodeny 49.33
freebsd 8.0