|
ipf 3.4.31,规则如下:
- @1 pass out from any to any
- @1 pass in from any to any
- @2 block return-rst in log quick proto tcp from any to any port 135 >< 139
- @3 block return-rst in log quick proto tcp from any to any port = 445
- @4 block return-icmp-as-dest(port-unr) in log quick proto udp from any to any port 135 >< 139
- @5 block return-icmp-as-dest(port-unr) in log quick proto udp from any to any port = 445
复制代码
偶发现这条规则不起作用:
- @2 block return-rst in log quick proto tcp from any to any port 135 >< 139
复制代码
如果把上面那条规则改成如下5条单独的规则,工作正常。
- block return-rst in log quick proto tcp from any to any port 135
- block return-rst in log quick proto tcp from any to any port 136
- block return-rst in log quick proto tcp from any to any port 137
- block return-rst in log quick proto tcp from any to any port 138
- block return-rst in log quick proto tcp from any to any port 139
复制代码
而同样使用Port range,这条规则就可以
- @4 block return-icmp-as-dest(port-unr) in log quick proto udp from any to any port 135 >< 139
复制代码
难道Port range对TCP规则无效? |
|