xref: /freebsd-12.1/contrib/ipfilter/rules/server (revision c9bff7ba)
1b4ebec5bSDarren Reed#
2b4ebec5bSDarren Reed# For a network server, which has two interfaces, 128.1.40.1 (le0) and
3b4ebec5bSDarren Reed# 128.1.2.1 (le1), we want to block all IP spoofing attacks.  le1 is
4b4ebec5bSDarren Reed# connected to the majority of the network, whilst le0 is connected to a
5b4ebec5bSDarren Reed# leaf subnet.  We're not concerned about filtering individual services
6b4ebec5bSDarren Reed# or
7b4ebec5bSDarren Reed#
8b4ebec5bSDarren Reedpass in quick on le0 from 128.1.40.0/24 to any
9*c9bff7baSGuido van Rooijblock in log quick on le0 from any to any
10*c9bff7baSGuido van Rooijblock in log quick on le1 from 128.1.1.0/24 to any
11b4ebec5bSDarren Reedpass in quick on le1 from any to any
12