No. So, if understand correctly with your rule: block in quick on IF_NET0 from <blck_zone-br-1> to any automatically are blocked any connections from any protocols disregarding if it is tcp, udp, icmp, icmp6, ipv4, ipv6, bgp, etc?
I found an detailed example of rules of PF from wich I extrapolate my rule that now look like this:
block in quick on IF_NET0 proto {tcp, udp, icmp, icmp6} from <blck_zone-br-1> to any
but you are right your rule is much shorter, simple and elegant. I just want to be sure that is blocking ALL PROTOCOLS from any connection attempt from that zone because I will expand this rule at blocking russians, chinese, etc.
So a lighter ruleset for matching in PF filtering but with the same efect or more powerfull efect is better for my server.
Thank you.
Last edited by S3TH76; 03-10-2016 at 01:19 AM.
|