Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 25 May 2008 16:07:29 +0200
From:      peter@bsdly.net (Peter N. M. Hansteen)
To:        freebsd-pf@freebsd.org
Subject:   Re: blackhole in PF possible?
Message-ID:  <87r6bqqxy6.fsf@thingy.bsdly.net>
In-Reply-To: <de5dfb5a0805250114m5f141e6ek5dcf83d916bc206f@mail.gmail.com> (Ighighi Ighighi's message of "Mon, 26 May 2008 03:44:19 %2B1930")
References:  <de5dfb5a0805250114m5f141e6ek5dcf83d916bc206f@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
"Ighighi Ighighi" <ighighi@gmail.com> writes:

> Is there a way to get the same functionality in PF so I can restrict
> those packets to external interfaces ?

block drop in all on $ext_ifs or something like that would have some
of the desired effect.  not sure how much it actually buys you, but
it's quite similar to blackhole.

-- 
Peter N. M. Hansteen, member of the first RFC 1149 implementation team
http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/
"Remember to set the evil bit on all malicious network traffic"
delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?87r6bqqxy6.fsf>