我准备了以下配置:
# cat /etc/firewall.conf
add 1000 count udp from any to me 10000
add 1001 count udp from any to me 10001
add 1002 count udp from any to me 10002
add 65000 allow ip from any to any
这是来自的输出ipfw
:
# ipfw list
00100 allow ip from any to any via lo0
00200 deny ip from any to 127.0.0.0/8
00300 deny ip from 127.0.0.0/8 to any
00400 deny ip from any to ::1
00500 deny ip from ::1 to any
00600 allow ipv6-icmp from :: to ff02::/16
00700 allow ipv6-icmp from fe80::/10 to fe80::/10
00800 allow ipv6-icmp from fe80::/10 to ff02::/16
00900 allow ipv6-icmp from any to any icmp6types 1
01000 allow ipv6-icmp from any to any icmp6types 2,135,136
01000 count udp from any to me 10000
01001 count udp from any to me 10001
01002 count udp from any to me 10002
65000 allow ip from any to any
65535 deny ip from any to any
我有以下两个问题:
允许来自to的
UDP
流量的命令是什么?下面的规则是正确的吗?IP 203.0.113.1
UDP port range 20500-20750
add 2000 allow udp from 203.0.113.1 to me 20500-20750
有了上面的配置,是不是保证所有的流量都是允许的?