ipf+ipnat+ipfw建立带流量控制的透明网关(9) echo 'block in log on '$ADSLDEV' all' >> /etc/ipf.rules echo '' >> /etc/ipf.rules echo '#阻塞内部网络访问以下指定IP地址' >> /etc/ipf.rules echo '#block in log quick on '$ADSLDEV' proto tcp from any to 202.106.185.77 flags S/SA #不能连接163.com' >> /etc/ipf.rules echo '' >> /etc/ipf.rules echo '#内部网络的数据全部可以通过防火墙' >> /etc/ipf.rules echo 'pass in on '$INTARNDEV' all' >> /etc/ipf.rules echo 'pass out on '$INTARNDEV' all' >> /etc/ipf.rules echo 'pass in on lo0 all' >> /etc/ipf.rules echo 'pass out on lo0 all' >> /etc/ipf.rules echo '' >> /etc/ipf.rules echo '#让VPN能通过防火墙' >> /etc/ipf.rules echo 'pass in quick on '$ADSLDEV' proto tcp from any to any port = 47 keep state' >> /etc/ipf.rules echo 'pass out quick on '$ADSLDEV' proto tcp from any port = 47 to any keep state' >> /etc/ipf.rules echo 'pass in quick on '$ADSLDEV' proto tcp from any to any port = 1723 keep state' >> /etc/ipf.rules echo 'pass out quick on '$ADSLDEV' proto tcp from any port = 1723 to any keep state' >> /etc/ipf.rules echo 'pass in proto gre from any to any keep state' >> /etc/ipf.rules