block return-rst in log on fxp0 proto tcp from any to any flags S/SA block return-icmp(net-unr) in log on fxp0 proto udp from any to any 以上对其他tcp请求,防火墙回应一个RST数据包关闭连接。对UDP请求,防火墙回应网络不可达到的ICMP包。 或者在/etc/sysctl.conf中加入: net.inet.tcp.blackhole=2 net.inet.udp.blackhole=1 能够有效地避免端口扫描