pf2.ok revision 1.10
1block out log on tun0 all 2block in log on tun0 all 3block return-rst out log on tun0 proto tcp all 4block return-rst in log on tun0 proto tcp all 5block return-icmp(port-unr, port-unr) out log on tun0 proto udp all 6block return-icmp(port-unr, port-unr) in log on tun0 proto udp all 7block out log quick on tun0 inet from ! 157.161.48.183 to any 8block in quick on tun0 inet from any to 255.255.255.255 9block in log quick on tun0 inet from 10.0.0.0/8 to any 10block in log quick on tun0 inet from 172.16.0.0/12 to any 11block in log quick on tun0 inet from 192.168.0.0/16 to any 12block in log quick on tun0 inet from 255.255.255.255 to any 13block in log quick from no-route to any 14pass out on tun0 inet proto icmp all icmp-type echoreq code 0 keep state 15pass in on tun0 inet proto icmp all icmp-type echoreq code 0 keep state 16pass out on tun0 proto udp all keep state 17pass in on tun0 proto udp from any to any port = domain keep state 18pass out on tun0 proto tcp all keep state 19pass in on tun0 proto tcp from any to any port = ssh keep state 20pass in on tun0 proto tcp from any to any port = smtp keep state 21pass in on tun0 proto tcp from any to any port = domain keep state 22pass in on tun0 proto tcp from any to any port = auth keep state 23