xref: /openbsd/etc/pf.conf (revision e4072164)
1*e4072164Ssthen#	$OpenBSD: pf.conf,v 1.55 2017/12/03 20:40:04 sthen Exp $
28e03518fSkjell#
383ea20a8Sderaadt# See pf.conf(5) and /etc/examples/pf.conf
4ac2c8deeSclaudio
51ac0638eSderaadtset skip on lo
6193e6e9cSdavid
7b12cbc59Sdtuckerblock return	# block stateless traffic
82b09cda0Shalexpass		# establish keep-state
91ac0638eSderaadt
101ac0638eSderaadt# By default, do not permit remote connections to X11
11b12cbc59Sdtuckerblock return in on ! lo0 proto tcp to port 6000:6010
12*e4072164Ssthen
13*e4072164Ssthen# Port build user does not need network
14*e4072164Ssthenblock return out log proto {tcp udp} user _pbuild
15