104c30bedSmcbride@0 block drop all 2*d500a270Smikeb [ Skip steps: i=5 d=2 r=end f=5 p=2 da=5 sp=end dp=5 ] 304c30bedSmcbride [ queue: qname= qid=0 pqname= pqid=0 ] 404c30bedSmcbride [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] 504c30bedSmcbride@1 block drop quick from <bad:0> to any 6*d500a270Smikeb [ Skip steps: i=5 r=end f=5 da=5 sp=end dp=5 ] 704c30bedSmcbride [ queue: qname= qid=0 pqname= pqid=0 ] 804c30bedSmcbride [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] 99ab08460Smcbride@2 pass out proto tcp all flags S/SA 10*d500a270Smikeb [ Skip steps: i=5 d=5 r=end f=5 sa=end da=5 sp=end dp=5 ] 1104c30bedSmcbride [ queue: qname= qid=0 pqname= pqid=0 ] 1204c30bedSmcbride [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] 139ab08460Smcbride@3 pass out proto icmp all 14*d500a270Smikeb [ Skip steps: i=5 d=5 r=end f=5 sa=end da=5 sp=end dp=5 ] 1504c30bedSmcbride [ queue: qname= qid=0 pqname= pqid=0 ] 1604c30bedSmcbride [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] 179ab08460Smcbride@4 pass out proto udp all 18*d500a270Smikeb [ Skip steps: r=end sa=end sp=end ] 1904c30bedSmcbride [ queue: qname= qid=0 pqname= pqid=0 ] 2004c30bedSmcbride [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] 21e090a2aeShenning@5 pass in on lo1000001 inet proto tcp from any to 10.0.0.1 port = 22 flags S/SA keep state (source-track rule, max-src-conn 10, max-src-conn-rate 3/99, src.track 99) 22*d500a270Smikeb [ Skip steps: i=8 d=end r=end f=end p=end sa=end sp=end dp=8 ] 2304c30bedSmcbride [ queue: qname= qid=0 pqname= pqid=0 ] 2404c30bedSmcbride [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] 25e090a2aeShenning@6 pass in on lo1000001 inet proto tcp from any to 10.0.0.2 port = 22 flags S/SA keep state (source-track rule, max-src-conn 10) 26*d500a270Smikeb [ Skip steps: i=8 d=end r=end f=end p=end sa=end sp=end dp=8 ] 2704c30bedSmcbride [ queue: qname= qid=0 pqname= pqid=0 ] 2804c30bedSmcbride [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] 29e090a2aeShenning@7 pass in on lo1000001 inet proto tcp from any to 10.0.0.3 port = 22 flags S/SA keep state (source-track rule, max-src-conn-rate 3/99, src.track 99) 30*d500a270Smikeb [ Skip steps: d=end r=end f=end p=end sa=end sp=end ] 3104c30bedSmcbride [ queue: qname= qid=0 pqname= pqid=0 ] 3204c30bedSmcbride [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] 33e090a2aeShenning@8 pass in on lo1000000 inet proto tcp from any to 10.0.0.1 port = 80 flags S/SA modulate state (source-track rule, max-src-conn 100, max-src-conn-rate 10/5, overload <bad> flush, src.track 5) 34*d500a270Smikeb [ Skip steps: i=end d=end r=end f=end p=end sa=end da=end sp=end ] 3504c30bedSmcbride [ queue: qname= qid=0 pqname= pqid=0 ] 3604c30bedSmcbride [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] 3704c30bedSmcbride@9 pass in on lo1000000 inet proto tcp from any to 10.0.0.1 port = 8080 flags S/SA synproxy state (source-track rule, max-src-conn 1000, max-src-conn-rate 1000/5, overload <bad> flush global, src.track 5) 38*d500a270Smikeb [ Skip steps: i=end d=end r=end f=end p=end sa=end da=end sp=end dp=end ] 3904c30bedSmcbride [ queue: qname= qid=0 pqname= pqid=0 ] 4004c30bedSmcbride [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] 41