Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Comment My stateful ipv6 fiewall rules (Score 1) 278 278

This lets me route all of my million billion zillion ip addresses in my /48 with no NAT and no inbound stuff allowed at all unless initiated from the inside.

block in on pppoe0 all
pass out quick on pppoe0 proto tcp/udp from xxxx:xxx:xxx::/48 to any keep state
pass out quick on pppoe0 proto ipv6-icmp from xxxx:xxx:xxx::/48 to any keep state
Whew... That was really hard to set up.

In any problem, if you find yourself doing an infinite amount of work, the answer may be obtained by inspection.

Working...