Собственно, есть конфиг, который лежит в /etc/fw.cfg
В /etc/rc.conf указан firewall_type="/etc/fw.cfg"
В /etc/fw.cfg есть набор правил:bs# less /etc/fw.cfg
add 100 allow tcp from 193.111.114.11 to xxxxxxxxx dst-port 22
add 150 allow tcp from 62.149.25.18 to xxxxxxxxx dst-port 22
add 200 allow tcp from xxxxxxxxx to 193.111.114.11
add 250 allow tcp from xxxxxxxxx to 62.149.25.18
add 300 allow tcp from any to xxxxxxxxx dst-port 80
add 350 allow tcp from xxxxxxxxx 80 to any
add 400 allow tcp from 62.149.25.18 to xxxxxxxxx dst-port 20,21
add 450 allow tcp from xxxxxxxxx 20 21 to 62.149.25.18
add 500 allow tcp from 62.149.25.18 to xxxxxxxxx dst-port 3306
add 550 allow tcp from xxxxxxxxx 3306 to 62.149.25.18
add 600 allow all from any to any via lo0
add 800 allow all from xxxxxxxxx to any
add 900 allow all from any to xxxxxxxxx keep-state
После перезапуска файрволла через sh /etc/rc.firewall& ipfw show сообщает:
bs# ipfw show
00100 109 9528 allow tcp from 193.111.114.11 to xxxxxxxxx dst-port 22
00150 0 0 allow tcp from 62.149.25.18 to xxxxxxxxx dst-port 22
00200 85 12961 allow tcp from xxxxxxxxx to 193.111.114.11
00250 0 0 allow tcp from xxxxxxxxx to 62.149.25.18
00300 2835 296807 allow tcp from any to xxxxxxxxx dst-port 80
00350 3094 3275885 allow tcp from xxxxxxxxx 80 to any
00400 0 0 allow tcp from 62.149.25.18 to xxxxxxxxx dst-port 20,21
65535 2378 177179 deny ip from any to any
Куда девались остальные правила? оО
Заранее благодарю за ответ.