set timeout udp.single 5 # # Scrub rules # match all scrub (reassemble tcp no-df ) match out all scrub (random-id min-ttl 1 max-mss 1460) # Tables: (1) table { 10.1.1.81 , 10.3.14.81 } # # Rule backup ssh access rule # backup ssh access rule pass in quick inet proto tcp from 10.3.14.30 to port 22 label "RULE -1 -- ACCEPT " # # Rule 0 (global) block log quick inet from any to any no state label "RULE 0 -- DROP " # # Rule fallback rule # fallback rule block quick inet from any to any no state label "RULE 10000 -- DROP "