站内公告:

亲友传真---海外信息直接看 https://qycz.org

Main Menu

pf Firewall : rules to block TCP RST attack

作者 jingyue, 昨天 05:07:39 上午

jingyue

pf Firewall: how to ignore TCP RST packets                           pf 防火墙添加一条规则可以屏蔽入站 TCP_RST 数据包,


在 pf 防火墙配置文件 pf.conf 中,添加如下一条规则,即可,
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

block drop in log quick proto tcp all flags R/R label  " block_TCP_RST_attack "

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

block drop in log quick on em1 inet proto tcp all flags R/R label  " block_TCP_RST_attack "


提示:网卡设备名称 em1 需要根据具体实例修改,
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

二者可选其一,


仅供参考
【特稿】非凡传奇时代 法轮大法传世33周年
https://www.epochtimes.com/gb/25/5/12/n14506735.htm
https://www.minghui.org/mh/articles/2023/1/20/为什么会有人类-455562.html
https://www.minghui.org/mh/articles/2023/4/17/为什么要救度众生-458929.htm

https://www.minghui.org/mh/articles/2024/9/30/为什么人类是迷的社会-483472.html
世上几人醒
https://gb.falundafa.org/chigb/hy4/hy4-051.htm

【特稿】法轮功创始人传功和生活的故事
https://cn.ntdtv.com/gb/2025/01/05/a103945427.html
https://www.minghui.org/mh/articles/2025/1/4/【专访】我们的师父-487964.html
https://www.minghui.org/mh/articles/2024/12/17/回忆修炼路上出现的一次神迹-486159.html
https://www.minghui.org/mh/articles/2024/8/5/深蓝色的法轮-480298.html
https://www.minghui.org/mh/articles/2010/5/18/【征稿选登】李洪志师父在92东方健康博览会的奇迹-223842.html
https://www.minghui.org/mh/articles/2012/11/3/未来人的神话——忆师尊在哈尔滨传法-264844.html
https://www.minghui.org/mh/articles/2014/5/11/【庆祝513】回忆师尊在北京传法的片段-291380.html
https://www.minghui.org/mh/articles/2022/5/21/【庆祝513】忆师恩-万载难遇的机缘(上)-442904.html
https://www.minghui.org/mh/articles/2022/5/21/【庆祝513】忆师恩-万载难遇的机缘(下)-443903.html
https://www.minghui.org/mh/articles/2023/6/11/在东方博览会上见证师父的神通法力-461847.html
https://www.minghui.org/mh/articles/2024/1/15/一名英国学员在神韵演出现场看到的(译文)-471044.html
https://www.minghui.org/mh/articles/2025/4/3/感谢中国大陆发资料的同修们-492243.html

jingyue

#1
如何查看被 pf 防火墙拦截下来的入站 TCP RST 数据包数目,

终端命令,root 权限,


# pfctl -s all | grep "block_TCP_RST_attack"

典型输出:

引用# pfctl -s all | grep "block_TCP_RST_attack"
block drop in log quick proto tcp all flags R/R label "block_TCP_RST_attack"
block_TCP_RST_attack  1722  0  0  0  0  0  0  0
#

其中第一列数字 1722 ,表示 pf 防火墙已经拦截下来 1722 个入站 TCP RST 数据包,


~~~~~~~~~~~~~~~~~~~~~~~~~~_END_~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


参考文献:

pf.conf(5) - OpenBSD manual pages

https://man.openbsd.org/pf.conf

引用自: jingyue 于 十二月 12, 2025, 05:08:25 上午中国长城防火墙 GFW 通过注入伪造的 TCP RST+ACK 数据包来破坏 TCP 端口 443 上的连接


【特稿】非凡传奇时代 法轮大法传世33周年
https://www.epochtimes.com/gb/25/5/12/n14506735.htm
https://www.minghui.org/mh/articles/2023/1/20/为什么会有人类-455562.html
https://www.minghui.org/mh/articles/2023/4/17/为什么要救度众生-458929.htm

https://www.minghui.org/mh/articles/2024/9/30/为什么人类是迷的社会-483472.html
世上几人醒
https://gb.falundafa.org/chigb/hy4/hy4-051.htm

【特稿】法轮功创始人传功和生活的故事
https://cn.ntdtv.com/gb/2025/01/05/a103945427.html
https://www.minghui.org/mh/articles/2025/1/4/【专访】我们的师父-487964.html
https://www.minghui.org/mh/articles/2024/12/17/回忆修炼路上出现的一次神迹-486159.html
https://www.minghui.org/mh/articles/2024/8/5/深蓝色的法轮-480298.html
https://www.minghui.org/mh/articles/2010/5/18/【征稿选登】李洪志师父在92东方健康博览会的奇迹-223842.html
https://www.minghui.org/mh/articles/2012/11/3/未来人的神话——忆师尊在哈尔滨传法-264844.html
https://www.minghui.org/mh/articles/2014/5/11/【庆祝513】回忆师尊在北京传法的片段-291380.html
https://www.minghui.org/mh/articles/2022/5/21/【庆祝513】忆师恩-万载难遇的机缘(上)-442904.html
https://www.minghui.org/mh/articles/2022/5/21/【庆祝513】忆师恩-万载难遇的机缘(下)-443903.html
https://www.minghui.org/mh/articles/2023/6/11/在东方博览会上见证师父的神通法力-461847.html
https://www.minghui.org/mh/articles/2024/1/15/一名英国学员在神韵演出现场看到的(译文)-471044.html
https://www.minghui.org/mh/articles/2025/4/3/感谢中国大陆发资料的同修们-492243.html

快速回复

Note: this post will not display until it has been approved by a moderator.

名称:
电子邮件:
验证码:
请将此框留空:
三乘七等于几?(请用阿拉伯数字回答):
Shortcuts: ALT+S post or ALT+P preview