#
# every attribute fw understands. an attribute that is absent does
# not constrain, so there is never a "*" to write; it is accepted, but
# leaving the attribute out says the same thing more quietly.
#
# allow=
the rule permits. dir is in, out or *
# deny= the rule refuses
# proto= a protocol: tcp, udp, icmp, ...
# port= the port at the far end
# lport= the port at this end
# ip= the address at the far end, optionally with a /mask
# ipmask= the mask, if you would rather write it separately
#
# in and out are directions, not layers: the same rule means the same
# thing whether fw is matching it against a packet on a wire or against
# a connection a program asked for. connect and announce are accepted
# as older spellings of out and in.
#
# rules are matched top to bottom and the first one that matches wins.
# nothing matching means deny, so a file with no rules permits nothing.
#
# deny before allow, since the first match wins
deny=out ip=1.1.1.1
deny=out ip=8.8.8.8
# the two spellings of a masked address are the same rule
allow=out ip=10.0.2.0/24
allow=out ip=192.168.0.0 ipmask=/16
# v6 needs no distinguishing: it is the same attribute
allow=out ip=2001:db8::/32
# an entry may also be spread over indented continuation lines
allow=out
proto=tcp
port=443
# answer on one port, but never call out on it. lport is our end, so
# this is the port we serve; port would be the caller's, which we do not
# get to know until they call.
allow=in proto=tcp lport=17019