Skip to content

Instantly share code, notes, and snippets.

@inC3ASE
Created October 14, 2016 09:05
Show Gist options
  • Save inC3ASE/4ccfdfad60b361f11f50b90ca2e67de0 to your computer and use it in GitHub Desktop.
Save inC3ASE/4ccfdfad60b361f11f50b90ca2e67de0 to your computer and use it in GitHub Desktop.
//private/etc/pf.conf * Abnormally important only because this is one of the ways things are bypassed
#
# Default PF configuration file.
#
# This file contains the main ruleset, which gets automatically loaded
# at startup. PF will not be automatically enabled, however. Instead,
# each component which utilizes PF is responsible for enabling and disabling
# PF via -E and -X as documented in pfctl(8). That will ensure that PF
# is disabled only when the last enable reference is released.
#
# Care must be taken to ensure that the main ruleset does not get flushed,
# as the nested anchors rely on the anchor point defined here. In addition,
# to the anchors loaded by this file, some system services would dynamically
# insert anchors into the main ruleset. These anchors will be added only when
# the system service is used and would removed on termination of the service.
#
# See pf.conf(5) for syntax.
#
#
# com.apple anchor point
#
scrub-anchor "com.apple/*"
nat-anchor "com.apple/*"
rdr-anchor "com.apple/*"
dummynet-anchor "com.apple/*"
anchor "com.apple/*"
load anchor "com.apple" from "/etc/pf.anchors/com.apple"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment