| # | |
| # block all incoming TCP connections but send back a TCP-RST for ones to | |
| # the ident port | |
| # | |
| block in proto tcp from any to any flags S/SA | |
| block return-rst in quick proto tcp from any to any port = 113 flags S/SA | |
| # | |
| # block all inbound UDP packets and send back an ICMP error. | |
| # | |
| block return-icmp in proto udp from any to any |