accept ethertype arp; # so nodes can find each other
drop not ipprotocol tcp;
accept dport 3389; # Destination is RDP
drop chr tcp_syn and not chr tcp_ack; # No new TCP connections (except RDP)
accept; # Accept what's left, returning RDP traffic
accept ethertype arp; # so nodes can find each other
drop not ipprotocol tcp;
accept dport 3389 and ipsrc 10.147.1.1 and ipdest 10.147.1.11
accept dport 3389 and ipsrc 10.147.1.2 and ipdest 10.147.1.12
drop chr tcp_syn and not chr tcp_ack; # No new TCP connections (except RDP)
accept; # Accept what's left, returning RDP traffic
Thanks @zt-travis, it’s work fine adding netmask and ‘;’
accept ethertype arp; # so nodes can find each other
drop not ipprotocol tcp;
accept dport 3389 and ipsrc 10.147.1.1/32 and ipdest 10.147.1.11/32;
accept dport 3389 and ipsrc 10.147.1.2/32 and ipdest 10.147.1.12/32;
drop chr tcp_syn and not chr tcp_ack; # No new TCP connections (except RDP)
accept; # Accept what's left, returning RDP traffic