block in all block out all pass in proto udp from any to any keep state pass in proto tcp from any to any flags S keep state