drop
not ethertype ipv4
and not ethertype arp
and not ethertype ipv6
;
accept
dport 6445
or sport 6445
or dport 28012-28013
or sport 28012-28013
;
break
chr tcp_syn
and not chr tcp_ack
;
accept;
accept ethertype arp;
accept dport 3389 or sport 3389 and ipprotocol tcp;
drop;