firewall 2.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119
  1. config 'defaults'
  2. option 'syn_flood' '1'
  3. option 'input' 'ACCEPT'
  4. option 'output' 'ACCEPT'
  5. option 'forward' 'REJECT'
  6. config 'zone'
  7. option 'name' 'lan'
  8. option 'network' 'lan'
  9. option 'input' 'ACCEPT'
  10. option 'output' 'ACCEPT'
  11. option 'forward' 'REJECT'
  12. config 'zone'
  13. option 'name' 'wan'
  14. option 'input' 'REJECT'
  15. option 'output' 'ACCEPT'
  16. option 'forward' 'REJECT'
  17. option 'masq' '1'
  18. option 'mtu_fix' '1'
  19. option 'network' 'wan wwan'
  20. config 'forwarding'
  21. option 'src' 'lan'
  22. option 'dest' 'wan'
  23. config 'rule'
  24. option 'name' 'Allow-DHCP-Renew'
  25. option 'src' 'wan'
  26. option 'proto' 'udp'
  27. option 'dest_port' '68'
  28. option 'target' 'ACCEPT'
  29. option 'family' 'ipv4'
  30. config 'rule'
  31. option 'name' 'Allow-Ping'
  32. option 'src' 'wan'
  33. option 'proto' 'icmp'
  34. option 'icmp_type' 'echo-request'
  35. option 'family' 'ipv4'
  36. option 'target' 'ACCEPT'
  37. config 'rule'
  38. option 'name' 'Allow-DHCPv6'
  39. option 'src' 'wan'
  40. option 'proto' 'udp'
  41. option 'src_ip' 'fe80::/10'
  42. option 'src_port' '547'
  43. option 'dest_ip' 'fe80::/10'
  44. option 'dest_port' '546'
  45. option 'family' 'ipv6'
  46. option 'target' 'ACCEPT'
  47. config 'rule'
  48. option 'name' 'Allow-ICMPv6-Input'
  49. option 'src' 'wan'
  50. option 'proto' 'icmp'
  51. list 'icmp_type' 'echo-request'
  52. list 'icmp_type' 'destination-unreachable'
  53. list 'icmp_type' 'packet-too-big'
  54. list 'icmp_type' 'time-exceeded'
  55. list 'icmp_type' 'bad-header'
  56. list 'icmp_type' 'unknown-header-type'
  57. list 'icmp_type' 'router-solicitation'
  58. list 'icmp_type' 'neighbour-solicitation'
  59. option 'limit' '1000/sec'
  60. option 'family' 'ipv6'
  61. option 'target' 'ACCEPT'
  62. config 'rule'
  63. option 'name' 'Allow-ICMPv6-Forward'
  64. option 'src' 'wan'
  65. option 'dest' '*'
  66. option 'proto' 'icmp'
  67. list 'icmp_type' 'echo-request'
  68. list 'icmp_type' 'destination-unreachable'
  69. list 'icmp_type' 'packet-too-big'
  70. list 'icmp_type' 'time-exceeded'
  71. list 'icmp_type' 'bad-header'
  72. list 'icmp_type' 'unknown-header-type'
  73. option 'limit' '1000/sec'
  74. option 'family' 'ipv6'
  75. option 'target' 'ACCEPT'
  76. config 'include'
  77. option 'path' '/etc/firewall.user'
  78. config 'zone'
  79. option 'name' 'newzone'
  80. option 'input' 'ACCEPT'
  81. option 'forward' 'REJECT'
  82. option 'network' ' '
  83. option 'output' 'ACCEPT'
  84. config 'rule'
  85. option 'target' 'ACCEPT'
  86. option 'src' 'wan'
  87. option 'dest_port' '22'
  88. option 'name' 'ssh'
  89. option 'family' 'ipv4'
  90. option 'proto' 'tcp udp'
  91. config 'rule'
  92. option 'target' 'ACCEPT'
  93. option 'src' 'wan'
  94. option 'dest_port' '80'
  95. option 'name' 'web'
  96. option 'family' 'ipv4'
  97. option 'proto' 'tcp udp'
  98. config 'rule'
  99. option 'target' 'ACCEPT'
  100. option 'src' 'wan'
  101. option 'dest_port' '4028'
  102. option 'name' 'cgminer'
  103. option 'family' 'ipv4'
  104. option 'proto' 'tcp udp'