firewall 1.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101
  1. config defaults
  2. option input 'ACCEPT'
  3. option output 'ACCEPT'
  4. option forward 'REJECT'
  5. option synflood_protect '1'
  6. config zone
  7. option name 'lan'
  8. option input 'ACCEPT'
  9. option output 'ACCEPT'
  10. option forward 'ACCEPT'
  11. option network 'lan'
  12. config zone
  13. option name 'wan'
  14. option input 'REJECT'
  15. option output 'ACCEPT'
  16. option forward 'REJECT'
  17. option masq '1'
  18. option mtu_fix '1'
  19. option network 'wan wan6'
  20. config forwarding
  21. option src 'lan'
  22. option dest 'wan'
  23. config rule
  24. option name 'Allow-ICMPv6-Forward'
  25. option src 'wan'
  26. option dest '*'
  27. option proto 'icmp'
  28. list icmp_type 'echo-request'
  29. list icmp_type 'echo-reply'
  30. list icmp_type 'destination-unreachable'
  31. list icmp_type 'packet-too-big'
  32. list icmp_type 'time-exceeded'
  33. list icmp_type 'bad-header'
  34. list icmp_type 'unknown-header-type'
  35. option limit '1000/sec'
  36. option family 'ipv6'
  37. option target 'ACCEPT'
  38. config rule
  39. option name 'Allow-IPSec-ESP'
  40. option src 'wan'
  41. option dest 'lan'
  42. option proto 'esp'
  43. option target 'ACCEPT'
  44. config rule
  45. option name 'Allow-ISAKMP'
  46. option src 'wan'
  47. option dest 'lan'
  48. option dest_port '500'
  49. option proto 'udp'
  50. option target 'ACCEPT'
  51. config include
  52. option path '/etc/firewall.user'
  53. config zone
  54. option name 'lan6v'
  55. option input 'ACCEPT'
  56. option network 'LAN6'
  57. option output 'ACCEPT'
  58. option forward 'ACCEPT'
  59. config forwarding
  60. option dest 'lan'
  61. option src 'lan6v'
  62. config zone
  63. option name 'lanv6wan'
  64. option input 'ACCEPT'
  65. option forward 'ACCEPT'
  66. option network 'LAN6'
  67. option output 'ACCEPT'
  68. config forwarding
  69. option dest 'wan'
  70. option src 'lanv6wan'
  71. config zone
  72. option name 'lanlan6v'
  73. option input 'ACCEPT'
  74. option forward 'ACCEPT'
  75. option network 'lan'
  76. option output 'ACCEPT'
  77. config forwarding
  78. option dest 'lan6v'
  79. option src 'lanlan6v'
  80. config zone
  81. option name 'VLAN7'
  82. option input 'ACCEPT'
  83. option forward 'ACCEPT'
  84. option network 'VLAN7'
  85. option output 'ACCEPT'