Просмотр исходного кода

firewall: add DHCPv6 default rule (#10381)

SVN-Revision: 28874
Jo-Philipp Wich 14 лет назад
Родитель
Сommit
10f199d832
2 измененных файлов с 13 добавлено и 1 удалено
  1. 1 1
      package/firewall/Makefile
  2. 12 0
      package/firewall/files/firewall.config

+ 1 - 1
package/firewall/Makefile

@@ -9,7 +9,7 @@ include $(TOPDIR)/rules.mk
 PKG_NAME:=firewall
 
 PKG_VERSION:=2
-PKG_RELEASE:=41
+PKG_RELEASE:=42
 
 include $(INCLUDE_DIR)/package.mk
 

+ 12 - 0
package/firewall/files/firewall.config

@@ -43,6 +43,18 @@ config rule
 	option family		ipv4
 	option target		ACCEPT
 
+# Allow DHCPv6 replies
+# see https://dev.openwrt.org/ticket/10381
+config rule
+	option src		wan
+	option proto		udp
+	option src_ip		fe80::/10
+	option src_port		547
+	option dest_ip		fe80::/10
+	option dest_port	546
+	option family		ipv6
+	option target		ACCEPT
+
 # Allow essential incoming IPv6 ICMP traffic
 config rule
 	option src		wan