firewall.config 1.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899
  1. config defaults
  2. option syn_flood 1
  3. option input ACCEPT
  4. option output ACCEPT
  5. option forward REJECT
  6. # Uncomment this line to disable ipv6 rules
  7. # option disable_ipv6 1
  8. config zone
  9. option name lan
  10. option input ACCEPT
  11. option output ACCEPT
  12. option forward REJECT
  13. config zone
  14. option name wan
  15. option input REJECT
  16. option output ACCEPT
  17. option forward REJECT
  18. option masq 1
  19. option mtu_fix 1
  20. config forwarding
  21. option src lan
  22. option dest wan
  23. # We need to accept udp packets on port 68,
  24. # see https://dev.openwrt.org/ticket/4108
  25. config rule
  26. option src wan
  27. option proto udp
  28. option dest_port 68
  29. option target ACCEPT
  30. option family ipv4
  31. #Allow ping
  32. config rule
  33. option src wan
  34. option proto icmp
  35. option icmp_type echo-request
  36. option target ACCEPT
  37. # include a file with users custom iptables rules
  38. config include
  39. option path /etc/firewall.user
  40. ### EXAMPLE CONFIG SECTIONS
  41. # do not allow a specific ip to access wan
  42. #config rule
  43. # option src lan
  44. # option src_ip 192.168.45.2
  45. # option dest wan
  46. # option proto tcp
  47. # option target REJECT
  48. # block a specific mac on wan
  49. #config rule
  50. # option dest wan
  51. # option src_mac 00:11:22:33:44:66
  52. # option target REJECT
  53. # block incoming ICMP traffic on a zone
  54. #config rule
  55. # option src lan
  56. # option proto ICMP
  57. # option target DROP
  58. # port redirect port coming in on wan to lan
  59. #config redirect
  60. # option src wan
  61. # option src_dport 80
  62. # option dest lan
  63. # option dest_ip 192.168.16.235
  64. # option dest_port 80
  65. # option proto tcp
  66. ### FULL CONFIG SECTIONS
  67. #config rule
  68. # option src lan
  69. # option src_ip 192.168.45.2
  70. # option src_mac 00:11:22:33:44:55
  71. # option src_port 80
  72. # option dest wan
  73. # option dest_ip 194.25.2.129
  74. # option dest_port 120
  75. # option proto tcp
  76. # option target REJECT
  77. #config redirect
  78. # option src lan
  79. # option src_ip 192.168.45.2
  80. # option src_mac 00:11:22:33:44:55
  81. # option src_port 1024
  82. # option src_dport 80
  83. # option dest_ip 194.25.2.129
  84. # option dest_port 120
  85. # option proto tcp