firewall.config 1.7 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889
  1. config defaults
  2. option syn_flood 1
  3. option input ACCEPT
  4. option output ACCEPT
  5. option forward REJECT
  6. config zone
  7. option name lan
  8. option input ACCEPT
  9. option output ACCEPT
  10. option forward REJECT
  11. config zone
  12. option name wan
  13. option input REJECT
  14. option output ACCEPT
  15. option forward REJECT
  16. option masq 1
  17. option mtu_fix 1
  18. config forwarding
  19. option src lan
  20. option dest wan
  21. # We need to accept udp packets on port 68,
  22. # see https://dev.openwrt.org/ticket/4108
  23. config rule
  24. option src wan
  25. option proto udp
  26. option dest_port 68
  27. option target ACCEPT
  28. # include a file with users custom iptables rules
  29. config include
  30. option path /etc/firewall.user
  31. ### EXAMPLE CONFIG SECTIONS
  32. # do not allow a specific ip to access wan
  33. #config rule
  34. # option src lan
  35. # option src_ip 192.168.45.2
  36. # option dest wan
  37. # option proto tcp
  38. # option target REJECT
  39. # block a specific mac on wan
  40. #config rule
  41. # option dest wan
  42. # option src_mac 00:11:22:33:44:66
  43. # option target REJECT
  44. # block incoming ICMP traffic on a zone
  45. #config rule
  46. # option src lan
  47. # option proto ICMP
  48. # option target DROP
  49. # port redirect port coming in on wan to lan
  50. #config redirect
  51. # option src wan
  52. # option src_dport 80
  53. # option dest lan
  54. # option dest_ip 192.168.16.235
  55. # option dest_port 80
  56. # option proto tcp
  57. ### FULL CONFIG SECTIONS
  58. #config rule
  59. # option src lan
  60. # option src_ip 192.168.45.2
  61. # option src_mac 00:11:22:33:44:55
  62. # option src_port 80
  63. # option dest wan
  64. # option dest_ip 194.25.2.129
  65. # option dest_port 120
  66. # option proto tcp
  67. # option target REJECT
  68. #config redirect
  69. # option src lan
  70. # option src_ip 192.168.45.2
  71. # option src_mac 00:11:22:33:44:55
  72. # option src_port 1024
  73. # option src_dport 80
  74. # option dest_ip 194.25.2.129
  75. # option dest_port 120
  76. # option proto tcp