firewall.config 1.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081
  1. config defaults
  2. option syn_flood 1
  3. option input ACCEPT
  4. option output ACCEPT
  5. option forward REJECT
  6. config zone
  7. option name lan
  8. option input ACCEPT
  9. option output ACCEPT
  10. option forward REJECT
  11. config zone
  12. option name wan
  13. option input REJECT
  14. option output ACCEPT
  15. option forward REJECT
  16. option masq 1
  17. config forwarding
  18. option src lan
  19. option dest wan
  20. option mtu_fix 1
  21. ### EXAMPLE CONFIG SECTIONS
  22. # do not allow a specific ip to access wan
  23. #config rule
  24. # option src lan
  25. # option src_ip 192.168.45.2
  26. # option dest wan
  27. # option proto tcp
  28. # option target REJECT
  29. # block a specific mac on wan
  30. #config rule
  31. # option dest wan
  32. # option src_mac 00:11:22:33:44:66
  33. # option target REJECT
  34. # block incoming ICMP traffic on a zone
  35. #config rule
  36. # option src lan
  37. # option proto ICMP
  38. # option target DROP
  39. # port redirect port coming in on wan to lan
  40. #config redirect
  41. # option src wan
  42. # option src_dport 80
  43. # option dest lan
  44. # option dest_ip 192.168.16.235
  45. # option dest_port 80
  46. # option proto tcp
  47. # include a file with users custom iptables rules
  48. #config include
  49. # option path /etc/firewall.user
  50. ### FULL CONFIG SECTIONS
  51. #config rule
  52. # option src lan
  53. # option src_ip 192.168.45.2
  54. # option src_mac 00:11:22:33:44:55
  55. # option src_port 80
  56. # option dest wan
  57. # option dest_ip 194.25.2.129
  58. # option dest_port 120
  59. # option proto tcp
  60. # option target REJECT
  61. #config redirect
  62. # option src lan
  63. # option src_ip 192.168.45.2
  64. # option src_mac 00:11:22:33:44:55
  65. # option src_port 1024
  66. # option src_dport 80
  67. # option dest_ip 194.25.2.129
  68. # option dest_port 120
  69. # option proto tcp