mirror of
https://dev.iopsys.eu/bbf/bbfdm.git
synced 2025-12-10 07:44:39 +01:00
185 lines
4 KiB
Text
185 lines
4 KiB
Text
|
|
config globals 'globals'
|
|
option enabled '1'
|
|
|
|
config defaults
|
|
option syn_flood '1'
|
|
option input 'ACCEPT'
|
|
option output 'ACCEPT'
|
|
option forward 'REJECT'
|
|
|
|
config zone 'lan'
|
|
option name 'lan'
|
|
list network 'lan'
|
|
option input 'ACCEPT'
|
|
option output 'ACCEPT'
|
|
option forward 'ACCEPT'
|
|
|
|
config zone 'wan'
|
|
option name 'wan'
|
|
list network 'wan'
|
|
list network 'wan6'
|
|
option input 'REJECT'
|
|
option output 'ACCEPT'
|
|
option forward 'REJECT'
|
|
option masq '1'
|
|
option mtu_fix '1'
|
|
|
|
config forwarding 'default_fwd_1'
|
|
option src 'lan'
|
|
option dest 'wan'
|
|
|
|
config rule 'default_rule_1'
|
|
option name 'Allow-DHCP-Renew'
|
|
option src 'wan'
|
|
option proto 'udp'
|
|
option dest_port '68'
|
|
option target 'ACCEPT'
|
|
option family 'ipv4'
|
|
|
|
config rule 'default_rule_2'
|
|
option name 'Allow-Ping'
|
|
option src 'wan'
|
|
option proto 'icmp'
|
|
option icmp_type 'echo-request'
|
|
option family 'ipv4'
|
|
option target 'ACCEPT'
|
|
|
|
config rule 'default_rule_3'
|
|
option name 'Allow-IGMP'
|
|
option src 'wan'
|
|
option proto 'igmp'
|
|
option family 'ipv4'
|
|
option target 'ACCEPT'
|
|
|
|
config rule 'default_rule_4'
|
|
option name 'Allow-DHCPv6'
|
|
option src 'wan'
|
|
option proto 'udp'
|
|
option src_ip 'fc00::/6'
|
|
option dest_ip 'fc00::/6'
|
|
option dest_port '546'
|
|
option family 'ipv6'
|
|
option target 'ACCEPT'
|
|
|
|
config rule 'default_rule_5'
|
|
option name 'Allow-MLD'
|
|
option src 'wan'
|
|
option proto 'icmp'
|
|
option src_ip 'fe80::/10'
|
|
list icmp_type '130/0'
|
|
list icmp_type '131/0'
|
|
list icmp_type '132/0'
|
|
list icmp_type '143/0'
|
|
option family 'ipv6'
|
|
option target 'ACCEPT'
|
|
|
|
config rule 'default_rule_6'
|
|
option name 'Allow-ICMPv6-Input'
|
|
option src 'wan'
|
|
option proto 'icmp'
|
|
list icmp_type 'echo-request'
|
|
list icmp_type 'echo-reply'
|
|
list icmp_type 'destination-unreachable'
|
|
list icmp_type 'packet-too-big'
|
|
list icmp_type 'time-exceeded'
|
|
list icmp_type 'bad-header'
|
|
list icmp_type 'unknown-header-type'
|
|
list icmp_type 'router-solicitation'
|
|
list icmp_type 'neighbour-solicitation'
|
|
list icmp_type 'router-advertisement'
|
|
list icmp_type 'neighbour-advertisement'
|
|
option limit '1000/sec'
|
|
option family 'ipv6'
|
|
option target 'ACCEPT'
|
|
|
|
config rule 'default_rule_7'
|
|
option name 'Allow-ICMPv6-Forward'
|
|
option src 'wan'
|
|
option dest '*'
|
|
option proto 'icmp'
|
|
list icmp_type 'echo-request'
|
|
list icmp_type 'echo-reply'
|
|
list icmp_type 'destination-unreachable'
|
|
list icmp_type 'packet-too-big'
|
|
list icmp_type 'time-exceeded'
|
|
list icmp_type 'bad-header'
|
|
list icmp_type 'unknown-header-type'
|
|
option limit '1000/sec'
|
|
option family 'ipv6'
|
|
option target 'ACCEPT'
|
|
|
|
config rule 'default_rule_8'
|
|
option name 'Allow-IPSec-ESP'
|
|
option src 'wan'
|
|
option dest 'lan'
|
|
option proto 'esp'
|
|
option target 'ACCEPT'
|
|
|
|
config rule 'default_rule_9'
|
|
option name 'Allow-ISAKMP'
|
|
option src 'wan'
|
|
option dest 'lan'
|
|
option dest_port '500'
|
|
option proto 'udp'
|
|
option target 'ACCEPT'
|
|
|
|
config rule 'default_rule_10'
|
|
option name 'Support-UDP-Traceroute'
|
|
option src 'wan'
|
|
option dest_port '33434:33689'
|
|
option proto 'udp'
|
|
option family 'ipv4'
|
|
option target 'REJECT'
|
|
option enabled 'false'
|
|
|
|
config dmz 'dmz'
|
|
option enabled '0'
|
|
option exclude_ports '5060 7547'
|
|
|
|
config include
|
|
option path '/etc/firewall.user'
|
|
option reload '1'
|
|
|
|
config include 'ddos'
|
|
option path '/etc/firewall.ddos'
|
|
option reload '1'
|
|
|
|
config include 'parental'
|
|
option path '/etc/firewall.parental'
|
|
option reload '1'
|
|
|
|
config include 'qos'
|
|
option path '/etc/firewall.qos'
|
|
option reload '1'
|
|
|
|
config include 'cwmp'
|
|
option path '/etc/firewall.cwmp'
|
|
option reload '1'
|
|
|
|
config include 'miniupnpd'
|
|
option type 'script'
|
|
option path '/usr/share/miniupnpd/firewall.include'
|
|
option family 'any'
|
|
option reload '1'
|
|
|
|
config include 'sip'
|
|
option path '/etc/firewall.sip'
|
|
option reload '1'
|
|
|
|
config include 'dmzhost'
|
|
option path '/etc/firewall.dmz'
|
|
option reload '1'
|
|
|
|
config redirect 'port_mapping_1'
|
|
option enabled '1'
|
|
option src 'wan'
|
|
option dest 'lan'
|
|
option target 'DNAT'
|
|
option reflection '1'
|
|
option name 'test'
|
|
option proto 'tcp'
|
|
option dest_ip 'wan'
|
|
option src_dport '192.168.3.45'
|
|
option src_dport '50:60'
|
|
option dest_port '44'
|