Guest User

Untitled

a guest
Jul 22nd, 2018
70
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.70 KB | None | 0 0
  1. package 'firewall'
  2.  
  3. config 'defaults'
  4. option 'syn_flood' '1'
  5. option 'input' 'ACCEPT'
  6. option 'output' 'ACCEPT'
  7. option 'forward' 'REJECT'
  8. option 'drop_invalid' '1'
  9.  
  10. config 'zone'
  11. option 'name' 'lan'
  12. option 'network' 'lan'
  13. option 'input' 'ACCEPT'
  14. option 'output' 'ACCEPT'
  15. option 'forward' 'REJECT'
  16.  
  17. config 'zone'
  18. option 'name' 'wan'
  19. option 'network' 'wan'
  20. option 'input' 'REJECT'
  21. option 'output' 'ACCEPT'
  22. option 'forward' 'REJECT'
  23. option 'masq' '1'
  24. option 'mtu_fix' '1'
  25.  
  26. config 'forwarding'
  27. option 'src' 'lan'
  28. option 'dest' 'wan'
  29.  
  30. config 'rule'
  31. option 'name' 'Allow-DHCP-Renew'
  32. option 'src' 'wan'
  33. option 'proto' 'udp'
  34. option 'dest_port' '68'
  35. option 'target' 'ACCEPT'
  36. option 'family' 'ipv4'
  37.  
  38. config 'rule'
  39. option 'name' 'Allow-Ping'
  40. option 'src' 'wan'
  41. option 'proto' 'icmp'
  42. option 'icmp_type' 'echo-request'
  43. option 'family' 'ipv4'
  44. option 'target' 'ACCEPT'
  45.  
  46. config 'rule'
  47. option 'name' 'Allow-DHCPv6'
  48. option 'src' 'wan'
  49. option 'proto' 'udp'
  50. option 'src_ip' 'fe80::/10'
  51. option 'src_port' '547'
  52. option 'dest_ip' 'fe80::/10'
  53. option 'dest_port' '546'
  54. option 'family' 'ipv6'
  55. option 'target' 'ACCEPT'
  56.  
  57. config 'rule'
  58. option 'name' 'Allow-ICMPv6-Input'
  59. option 'src' 'wan'
  60. option 'proto' 'icmp'
  61. list 'icmp_type' 'echo-request'
  62. list 'icmp_type' 'destination-unreachable'
  63. list 'icmp_type' 'packet-too-big'
  64. list 'icmp_type' 'time-exceeded'
  65. list 'icmp_type' 'bad-header'
  66. list 'icmp_type' 'unknown-header-type'
  67. list 'icmp_type' 'router-solicitation'
  68. list 'icmp_type' 'neighbour-solicitation'
  69. option 'limit' '1000/sec'
  70. option 'family' 'ipv6'
  71. option 'target' 'ACCEPT'
  72.  
  73. config 'rule'
  74. option 'name' 'Allow-ICMPv6-Forward'
  75. option 'src' 'wan'
  76. option 'dest' '*'
  77. option 'proto' 'icmp'
  78. list 'icmp_type' 'echo-request'
  79. list 'icmp_type' 'destination-unreachable'
  80. list 'icmp_type' 'packet-too-big'
  81. list 'icmp_type' 'time-exceeded'
  82. list 'icmp_type' 'bad-header'
  83. list 'icmp_type' 'unknown-header-type'
  84. option 'limit' '1000/sec'
  85. option 'family' 'ipv6'
  86. option 'target' 'ACCEPT'
  87.  
  88. config 'include'
  89. option 'path' '/etc/firewall.user'
  90.  
  91. config 'redirect'
  92. option '_name' 'AnsibleStorage SSH'
  93. option 'src' 'wan'
  94. option 'proto' 'tcp'
  95. option 'src_dport' '22'
  96. option 'dest_ip' '172.16.1.150'
  97. option 'dest_port' '22'
  98. option 'target' 'DNAT'
  99. option 'dest' 'lan'
  100.  
  101. config 'redirect'
  102. option 'src' 'wan'
  103. option 'proto' 'udp'
  104. option 'dest_ip' '172.16.1.152'
  105. option 'target' 'DNAT'
  106. option 'dest' 'lan'
  107. option '_name' 'AnsibleThreshold OpenVPN 1'
  108. option 'src_dport' '1294'
  109. option 'dest_port' '1294'
  110.  
  111. config 'rule'
  112. option 'target' 'ACCEPT'
  113.  
  114. config 'rule'
  115. option 'target' 'ACCEPT'
  116.  
  117. config 'rule'
  118. option 'target' 'ACCEPT'
Add Comment
Please, Sign In to add comment