Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- firewall.@rule[0]=rule
- firewall.@rule[0].name='Allow-DHCP-Renew'
- firewall.@rule[0].src='wan'
- firewall.@rule[0].proto='udp'
- firewall.@rule[0].dest_port='68'
- firewall.@rule[0].target='ACCEPT'
- firewall.@rule[0].family='ipv4'
- firewall.@rule[1]=rule
- firewall.@rule[1].name='Allow-Ping'
- firewall.@rule[1].src='wan'
- firewall.@rule[1].proto='icmp'
- firewall.@rule[1].icmp_type='echo-request'
- firewall.@rule[1].family='ipv4'
- firewall.@rule[1].target='ACCEPT'
- firewall.@rule[2]=rule
- firewall.@rule[2].name='Allow-IGMP'
- firewall.@rule[2].src='wan'
- firewall.@rule[2].proto='igmp'
- firewall.@rule[2].family='ipv4'
- firewall.@rule[2].target='ACCEPT'
- firewall.@rule[3]=rule
- firewall.@rule[3].name='Allow-DHCPv6'
- firewall.@rule[3].src='wan'
- firewall.@rule[3].proto='udp'
- firewall.@rule[3].src_ip='fc00::/6'
- firewall.@rule[3].dest_ip='fc00::/6'
- firewall.@rule[3].dest_port='546'
- firewall.@rule[3].family='ipv6'
- firewall.@rule[3].target='ACCEPT'
- firewall.@rule[4]=rule
- firewall.@rule[4].name='Allow-MLD'
- firewall.@rule[4].src='wan'
- firewall.@rule[4].proto='icmp'
- firewall.@rule[4].src_ip='fe80::/10'
- firewall.@rule[4].icmp_type='130/0' '131/0' '132/0' '143/0'
- firewall.@rule[4].family='ipv6'
- firewall.@rule[4].target='ACCEPT'
- firewall.@rule[5]=rule
- firewall.@rule[5].target='ACCEPT'
- firewall.@rule[5].name='Allow-All-Ping'
- firewall.@rule[5].proto='icmp'
- firewall.@rule[5].dest='*'
- firewall.@rule[5].src='*'
- firewall.@rule[5].icmp_type='echo-request'
- firewall.@rule[6]=rule
- firewall.@rule[6].target='ACCEPT'
- firewall.@rule[6].name='Allow-VPN-ICMP'
- firewall.@rule[6].proto='icmp'
- firewall.@rule[6].src='vpn'
- firewall.@rule[7]=rule
- firewall.@rule[7].target='ACCEPT'
- firewall.@rule[7].name='Allow-Lan-to-Wan'
- firewall.@rule[7].dest='wan'
- firewall.@rule[7].src='lan'
- firewall.@rule[8]=rule
- firewall.@rule[8].target='ACCEPT'
- firewall.@rule[8].name='ICMPv6-Lan-to-OMR'
- firewall.@rule[8].src='lan'
- firewall.@rule[8].family='ipv6'
- firewall.@rule[8].proto='icmp'
- firewall.@rule[8].limit='1000/sec'
- firewall.@rule[8].icmp_type='echo-reply destination-unreachable echo-request router-advertisement router-solicitation time-exceeded'
- firewall.@defaults[0]=defaults
- firewall.@defaults[0].syn_flood='1'
- firewall.@defaults[0].forward='REJECT'
- firewall.@defaults[0].disable_ipv6='1'
- firewall.@defaults[0].input='REJECT'
- firewall.@defaults[0].output='REJECT'
- firewall.@zone[0]=zone
- firewall.@zone[0].name='lan'
- firewall.@zone[0].input='ACCEPT'
- firewall.@zone[0].output='ACCEPT'
- firewall.@zone[0].forward='ACCEPT'
- firewall.@zone[0].mtu_fix='1'
- firewall.@zone[0].network='lan'
- firewall.@zone[1]=zone
- firewall.@zone[1].name='wan'
- firewall.@zone[1].input='REJECT'
- firewall.@zone[1].output='ACCEPT'
- firewall.@zone[1].forward='REJECT'
- firewall.@zone[1].masq='1'
- firewall.@zone[1].mtu_fix='1'
- firewall.@zone[1].network='wan wan6 WAN1 WAN1 wan1 WAN1 wan1 wan3 wan2 wan1 wan1'
- firewall.@forwarding[0]=forwarding
- firewall.@forwarding[0].src='lan'
- firewall.@forwarding[0].dest='wan'
- firewall.@include[0]=include
- firewall.@include[0].path='/etc/firewall.user'
- firewall.ss_rules=include
- firewall.ss_rules.path='/etc/firewall.ss-rules'
- firewall.ss_rules.reload='1'
- firewall.@redirect[0]=redirect
- firewall.@redirect[0].target='DNAT'
- firewall.@redirect[0].src='vpn'
- firewall.@redirect[0].dest='lan'
- firewall.@redirect[0].proto='tcp'
- firewall.@redirect[0].src_dport='15501'
- firewall.@redirect[0].dest_ip='192.168.21.150'
- firewall.@redirect[0].dest_port='15501'
- firewall.@redirect[0].name='interface WEB DSM HTTPS 15501'
- firewall.@redirect[1]=redirect
- firewall.@redirect[1].target='DNAT'
- firewall.@redirect[1].src='vpn'
- firewall.@redirect[1].dest='lan'
- firewall.@redirect[1].proto='tcp'
- firewall.@redirect[1].src_dport='15500'
- firewall.@redirect[1].dest_ip='192.168.21.150'
- firewall.@redirect[1].dest_port='15500'
- firewall.@redirect[1].name='Interface WEB DSM HTTP 15500'
- firewall.@redirect[2]=redirect
- firewall.@redirect[2].target='DNAT'
- firewall.@redirect[2].proto='tcp'
- firewall.@redirect[2].src='vpn'
- firewall.@redirect[2].src_dport='443'
- firewall.@redirect[2].dest='lan'
- firewall.@redirect[2].dest_ip='192.168.21.150'
- firewall.@redirect[2].name='interface WEB DSM HTTPS 443'
- firewall.@redirect[2].dest_port='443'
- firewall.@redirect[3]=redirect
- firewall.@redirect[3].target='DNAT'
- firewall.@redirect[3].src='vpn'
- firewall.@redirect[3].dest='lan'
- firewall.@redirect[3].proto='tcp'
- firewall.@redirect[3].src_dport='443'
- firewall.@redirect[3].dest_ip='192.168.21.150'
- firewall.@redirect[3].dest_port='15501'
- firewall.@redirect[3].name='interface-DSM-contournement-firewall'
- firewall.@redirect[3].enabled='0'
- firewall.@redirect[4]=redirect
- firewall.@redirect[4].target='DNAT'
- firewall.@redirect[4].src='vpn'
- firewall.@redirect[4].dest='lan'
- firewall.@redirect[4].proto='tcp'
- firewall.@redirect[4].src_dport='80'
- firewall.@redirect[4].dest_ip='192.168.21.150'
- firewall.@redirect[4].dest_port='80'
- firewall.@redirect[4].name='activation certificat let'\''s encrypt'
- firewall.@redirect[5]=redirect
- firewall.@redirect[5].target='DNAT'
- firewall.@redirect[5].src='vpn'
- firewall.@redirect[5].dest='lan'
- firewall.@redirect[5].proto='tcp'
- firewall.@redirect[5].src_dport='5006'
- firewall.@redirect[5].dest_ip='192.168.21.150'
- firewall.@redirect[5].dest_port='5006'
- firewall.@redirect[5].name='WEBDAVS synology'
- firewall.@redirect[6]=redirect
- firewall.@redirect[6].target='DNAT'
- firewall.@redirect[6].name='WEBDAV synology'
- firewall.@redirect[6].proto='tcp udp'
- firewall.@redirect[6].src='vpn'
- firewall.@redirect[6].src_dport='5005'
- firewall.@redirect[6].dest='lan'
- firewall.@redirect[6].dest_ip='192.168.21.150'
- firewall.@redirect[6].dest_port='5005'
- firewall.@redirect[6].enabled='0'
- firewall.@redirect[7]=redirect
- firewall.@redirect[7].target='DNAT'
- firewall.@redirect[7].src='vpn'
- firewall.@redirect[7].dest='lan'
- firewall.@redirect[7].proto='tcp'
- firewall.@redirect[7].src_dport='6690'
- firewall.@redirect[7].dest_ip='192.168.21.150'
- firewall.@redirect[7].dest_port='6690'
- firewall.@redirect[7].name='drive'
- firewall.@redirect[8]=redirect
- firewall.@redirect[8].target='DNAT'
- firewall.@redirect[8].src='vpn'
- firewall.@redirect[8].dest='lan'
- firewall.@redirect[8].proto='tcp'
- firewall.@redirect[8].dest_ip='192.168.21.150'
- firewall.@redirect[8].dest_port='6690'
- firewall.@redirect[8].name='drive_contournement'
- firewall.@redirect[8].src_dport='53'
- firewall.@rule[9]=rule
- firewall.@rule[9].target='ACCEPT'
- firewall.@rule[9].name='Allow-All-Ping'
- firewall.@rule[9].proto='icmp'
- firewall.@rule[9].dest='*'
- firewall.@rule[9].src='*'
- firewall.@rule[9].icmp_type='echo-request'
- firewall.@rule[10]=rule
- firewall.@rule[10].target='ACCEPT'
- firewall.@rule[10].name='Allow-All-Ping'
- firewall.@rule[10].proto='icmp'
- firewall.@rule[10].dest='*'
- firewall.@rule[10].src='*'
- firewall.@rule[10].icmp_type='echo-request'
- firewall.@rule[11]=rule
- firewall.@rule[11].target='ACCEPT'
- firewall.@rule[11].name='Allow-All-Ping'
- firewall.@rule[11].proto='icmp'
- firewall.@rule[11].dest='*'
- firewall.@rule[11].src='*'
- firewall.@rule[11].icmp_type='echo-request'
- firewall.@rule[12]=rule
- firewall.@rule[12].target='ACCEPT'
- firewall.@rule[12].name='Allow-All-Ping'
- firewall.@rule[12].proto='icmp'
- firewall.@rule[12].dest='*'
- firewall.@rule[12].src='*'
- firewall.@rule[12].icmp_type='echo-request'
- firewall.@rule[13]=rule
- firewall.@rule[13].target='ACCEPT'
- firewall.@rule[13].name='Allow-All-Ping'
- firewall.@rule[13].proto='icmp'
- firewall.@rule[13].dest='*'
- firewall.@rule[13].src='*'
- firewall.@rule[13].icmp_type='echo-request'
- firewall.@rule[14]=rule
- firewall.@rule[14].target='ACCEPT'
- firewall.@rule[14].name='Allow-All-Ping'
- firewall.@rule[14].proto='icmp'
- firewall.@rule[14].dest='*'
- firewall.@rule[14].src='*'
- firewall.@rule[14].icmp_type='echo-request'
- firewall.@rule[15]=rule
- firewall.@rule[15].target='ACCEPT'
- firewall.@rule[15].name='Allow-All-Ping'
- firewall.@rule[15].proto='icmp'
- firewall.@rule[15].dest='*'
- firewall.@rule[15].src='*'
- firewall.@rule[15].icmp_type='echo-request'
- firewall.omr_server=include
- firewall.omr_server.path='/etc/firewall.omr-server'
- firewall.omr_server.reload='1'
- firewall.@rule[16]=rule
- firewall.@rule[16].target='ACCEPT'
- firewall.@rule[16].name='Allow-All-Ping'
- firewall.@rule[16].proto='icmp'
- firewall.@rule[16].dest='*'
- firewall.@rule[16].src='*'
- firewall.@rule[16].icmp_type='echo-request'
- firewall.@rule[17]=rule
- firewall.@rule[17].target='ACCEPT'
- firewall.@rule[17].name='Allow-All-Ping'
- firewall.@rule[17].proto='icmp'
- firewall.@rule[17].dest='*'
- firewall.@rule[17].src='*'
- firewall.@rule[17].icmp_type='echo-request'
- firewall.@rule[18]=rule
- firewall.@rule[18].target='ACCEPT'
- firewall.@rule[18].name='Allow-All-Ping'
- firewall.@rule[18].proto='icmp'
- firewall.@rule[18].dest='*'
- firewall.@rule[18].src='*'
- firewall.@rule[18].icmp_type='echo-request'
- firewall.@rule[19]=rule
- firewall.@rule[19].target='ACCEPT'
- firewall.@rule[19].name='Allow-All-Ping'
- firewall.@rule[19].proto='icmp'
- firewall.@rule[19].dest='*'
- firewall.@rule[19].src='*'
- firewall.@rule[19].icmp_type='echo-request'
- firewall.@rule[20]=rule
- firewall.@rule[20].target='ACCEPT'
- firewall.@rule[20].name='Allow-All-Ping'
- firewall.@rule[20].proto='icmp'
- firewall.@rule[20].dest='*'
- firewall.@rule[20].src='*'
- firewall.@rule[20].icmp_type='echo-request'
- firewall.@rule[21]=rule
- firewall.@rule[21].target='ACCEPT'
- firewall.@rule[21].name='Allow-All-Ping'
- firewall.@rule[21].proto='icmp'
- firewall.@rule[21].dest='*'
- firewall.@rule[21].src='*'
- firewall.@rule[21].icmp_type='echo-request'
- firewall.@rule[22]=rule
- firewall.@rule[22].target='ACCEPT'
- firewall.@rule[22].name='Allow-All-Ping'
- firewall.@rule[22].proto='icmp'
- firewall.@rule[22].dest='*'
- firewall.@rule[22].src='*'
- firewall.@rule[22].icmp_type='echo-request'
- firewall.@rule[23]=rule
- firewall.@rule[23].target='ACCEPT'
- firewall.@rule[23].name='Allow-All-Ping'
- firewall.@rule[23].proto='icmp'
- firewall.@rule[23].dest='*'
- firewall.@rule[23].src='*'
- firewall.@rule[23].icmp_type='echo-request'
- firewall.@redirect[9]=redirect
- firewall.@redirect[9].dest_port='500'
- firewall.@redirect[9].src='vpn'
- firewall.@redirect[9].name='ipsec'
- firewall.@redirect[9].src_dport='500'
- firewall.@redirect[9].target='DNAT'
- firewall.@redirect[9].dest='lan'
- firewall.@redirect[9].proto='udp'
- firewall.@redirect[9].dest_ip='192.168.21.253'
- firewall.@redirect[9].enabled='0'
- firewall.@redirect[10]=redirect
- firewall.@redirect[10].dest_port='4500'
- firewall.@redirect[10].name='ipsec'
- firewall.@redirect[10].src_dport='4500'
- firewall.@redirect[10].target='DNAT'
- firewall.@redirect[10].dest_ip='192.168.21.253'
- firewall.@redirect[10].dest='lan'
- firewall.@redirect[10].proto='udp'
- firewall.@redirect[10].src='vpn'
- firewall.@redirect[10].enabled='0'
- firewall.zone_vpn=zone
- firewall.zone_vpn.name='vpn'
- firewall.zone_vpn.masq='1'
- firewall.zone_vpn.input='REJECT'
- firewall.zone_vpn.forward='ACCEPT'
- firewall.zone_vpn.output='ACCEPT'
- firewall.zone_vpn.mtu_fix='1'
- firewall.zone_vpn.network='glorytun' 'omrvpn' 'omr6in4'
- firewall.gre_tunnel=include
- firewall.gre_tunnel.path='/etc/firewall.gre-tunnel'
- firewall.gre_tunnel.reload='1'
- firewall.allow_dhcp_request_vpn=rule
- firewall.allow_dhcp_request_vpn.name='Allow-DHCP-Request-VPN'
- firewall.allow_dhcp_request_vpn.src='vpn'
- firewall.allow_dhcp_request_vpn.proto='udp'
- firewall.allow_dhcp_request_vpn.dest_port='67'
- firewall.allow_dhcp_request_vpn.target='ACCEPT'
- firewall.allow_dhcp_request_vpn.family='ipv4'
- firewall.miniupnpd=include
- firewall.miniupnpd.type='script'
- firewall.miniupnpd.path='/usr/share/miniupnpd/firewall.include'
- firewall.miniupnpd.family='any'
- firewall.miniupnpd.reload='1'
Add Comment
Please, Sign In to add comment