Guest User

Untitled

a guest
Jul 22nd, 2018
89
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.11 KB | None | 0 0
  1. config 'defaults'
  2. option 'syn_flood' '1'
  3. option 'input' 'ACCEPT'
  4. option 'output' 'ACCEPT'
  5. option 'forward' 'REJECT'
  6. option 'drop_invalid' '1'
  7.  
  8. config 'zone'
  9. option 'name' 'lan'
  10. option 'input' 'ACCEPT'
  11. option 'output' 'ACCEPT'
  12. option 'forward' 'REJECT'
  13.  
  14. config 'zone'
  15. option 'name' 'wan'
  16. option 'network' 'wan henet'
  17. option 'output' 'ACCEPT'
  18. option 'masq' '1'
  19. option 'mtu_fix' '1'
  20. option 'input' 'ACCEPT'
  21. option 'forward' 'ACCEPT'
  22.  
  23. config 'forwarding'
  24. option 'src' 'lan'
  25. option 'dest' 'wan'
  26.  
  27. config 'rule'
  28. option 'src' 'wan'
  29. option 'proto' 'udp'
  30. option 'dest_port' '68'
  31. option 'target' 'ACCEPT'
  32. option 'family' 'ipv4'
  33.  
  34. config 'rule'
  35. option 'src' 'wan'
  36. option 'proto' 'icmp'
  37. option 'icmp_type' 'echo-request'
  38. option 'target' 'ACCEPT'
  39.  
  40. config 'include'
  41. option 'path' '/etc/firewall.user'
  42.  
  43. config 'rule'
  44. option 'target' 'ACCEPT'
  45.  
  46. config 'redirect'
  47. option '_name' 'burns-ssh'
  48. option 'src' 'wan'
  49. option 'proto' 'tcp'
  50. option 'src_dport' '23'
  51. option 'dest_ip' '192.168.2.50'
  52. option 'dest_port' '22'
  53. option 'target' 'DNAT'
  54. option 'dest' 'lan'
  55.  
  56. config 'redirect'
  57. option '_name' 'burns-torrent'
  58. option 'src' 'wan'
  59. option 'proto' 'tcpudp'
  60. option 'src_dport' '6881-6999'
  61. option 'dest_ip' '192.168.2.50'
  62. option 'target' 'DNAT'
  63. option 'dest' 'lan'
  64.  
  65. config 'rule'
  66. option '_name' 'block dns from outside'
  67. option 'src' 'wan'
  68. option 'proto' 'udp'
  69. option 'dest_port' '53'
  70. option 'target' 'REJECT'
  71.  
  72. config 'redirect'
  73. option '_name' 'burns-miro-torrent'
  74. option 'src' 'wan'
  75. option 'proto' 'tcpudp'
  76. option 'src_dport' '8500-8600'
  77. option 'target' 'DNAT'
  78. option 'dest' 'lan'
  79. option 'dest_ip' '192.168.2.50'
  80.  
  81. config 'rule'
  82. option '_name' 'block this stupid korean adsress'
  83. option 'src' 'wan'
  84. option 'proto' 'all'
  85. option 'src_ip' '211.235.245.121'
  86. option 'target' 'DROP'
  87.  
  88. config 'redirect'
  89. option '_name' 'ralph'
  90. option 'src' 'wan'
  91. option 'proto' 'tcp'
  92. option 'src_dport' '24'
  93. option 'dest_ip' '192.168.2.51'
  94. option 'dest_port' '22'
  95. option 'target' 'DNAT'
  96. option 'dest' 'lan'
  97.  
  98. root@bart:~# cat /etc/config/firewall
  99.  
  100. config 'defaults'
  101. option 'syn_flood' '1'
  102. option 'input' 'ACCEPT'
  103. option 'output' 'ACCEPT'
  104. option 'forward' 'REJECT'
  105. option 'drop_invalid' '1'
  106.  
  107. config 'zone'
  108. option 'name' 'lan'
  109. option 'input' 'ACCEPT'
  110. option 'output' 'ACCEPT'
  111. option 'forward' 'REJECT'
  112.  
  113. config 'zone'
  114. option 'name' 'wan'
  115. option 'network' 'wan henet'
  116. option 'output' 'ACCEPT'
  117. option 'masq' '1'
  118. option 'mtu_fix' '1'
  119. option 'input' 'ACCEPT'
  120. option 'forward' 'ACCEPT'
  121.  
  122. config 'forwarding'
  123. option 'src' 'lan'
  124. option 'dest' 'wan'
  125.  
  126. config 'rule'
  127. option 'src' 'wan'
  128. option 'proto' 'udp'
  129. option 'dest_port' '68'
  130. option 'target' 'ACCEPT'
  131. option 'family' 'ipv4'
  132.  
  133. config 'rule'
  134. option 'src' 'wan'
  135. option 'proto' 'icmp'
  136. option 'icmp_type' 'echo-request'
  137. option 'target' 'ACCEPT'
  138.  
  139. config 'include'
  140. option 'path' '/etc/firewall.user'
  141.  
  142. config 'rule'
  143. option 'target' 'ACCEPT'
  144.  
  145. config 'redirect'
  146. option '_name' 'burns-ssh'
  147. option 'src' 'wan'
  148. option 'proto' 'tcp'
  149. option 'src_dport' '23'
  150. option 'dest_ip' '192.168.2.50'
  151. option 'dest_port' '22'
  152. option 'target' 'DNAT'
  153. option 'dest' 'lan'
  154.  
  155. config 'redirect'
  156. option '_name' 'burns-torrent'
  157. option 'src' 'wan'
  158. option 'proto' 'tcpudp'
  159. option 'src_dport' '6881-6999'
  160. option 'dest_ip' '192.168.2.50'
  161. option 'target' 'DNAT'
  162. option 'dest' 'lan'
  163.  
  164. config 'rule'
  165. option '_name' 'block dns from outside'
  166. option 'src' 'wan'
  167. option 'proto' 'udp'
  168. option 'dest_port' '53'
  169. option 'target' 'REJECT'
  170.  
  171. config 'redirect'
  172. option '_name' 'burns-miro-torrent'
  173. option 'src' 'wan'
  174. option 'proto' 'tcpudp'
  175. option 'src_dport' '8500-8600'
  176. option 'target' 'DNAT'
  177. option 'dest' 'lan'
  178. option 'dest_ip' '192.168.2.50'
  179.  
  180. config 'rule'
  181. option '_name' 'block this stupid korean adsress'
  182. option 'src' 'wan'
  183. option 'proto' 'all'
  184. option 'src_ip' '211.235.245.121'
  185. option 'target' 'DROP'
  186.  
  187. config 'redirect'
  188. option '_name' 'ralph'
  189. option 'src' 'wan'
  190. option 'proto' 'tcp'
  191. option 'src_dport' '24'
  192. option 'dest_ip' '192.168.2.51'
  193. option 'dest_port' '22'
  194. option 'target' 'DNAT'
  195. option 'dest' 'lan'
Add Comment
Please, Sign In to add comment