Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- root@OpenWrt:~# ubus call system board
- {
- "kernel": "4.14.209",
- "hostname": "OpenWrt",
- "system": "MediaTek MT7621 ver:1 eco:3",
- "model": "Netgear R6220",
- "board_name": "r6220",
- "release": {
- "distribution": "OpenWrt",
- "version": "19.07.5",
- "revision": "r11257-5090152ae3",
- "target": "ramips/mt7621",
- "description": "OpenWrt 19.07.5 r11257-5090152ae3"
- }
- }
- root@OpenWrt:~# uci show network
- network.loopback=interface
- network.loopback.ifname='lo'
- network.loopback.proto='static'
- network.loopback.ipaddr='127.0.0.1'
- network.loopback.netmask='255.0.0.0'
- network.globals=globals
- network.globals.ula_prefix='dd4e:2271:c462::/48'
- network.lan=interface
- network.lan.type='bridge'
- network.lan.ifname='eth0.1'
- network.lan.proto='static'
- network.lan.netmask='255.255.255.0'
- network.lan.ip6assign='60'
- network.lan.ipaddr='192.168.0.1'
- network.lan_eth0_1_dev=device
- network.lan_eth0_1_dev.name='eth0.1'
- network.lan_eth0_1_dev.macaddr='08:02:8e:e6:43:e8'
- network.wan=interface
- network.wan.ifname='eth0.2'
- network.wan.proto='dhcp'
- network.wan.metric='10'
- network.wan.delegate='0'
- network.wan_eth0_2_dev=device
- network.wan_eth0_2_dev.name='eth0.2'
- network.wan_eth0_2_dev.macaddr='08:02:8e:e6:43:e9'
- network.wan6=interface
- network.wan6.ifname='eth0.2'
- network.wan6.proto='dhcpv6'
- network.wan6.reqaddress='try'
- network.wan6.reqprefix='auto'
- network.wan6.metric='10'
- network.@switch[0]=switch
- network.@switch[0].name='switch0'
- network.@switch[0].reset='1'
- network.@switch[0].enable_vlan='1'
- network.@switch_vlan[0]=switch_vlan
- network.@switch_vlan[0].device='switch0'
- network.@switch_vlan[0].vlan='1'
- network.@switch_vlan[0].vid='1'
- network.@switch_vlan[0].ports='6t 1 0'
- network.@switch_vlan[1]=switch_vlan
- network.@switch_vlan[1].device='switch0'
- network.@switch_vlan[1].vlan='2'
- network.@switch_vlan[1].vid='2'
- network.@switch_vlan[1].ports='6t 4'
- network.@switch_vlan[2]=switch_vlan
- network.@switch_vlan[2].device='switch0'
- network.@switch_vlan[2].vlan='3'
- network.@switch_vlan[2].vid='3'
- network.@switch_vlan[2].ports='6t 3'
- network.wanb=interface
- network.wanb.ifname='eth0.3'
- network.wanb.proto='static'
- network.wanb.netmask='255.255.255.0'
- network.wanb.ipaddr='192.168.4.4'
- network.wanb.gateway='192.168.4.1'
- network.wanb.metric='20'
- network.wanb.macaddr='08:02:8e:e6:43:e7'
- network.wanb.force_link='0'
- network.wanb.delegate='0'
- network.wanb6=interface
- network.wanb6.ifname='eth0.3'
- network.wanb6.proto='dhcpv6'
- network.wanb6.reqaddress='try'
- network.wanb6.reqprefix='auto'
- network.wanb6.macaddr='08:02:8e:e6:43:e7'
- network.wanb6.metric='20'
- network.@switch_vlan[3]=switch_vlan
- network.@switch_vlan[3].device='switch0'
- network.@switch_vlan[3].vlan='5'
- network.@switch_vlan[3].vid='131'
- network.@switch_vlan[3].ports='6t 2t'
- network.@switch_vlan[4]=switch_vlan
- network.@switch_vlan[4].device='switch0'
- network.@switch_vlan[4].vlan='6'
- network.@switch_vlan[4].vid='1849'
- network.@switch_vlan[4].ports='6t 2t'
- network.@switch_vlan[5]=switch_vlan
- network.@switch_vlan[5].device='switch0'
- network.@switch_vlan[5].vlan='7'
- network.@switch_vlan[5].ports='6t 2'
- network.@switch_vlan[5].vid='4'
- network.wanc=interface
- network.wanc.ifname='eth0.4'
- network.wanc.proto='static'
- network.wanc.netmask='255.255.255.0'
- network.wanc.ipaddr='192.168.100.2'
- network.wanc.gateway='192.168.100.1'
- network.wanc.metric='30'
- network.wanc.delegate='0'
- network.wancvirtual=interface
- network.wancvirtual.ifname='eth0.4'
- network.wancvirtual.proto='static'
- network.wancvirtual.netmask='255.255.255.0'
- network.wancvirtual.ipaddr='192.168.100.4'
- network.wancvirtual.gateway='192.168.100.1'
- network.wancvirtual.metric='35'
- network.wancvirtual.macaddr='7c:a9:6b:37:28:2d'
- network.wanc6=interface
- network.wanc6.proto='dhcpv6'
- network.wanc6.reqprefix='auto'
- network.wanc6.reqaddress='try'
- network.wanc6.mtu='1492'
- network.wanc6.macaddr='7c:a9:6b:37:28:2e'
- network.wanc6.ifname='eth0.4'
- network.wanc6.metric='30'
- root@OpenWrt:~# uci show dhcp
- dhcp.@dnsmasq[0]=dnsmasq
- dhcp.@dnsmasq[0].domainneeded='1'
- dhcp.@dnsmasq[0].boguspriv='1'
- dhcp.@dnsmasq[0].filterwin2k='0'
- dhcp.@dnsmasq[0].localise_queries='1'
- dhcp.@dnsmasq[0].rebind_protection='1'
- dhcp.@dnsmasq[0].rebind_localhost='1'
- dhcp.@dnsmasq[0].local='/lan/'
- dhcp.@dnsmasq[0].domain='lan'
- dhcp.@dnsmasq[0].expandhosts='1'
- dhcp.@dnsmasq[0].nonegcache='0'
- dhcp.@dnsmasq[0].authoritative='1'
- dhcp.@dnsmasq[0].readethers='1'
- dhcp.@dnsmasq[0].leasefile='/tmp/dhcp.leases'
- dhcp.@dnsmasq[0].resolvfile='/tmp/resolv.conf.auto'
- dhcp.@dnsmasq[0].nonwildcard='1'
- dhcp.@dnsmasq[0].localservice='1'
- dhcp.lan=dhcp
- dhcp.lan.interface='lan'
- dhcp.lan.start='100'
- dhcp.lan.limit='150'
- dhcp.lan.leasetime='12h'
- dhcp.lan.ra='server'
- dhcp.lan.dhcpv6='server'
- dhcp.lan.ra_management='1'
- dhcp.wan=dhcp
- dhcp.wan.interface='wan'
- dhcp.wan.ignore='1'
- dhcp.odhcpd=odhcpd
- dhcp.odhcpd.maindhcp='0'
- dhcp.odhcpd.leasefile='/tmp/hosts/odhcpd'
- dhcp.odhcpd.leasetrigger='/usr/sbin/odhcpd-update'
- dhcp.odhcpd.loglevel='4'
- root@OpenWrt:~# uci show firewall
- firewall.@defaults[0]=defaults
- firewall.@defaults[0].input='ACCEPT'
- firewall.@defaults[0].output='ACCEPT'
- firewall.@defaults[0].synflood_protect='1'
- firewall.@defaults[0].forward='ACCEPT'
- firewall.@zone[0]=zone
- firewall.@zone[0].name='lan'
- firewall.@zone[0].input='ACCEPT'
- firewall.@zone[0].output='ACCEPT'
- firewall.@zone[0].forward='ACCEPT'
- firewall.@zone[0].network='lan'
- firewall.@zone[1]=zone
- firewall.@zone[1].name='wan'
- firewall.@zone[1].input='REJECT'
- firewall.@zone[1].output='ACCEPT'
- firewall.@zone[1].forward='REJECT'
- firewall.@zone[1].mtu_fix='1'
- firewall.@zone[1].masq='1'
- firewall.@zone[1].network='wan wan6 wanb wanb6 wanc wancvirtual wanc6'
- firewall.@zone[1].masq6=''\''1'\'''
- firewall.@forwarding[0]=forwarding
- firewall.@forwarding[0].src='lan'
- firewall.@forwarding[0].dest='wan'
- firewall.@rule[0]=rule
- firewall.@rule[0].name='Allow-DHCP-Renew'
- firewall.@rule[0].src='wan'
- firewall.@rule[0].proto='udp'
- firewall.@rule[0].dest_port='68'
- firewall.@rule[0].target='ACCEPT'
- firewall.@rule[0].family='ipv4'
- firewall.@rule[1]=rule
- firewall.@rule[1].name='Allow-Ping'
- firewall.@rule[1].src='wan'
- firewall.@rule[1].proto='icmp'
- firewall.@rule[1].icmp_type='echo-request'
- firewall.@rule[1].family='ipv4'
- firewall.@rule[1].target='ACCEPT'
- firewall.@rule[2]=rule
- firewall.@rule[2].name='Allow-IGMP'
- firewall.@rule[2].src='wan'
- firewall.@rule[2].proto='igmp'
- firewall.@rule[2].family='ipv4'
- firewall.@rule[2].target='ACCEPT'
- firewall.@rule[3]=rule
- firewall.@rule[3].name='Allow-DHCPv6'
- firewall.@rule[3].src='wan'
- firewall.@rule[3].proto='udp'
- firewall.@rule[3].src_ip='fc00::/6'
- firewall.@rule[3].dest_ip='fc00::/6'
- firewall.@rule[3].dest_port='546'
- firewall.@rule[3].family='ipv6'
- firewall.@rule[3].target='ACCEPT'
- firewall.@rule[4]=rule
- firewall.@rule[4].name='Allow-MLD'
- firewall.@rule[4].src='wan'
- firewall.@rule[4].proto='icmp'
- firewall.@rule[4].src_ip='fe80::/10'
- firewall.@rule[4].icmp_type='130/0' '131/0' '132/0' '143/0'
- firewall.@rule[4].family='ipv6'
- firewall.@rule[4].target='ACCEPT'
- firewall.@rule[5]=rule
- firewall.@rule[5].name='Allow-ICMPv6-Input'
- firewall.@rule[5].src='wan'
- firewall.@rule[5].proto='icmp'
- firewall.@rule[5].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type' 'router-solicitation' 'neighbour-solicitation' 'router-advertisement' 'neighbour-advertisement'
- firewall.@rule[5].limit='1000/sec'
- firewall.@rule[5].family='ipv6'
- firewall.@rule[5].target='ACCEPT'
- firewall.@rule[6]=rule
- firewall.@rule[6].name='Allow-ICMPv6-Forward'
- firewall.@rule[6].src='wan'
- firewall.@rule[6].dest='*'
- firewall.@rule[6].proto='icmp'
- firewall.@rule[6].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type'
- firewall.@rule[6].limit='1000/sec'
- firewall.@rule[6].family='ipv6'
- firewall.@rule[6].target='ACCEPT'
- firewall.@rule[6].enabled=''\''0'\'''
- firewall.@rule[7]=rule
- firewall.@rule[7].name='Allow-IPSec-ESP'
- firewall.@rule[7].src='wan'
- firewall.@rule[7].dest='lan'
- firewall.@rule[7].proto='esp'
- firewall.@rule[7].target='ACCEPT'
- firewall.@rule[8]=rule
- firewall.@rule[8].name='Allow-ISAKMP'
- firewall.@rule[8].src='wan'
- firewall.@rule[8].dest='lan'
- firewall.@rule[8].dest_port='500'
- firewall.@rule[8].proto='udp'
- firewall.@rule[8].target='ACCEPT'
- firewall.@include[0]=include
- firewall.@include[0].path='/etc/firewall.user'
- firewall.@forwarding[1]=forwarding
- firewall.@forwarding[1].dest='lan'
- firewall.@forwarding[1].src='wan'
- firewall.@redirect[0]=redirect
- firewall.@redirect[0].dest_port='21'
- firewall.@redirect[0].src='wan'
- firewall.@redirect[0].name='Linphone'
- firewall.@redirect[0].src_dport='21'
- firewall.@redirect[0].target='DNAT'
- firewall.@redirect[0].dest_ip='192.168.0.187'
- firewall.@redirect[0].dest='lan'
- firewall.@redirect[0].proto='udp'
- firewall.@redirect[0].src_ip='192.168.4.1'
- firewall.@redirect[0].src_mac='B4:6E:08:93:57:C2'
- root@OpenWrt:~# \
- > ip address show
- 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
- link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
- inet 127.0.0.1/8 scope host lo
- valid_lft forever preferred_lft forever
- inet6 ::1/128 scope host
- valid_lft forever preferred_lft forever
- 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 1000
- link/ether 08:02:8e:e6:43:e8 brd ff:ff:ff:ff:ff:ff
- inet6 fe80::a02:8eff:fee6:43e8/64 scope link
- valid_lft forever preferred_lft forever
- 5: br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
- link/ether 08:02:8e:e6:43:e8 brd ff:ff:ff:ff:ff:ff
- inet 192.168.0.1/24 brd 192.168.0.255 scope global br-lan
- valid_lft forever preferred_lft forever
- inet6 2001:4490:4409:5010::1/64 scope global dynamic noprefixroute
- valid_lft 82985sec preferred_lft 82985sec
- inet6 2001:4490:4409:4ea6::1/64 scope global dynamic noprefixroute
- valid_lft 39783sec preferred_lft 39783sec
- inet6 dd4e:2271:c462::1/60 scope global noprefixroute
- valid_lft forever preferred_lft forever
- inet6 fe80::a02:8eff:fee6:43e8/64 scope link
- valid_lft forever preferred_lft forever
- 6: eth0.1@eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-lan state UP group default qlen 1000
- link/ether 08:02:8e:e6:43:e8 brd ff:ff:ff:ff:ff:ff
- 7: eth0.2@eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
- link/ether 08:02:8e:e6:43:e9 brd ff:ff:ff:ff:ff:ff
- inet 192.168.29.13/24 brd 192.168.29.255 scope global eth0.2
- valid_lft forever preferred_lft forever
- inet6 2405:201:300f:d4:a02:8eff:fee6:43e9/64 scope global dynamic noprefixroute
- valid_lft 3593sec preferred_lft 3593sec
- inet6 fe80::a02:8eff:fee6:43e9/64 scope link
- valid_lft forever preferred_lft forever
- 8: eth0.3@eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
- link/ether 08:02:8e:e6:43:e7 brd ff:ff:ff:ff:ff:ff
- inet 192.168.4.4/24 brd 192.168.4.255 scope global eth0.3
- valid_lft forever preferred_lft forever
- inet6 fdb4:6e08:9357:c200:a02:8eff:fee6:43e7/64 scope global dynamic noprefixroute
- valid_lft 6742sec preferred_lft 3142sec
- inet6 fe80::a02:8eff:fee6:43e7/64 scope link
- valid_lft forever preferred_lft forever
- 9: eth0.4@eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1492 qdisc noqueue state UP group default qlen 1000
- link/ether 7c:a9:6b:37:28:2e brd ff:ff:ff:ff:ff:ff
- inet 192.168.100.2/24 brd 192.168.100.255 scope global eth0.4
- valid_lft forever preferred_lft forever
- inet 192.168.100.4/24 brd 192.168.100.255 scope global secondary eth0.4
- valid_lft forever preferred_lft forever
- inet6 2001:4490:4409:5010:7ea9:6bff:fe37:282e/64 scope global dynamic noprefixroute
- valid_lft 85851sec preferred_lft 85851sec
- inet6 fd8c:fd18:2c36:c100:7ea9:6bff:fe37:282e/64 scope global dynamic noprefixroute
- valid_lft 6651sec preferred_lft 3051sec
- inet6 2001:4490:4409:4ea6::1/128 scope global dynamic noprefixroute
- valid_lft 39783sec preferred_lft 39783sec
- inet6 fe80::7ea9:6bff:fe37:282e/64 scope link
- valid_lft forever preferred_lft forever
- 10: wlan0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-lan state UP group default qlen 1000
- link/ether 08:02:8e:e6:43:e8 brd ff:ff:ff:ff:ff:ff
- inet6 fe80::a02:8eff:fee6:43e8/64 scope link
- valid_lft forever preferred_lft forever
- 11: wlan1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-lan state UP group default qlen 1000
- link/ether 08:02:8e:e6:43:ec brd ff:ff:ff:ff:ff:ff
- inet6 fe80::a02:8eff:fee6:43ec/64 scope link
- valid_lft forever preferred_lft forever
- root@OpenWrt:~# ip route show table all
- default via 192.168.29.1 dev eth0.2 table 1 metric 10
- 192.168.0.0/24 dev br-lan table 1 proto kernel scope link src 192.168.0.1
- 192.168.4.0/24 dev eth0.3 table 1 proto static scope link metric 20
- 192.168.29.0/24 dev eth0.2 table 1 proto static scope link metric 10
- 192.168.100.0/24 dev eth0.4 table 1 proto static scope link metric 30
- 192.168.100.0/24 dev eth0.4 table 1 proto static scope link metric 35
- default via 192.168.4.1 dev eth0.3 table 3 metric 20
- 192.168.0.0/24 dev br-lan table 3 proto kernel scope link src 192.168.0.1
- 192.168.4.0/24 dev eth0.3 table 3 proto static scope link metric 20
- 192.168.29.0/24 dev eth0.2 table 3 proto static scope link metric 10
- 192.168.100.0/24 dev eth0.4 table 3 proto static scope link metric 30
- 192.168.100.0/24 dev eth0.4 table 3 proto static scope link metric 35
- default via 192.168.100.1 dev eth0.4 table 5 metric 30
- 192.168.0.0/24 dev br-lan table 5 proto kernel scope link src 192.168.0.1
- 192.168.4.0/24 dev eth0.3 table 5 proto static scope link metric 20
- 192.168.29.0/24 dev eth0.2 table 5 proto static scope link metric 10
- 192.168.100.0/24 dev eth0.4 table 5 proto static scope link metric 30
- 192.168.100.0/24 dev eth0.4 table 5 proto static scope link metric 35
- default via 192.168.29.1 dev eth0.2 proto static src 192.168.29.13 metric 10
- default via 192.168.4.1 dev eth0.3 proto static metric 20
- default via 192.168.100.1 dev eth0.4 proto static metric 30
- default via 192.168.100.1 dev eth0.4 proto static metric 35
- 192.168.0.0/24 dev br-lan proto kernel scope link src 192.168.0.1
- 192.168.4.0/24 dev eth0.3 proto static scope link metric 20
- 192.168.29.0/24 dev eth0.2 proto static scope link metric 10
- 192.168.100.0/24 dev eth0.4 proto static scope link metric 30
- 192.168.100.0/24 dev eth0.4 proto static scope link metric 35
- broadcast 127.0.0.0 dev lo table local proto kernel scope link src 127.0.0.1
- local 127.0.0.0/8 dev lo table local proto kernel scope host src 127.0.0.1
- local 127.0.0.1 dev lo table local proto kernel scope host src 127.0.0.1
- broadcast 127.255.255.255 dev lo table local proto kernel scope link src 127.0.0.1
- broadcast 192.168.0.0 dev br-lan table local proto kernel scope link src 192.168.0.1
- local 192.168.0.1 dev br-lan table local proto kernel scope host src 192.168.0.1
- broadcast 192.168.0.255 dev br-lan table local proto kernel scope link src 192.168.0.1
- broadcast 192.168.4.0 dev eth0.3 table local proto kernel scope link src 192.168.4.4
- local 192.168.4.4 dev eth0.3 table local proto kernel scope host src 192.168.4.4
- broadcast 192.168.4.255 dev eth0.3 table local proto kernel scope link src 192.168.4.4
- broadcast 192.168.29.0 dev eth0.2 table local proto kernel scope link src 192.168.29.13
- local 192.168.29.13 dev eth0.2 table local proto kernel scope host src 192.168.29.13
- broadcast 192.168.29.255 dev eth0.2 table local proto kernel scope link src 192.168.29.13
- broadcast 192.168.100.0 dev eth0.4 table local proto kernel scope link src 192.168.100.2
- local 192.168.100.2 dev eth0.4 table local proto kernel scope host src 192.168.100.2
- local 192.168.100.4 dev eth0.4 table local proto kernel scope host src 192.168.100.2
- broadcast 192.168.100.255 dev eth0.4 table local proto kernel scope link src 192.168.100.2
- 2001:4490:4409:4ea6::/64 dev eth0.4 table 2 proto static metric 256 pref medium
- 2001:4490:4409:4ea6::/64 dev br-lan table 2 proto static metric 1024 pref medium
- 2405:201:300f:d4::/64 dev eth0.2 table 2 proto static metric 256 pref medium
- dd4e:2271:c462::/64 dev br-lan table 2 proto static metric 1024 pref medium
- fd8c:fd18:2c36:c100::/64 dev eth0.4 table 2 proto static metric 256 pref medium
- fdb4:6e08:9357:c200::/64 dev eth0.3 table 2 proto static metric 256 pref medium
- default dev eth0.2 table 2 metric 10 pref medium
- 2001:4490:4409:4ea6::/64 dev eth0.4 table 4 proto static metric 256 pref medium
- 2001:4490:4409:4ea6::/64 dev br-lan table 4 proto static metric 1024 pref medium
- 2405:201:300f:d4::/64 dev eth0.2 table 4 proto static metric 256 pref medium
- dd4e:2271:c462::/64 dev br-lan table 4 proto static metric 1024 pref medium
- fd8c:fd18:2c36:c100::/64 dev eth0.4 table 4 proto static metric 256 pref medium
- fdb4:6e08:9357:c200::/64 dev eth0.3 table 4 proto static metric 256 pref medium
- default via fe80::1 dev eth0.3 table 4 metric 20 pref medium
- 2001:4490:4409:4ea6::/64 dev eth0.4 table 6 proto static metric 256 pref medium
- 2001:4490:4409:4ea6::/64 dev br-lan table 6 proto static metric 1024 pref medium
- 2405:201:300f:d4::/64 dev eth0.2 table 6 proto static metric 256 pref medium
- dd4e:2271:c462::/64 dev br-lan table 6 proto static metric 1024 pref medium
- fd8c:fd18:2c36:c100::/64 dev eth0.4 table 6 proto static metric 256 pref medium
- fdb4:6e08:9357:c200::/64 dev eth0.3 table 6 proto static metric 256 pref medium
- default via fe80::1 dev eth0.4 table 6 metric 30 pref medium
- default from 2001:4490:4409:4ea6::1 via fe80::1 dev eth0.4 proto static metric 512 pref medium
- default from 2001:4490:4409:5010::/64 via fe80::1 dev eth0.4 proto static metric 512 pref medium
- default from 2405:201:300f:d4::/64 via fe80::6a14:1ff:fe58:9f8b dev eth0.2 proto static metric 384 pref medium
- default from fd8c:fd18:2c36:c100::/64 via fe80::1 dev eth0.4 proto static metric 512 pref medium
- default from fdb4:6e08:9357:c200::/64 via fe80::1 dev eth0.3 proto static metric 512 pref medium
- 2001:4490:4409:4ea6::/64 dev eth0.4 proto static metric 256 pref medium
- 2001:4490:4409:4ea6::/64 dev br-lan proto static metric 1024 pref medium
- unreachable 2001:4490:4409:4ea6::/64 dev lo proto static metric 2147483647 error 4294967148 pref medium
- 2001:4490:4409:4fe4::/64 dev eth0.4 proto static metric 256 pref medium
- 2001:4490:4409:5010::/64 dev eth0.4 proto static metric 256 pref medium
- 2001:4490:4409:5010::/64 dev br-lan proto static metric 1024 pref medium
- unreachable 2001:4490:4409:5010::/64 dev lo proto static metric 2147483647 error 4294967148 pref medium
- 2405:201:300f:d4::/64 dev eth0.2 proto static metric 256 pref medium
- dd4e:2271:c462::/64 dev br-lan proto static metric 1024 pref medium
- unreachable dd4e:2271:c462::/48 dev lo proto static metric 2147483647 error 4294967148 pref medium
- fd8c:fd18:2c36:c100::/64 dev eth0.4 proto static metric 256 pref medium
- fdb4:6e08:9357:c200::/64 dev eth0.3 proto static metric 256 pref medium
- fe80::/64 dev eth0 proto kernel metric 256 pref medium
- fe80::/64 dev eth0.2 proto kernel metric 256 pref medium
- fe80::/64 dev eth0.3 proto kernel metric 256 pref medium
- fe80::/64 dev eth0.4 proto kernel metric 256 pref medium
- fe80::/64 dev br-lan proto kernel metric 256 pref medium
- fe80::/64 dev wlan0 proto kernel metric 256 pref medium
- fe80::/64 dev wlan1 proto kernel metric 256 pref medium
- local ::1 dev lo table local proto kernel metric 0 pref medium
- anycast 2001:4490:4409:4ea6:: dev br-lan table local proto kernel metric 0 pref medium
- local 2001:4490:4409:4ea6::1 dev eth0.4 table local proto kernel metric 0 pref medium
- local 2001:4490:4409:4ea6::1 dev br-lan table local proto kernel metric 0 pref medium
- anycast 2001:4490:4409:5010:: dev eth0.4 table local proto kernel metric 0 pref medium
- anycast 2001:4490:4409:5010:: dev br-lan table local proto kernel metric 0 pref medium
- local 2001:4490:4409:5010::1 dev br-lan table local proto kernel metric 0 pref medium
- local 2001:4490:4409:5010:7ea9:6bff:fe37:282e dev eth0.4 table local proto kernel metric 0 pref medium
- anycast 2405:201:300f:d4:: dev eth0.2 table local proto kernel metric 0 pref medium
- local 2405:201:300f:d4:a02:8eff:fee6:43e9 dev eth0.2 table local proto kernel metric 0 pref medium
- anycast dd4e:2271:c462:: dev br-lan table local proto kernel metric 0 pref medium
- local dd4e:2271:c462::1 dev br-lan table local proto kernel metric 0 pref medium
- anycast fd8c:fd18:2c36:c100:: dev eth0.4 table local proto kernel metric 0 pref medium
- local fd8c:fd18:2c36:c100:7ea9:6bff:fe37:282e dev eth0.4 table local proto kernel metric 0 pref medium
- anycast fdb4:6e08:9357:c200:: dev eth0.3 table local proto kernel metric 0 pref medium
- local fdb4:6e08:9357:c200:a02:8eff:fee6:43e7 dev eth0.3 table local proto kernel metric 0 pref medium
- anycast fe80:: dev eth0 table local proto kernel metric 0 pref medium
- anycast fe80:: dev eth0.2 table local proto kernel metric 0 pref medium
- anycast fe80:: dev eth0.4 table local proto kernel metric 0 pref medium
- anycast fe80:: dev eth0.3 table local proto kernel metric 0 pref medium
- anycast fe80:: dev br-lan table local proto kernel metric 0 pref medium
- anycast fe80:: dev wlan0 table local proto kernel metric 0 pref medium
- anycast fe80:: dev wlan1 table local proto kernel metric 0 pref medium
- local fe80::a02:8eff:fee6:43e7 dev eth0.3 table local proto kernel metric 0 pref medium
- local fe80::a02:8eff:fee6:43e8 dev eth0 table local proto kernel metric 0 pref medium
- local fe80::a02:8eff:fee6:43e8 dev br-lan table local proto kernel metric 0 pref medium
- local fe80::a02:8eff:fee6:43e8 dev wlan0 table local proto kernel metric 0 pref medium
- local fe80::a02:8eff:fee6:43e9 dev eth0.2 table local proto kernel metric 0 pref medium
- local fe80::a02:8eff:fee6:43ec dev wlan1 table local proto kernel metric 0 pref medium
- local fe80::7ea9:6bff:fe37:282e dev eth0.4 table local proto kernel metric 0 pref medium
- ff00::/8 dev eth0 table local metric 256 pref medium
- ff00::/8 dev br-lan table local metric 256 pref medium
- ff00::/8 dev eth0.2 table local metric 256 pref medium
- ff00::/8 dev eth0.3 table local metric 256 pref medium
- ff00::/8 dev eth0.4 table local metric 256 pref medium
- ff00::/8 dev wlan0 table local metric 256 pref medium
- ff00::/8 dev wlan1 table local metric 256 pref medium
- root@OpenWrt:~# ip -6 rule show
- 0: from all lookup local
- 1002: from all iif eth0.2 lookup 2
- 1004: from all iif eth0.3 lookup 4
- 1006: from all iif eth0.4 lookup 6
- 2002: from all fwmark 0x200/0x3f00 lookup 2
- 2004: from all fwmark 0x400/0x3f00 lookup 4
- 2006: from all fwmark 0x600/0x3f00 lookup 6
- 2061: from all fwmark 0x3d00/0x3f00 blackhole
- 2062: from all fwmark 0x3e00/0x3f00 unreachable
- 32766: from all lookup main
- 4200000000: from 2001:4490:4409:4ea6::1/64 iif br-lan unreachable
- 4200000000: from 2001:4490:4409:5010::1/64 iif br-lan unreachable
- 4200000001: from all iif lo failed_policy
- 4200000005: from all iif br-lan failed_policy
- 4200000007: from all iif eth0.2 failed_policy
- 4200000007: from all iif eth0.2 failed_policy
- 4200000008: from all iif eth0.3 failed_policy
- 4200000008: from all iif eth0.3 failed_policy
- 4200000009: from all iif eth0.4 failed_policy
- 4200000009: from all iif eth0.4 failed_policy
- 4200000009: from all iif eth0.4 failed_policy
- root@OpenWrt:~# ip6tables-save -c
- # Generated by ip6tables-save v1.8.3 on Thu May 13 02:29:22 2021
- *nat
- :PREROUTING ACCEPT [70623:7909779]
- :INPUT ACCEPT [18475:1631107]
- :OUTPUT ACCEPT [67052:6482195]
- :POSTROUTING ACCEPT [109855:10728365]
- COMMIT
- # Completed on Thu May 13 02:29:22 2021
- # Generated by ip6tables-save v1.8.3 on Thu May 13 02:29:22 2021
- *mangle
- :PREROUTING ACCEPT [14373:2225902]
- :INPUT ACCEPT [10568:1235553]
- :FORWARD ACCEPT [2893:779299]
- :OUTPUT ACCEPT [20269:2365271]
- :POSTROUTING ACCEPT [23162:3144570]
- :mwan3_connected - [0:0]
- :mwan3_hook - [0:0]
- :mwan3_iface_in_wan6 - [0:0]
- :mwan3_iface_in_wanb6 - [0:0]
- :mwan3_iface_in_wanc6 - [0:0]
- :mwan3_ifaces_in - [0:0]
- :mwan3_policy_balanced - [0:0]
- :mwan3_policy_wan_only - [0:0]
- :mwan3_policy_wan_wanb - [0:0]
- :mwan3_policy_wanb_only - [0:0]
- :mwan3_policy_wanb_wan - [0:0]
- :mwan3_rule_https - [0:0]
- :mwan3_rules - [0:0]
- [230920:27418384] -A PREROUTING -j mwan3_hook
- [2319:185092] -A FORWARD -o eth0.2 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone wan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A FORWARD -i eth0.2 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone wan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A FORWARD -o eth0.3 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone wan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A FORWARD -i eth0.3 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone wan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A FORWARD -o eth0.4 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone wan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A FORWARD -i eth0.4 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone wan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [292633:30410939] -A OUTPUT -j mwan3_hook
- [132679:16243364] -A mwan3_connected -m set --match-set mwan3_connected dst -j MARK --set-xmark 0x3f00/0x3f00
- [69:3784] -A mwan3_hook -p ipv6-icmp -m icmp6 --icmpv6-type 133 -j RETURN
- [3003:391168] -A mwan3_hook -p ipv6-icmp -m icmp6 --icmpv6-type 134 -j RETURN
- [175113:12605800] -A mwan3_hook -p ipv6-icmp -m icmp6 --icmpv6-type 135 -j RETURN
- [25510:1644312] -A mwan3_hook -p ipv6-icmp -m icmp6 --icmpv6-type 136 -j RETURN
- [3:504] -A mwan3_hook -p ipv6-icmp -m icmp6 --icmpv6-type 137 -j RETURN
- [31810:3308240] -A mwan3_hook -p ipv6-icmp -m set --match-set mwan3_source_v6 src -m icmp6 --icmpv6-type 128 -j RETURN
- [288045:39875515] -A mwan3_hook -j CONNMARK --restore-mark --nfmask 0x3f00 --ctmask 0x3f00
- [136235:14181473] -A mwan3_hook -m mark --mark 0x0/0x3f00 -j mwan3_ifaces_in
- [100412:10093535] -A mwan3_hook -m mark --mark 0x0/0x3f00 -j mwan3_connected
- [53028:5888077] -A mwan3_hook -m mark --mark 0x0/0x3f00 -j mwan3_rules
- [288045:39875515] -A mwan3_hook -j CONNMARK --save-mark --nfmask 0x3f00 --ctmask 0x3f00
- [171875:23595506] -A mwan3_hook -m mark ! --mark 0x3f00/0x3f00 -j mwan3_connected
- [2340:178065] -A mwan3_iface_in_wan6 -i eth0.2 -m set --match-set mwan3_connected_v6 src -m mark --mark 0x0/0x3f00 -m comment --comment default -j MARK --set-xmark 0x3f00/0x3f00
- [18162:1888848] -A mwan3_iface_in_wan6 -i eth0.2 -m mark --mark 0x0/0x3f00 -m comment --comment wan6 -j MARK --set-xmark 0x200/0x3f00
- [0:0] -A mwan3_iface_in_wanb6 -i eth0.3 -m set --match-set mwan3_connected_v6 src -m mark --mark 0x0/0x3f00 -m comment --comment default -j MARK --set-xmark 0x3f00/0x3f00
- [0:0] -A mwan3_iface_in_wanb6 -i eth0.3 -m mark --mark 0x0/0x3f00 -m comment --comment wanb6 -j MARK --set-xmark 0x400/0x3f00
- [5935:1033356] -A mwan3_iface_in_wanc6 -i eth0.4 -m set --match-set mwan3_connected_v6 src -m mark --mark 0x0/0x3f00 -m comment --comment default -j MARK --set-xmark 0x3f00/0x3f00
- [9304:969494] -A mwan3_iface_in_wanc6 -i eth0.4 -m mark --mark 0x0/0x3f00 -m comment --comment wanc6 -j MARK --set-xmark 0x600/0x3f00
- [136217:14179579] -A mwan3_ifaces_in -m mark --mark 0x0/0x3f00 -j mwan3_iface_in_wanb6
- [134849:14032759] -A mwan3_ifaces_in -m mark --mark 0x0/0x3f00 -j mwan3_iface_in_wanc6
- [118997:11974327] -A mwan3_ifaces_in -m mark --mark 0x0/0x3f00 -j mwan3_iface_in_wan6
- [13582:1563236] -A mwan3_policy_balanced -m mark --mark 0x0/0x3f00 -m comment --comment "wan6 3 3" -j MARK --set-xmark 0x200/0x3f00
- [0:0] -A mwan3_policy_wan_only -m mark --mark 0x0/0x3f00 -m comment --comment "wan6 3 3" -j MARK --set-xmark 0x200/0x3f00
- [0:0] -A mwan3_policy_wan_wanb -m mark --mark 0x0/0x3f00 -m comment --comment "wan6 3 3" -j MARK --set-xmark 0x200/0x3f00
- [0:0] -A mwan3_policy_wanb_only -o eth0.3 -m mark --mark 0x0/0x3f00 -m comment --comment "out wanb6 eth0.3" -j MARK --set-xmark 0x3f00/0x3f00
- [0:0] -A mwan3_policy_wanb_only -m mark --mark 0x0/0x3f00 -m comment --comment unreachable -j MARK --set-xmark 0x3e00/0x3f00
- [0:0] -A mwan3_policy_wanb_wan -m mark --mark 0x0/0x3f00 -m comment --comment "wan6 3 3" -j MARK --set-xmark 0x200/0x3f00
- [2271:181500] -A mwan3_rule_https -m mark --mark 0x0/0x3f00 -j mwan3_policy_balanced
- [2271:181500] -A mwan3_rule_https -m mark ! --mark 0xfc00/0xfc00 -j SET --del-set mwan3_sticky_https src,src
- [2271:181500] -A mwan3_rule_https -m mark ! --mark 0xfc00/0xfc00 -j SET --add-set mwan3_sticky_https src,src
- [2271:181500] -A mwan3_rules -p tcp -m multiport --dports 443 -m mark --mark 0x0/0x3f00 -j mwan3_rule_https
- [11310:1381640] -A mwan3_rules -m mark --mark 0x0/0x3f00 -j mwan3_policy_balanced
- COMMIT
- # Completed on Thu May 13 02:29:22 2021
- # Generated by ip6tables-save v1.8.3 on Thu May 13 02:29:22 2021
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- :forwarding_lan_rule - [0:0]
- :forwarding_rule - [0:0]
- :forwarding_wan_rule - [0:0]
- :input_lan_rule - [0:0]
- :input_rule - [0:0]
- :input_wan_rule - [0:0]
- :output_lan_rule - [0:0]
- :output_rule - [0:0]
- :output_wan_rule - [0:0]
- :reject - [0:0]
- :syn_flood - [0:0]
- :zone_lan_dest_ACCEPT - [0:0]
- :zone_lan_forward - [0:0]
- :zone_lan_input - [0:0]
- :zone_lan_output - [0:0]
- :zone_lan_src_ACCEPT - [0:0]
- :zone_wan_dest_ACCEPT - [0:0]
- :zone_wan_dest_REJECT - [0:0]
- :zone_wan_forward - [0:0]
- :zone_wan_input - [0:0]
- :zone_wan_output - [0:0]
- :zone_wan_src_REJECT - [0:0]
- [338:46904] -A INPUT -i lo -m comment --comment "!fw3" -j ACCEPT
- [10230:1188649] -A INPUT -m comment --comment "!fw3: Custom input rule chain" -j input_rule
- [4232:706261] -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
- [2:152] -A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m comment --comment "!fw3" -j syn_flood
- [4155:342152] -A INPUT -i br-lan -m comment --comment "!fw3" -j zone_lan_input
- [604:51372] -A INPUT -i eth0.2 -m comment --comment "!fw3" -j zone_wan_input
- [93:6480] -A INPUT -i eth0.3 -m comment --comment "!fw3" -j zone_wan_input
- [1146:82384] -A INPUT -i eth0.4 -m comment --comment "!fw3" -j zone_wan_input
- [2893:779299] -A FORWARD -m comment --comment "!fw3: Custom forwarding rule chain" -j forwarding_rule
- [0:0] -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
- [2893:779299] -A FORWARD -i br-lan -m comment --comment "!fw3" -j zone_lan_forward
- [0:0] -A FORWARD -i eth0.2 -m comment --comment "!fw3" -j zone_wan_forward
- [0:0] -A FORWARD -i eth0.3 -m comment --comment "!fw3" -j zone_wan_forward
- [0:0] -A FORWARD -i eth0.4 -m comment --comment "!fw3" -j zone_wan_forward
- [338:46904] -A OUTPUT -o lo -m comment --comment "!fw3" -j ACCEPT
- [19931:2318367] -A OUTPUT -m comment --comment "!fw3: Custom output rule chain" -j output_rule
- [5792:1179683] -A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
- [1167:82940] -A OUTPUT -o br-lan -m comment --comment "!fw3" -j zone_lan_output
- [6741:536255] -A OUTPUT -o eth0.2 -m comment --comment "!fw3" -j zone_wan_output
- [2611:229931] -A OUTPUT -o eth0.3 -m comment --comment "!fw3" -j zone_wan_output
- [3620:289558] -A OUTPUT -o eth0.4 -m comment --comment "!fw3" -j zone_wan_output
- [0:0] -A reject -p tcp -m comment --comment "!fw3" -j REJECT --reject-with tcp-reset
- [0:0] -A reject -m comment --comment "!fw3" -j REJECT --reject-with icmp6-port-unreachable
- [2:152] -A syn_flood -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 25/sec --limit-burst 50 -m comment --comment "!fw3" -j RETURN
- [0:0] -A syn_flood -m comment --comment "!fw3" -j DROP
- [1167:82940] -A zone_lan_dest_ACCEPT -o br-lan -m comment --comment "!fw3" -j ACCEPT
- [2893:779299] -A zone_lan_forward -m comment --comment "!fw3: Custom lan forwarding rule chain" -j forwarding_lan_rule
- [2893:779299] -A zone_lan_forward -m comment --comment "!fw3: Zone lan to wan forwarding policy" -j zone_wan_dest_ACCEPT
- [0:0] -A zone_lan_forward -m comment --comment "!fw3" -j zone_lan_dest_ACCEPT
- [4155:342152] -A zone_lan_input -m comment --comment "!fw3: Custom lan input rule chain" -j input_lan_rule
- [4155:342152] -A zone_lan_input -m comment --comment "!fw3" -j zone_lan_src_ACCEPT
- [1167:82940] -A zone_lan_output -m comment --comment "!fw3: Custom lan output rule chain" -j output_lan_rule
- [1167:82940] -A zone_lan_output -m comment --comment "!fw3" -j zone_lan_dest_ACCEPT
- [4155:342152] -A zone_lan_src_ACCEPT -i br-lan -m conntrack --ctstate NEW,UNTRACKED -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A zone_wan_dest_ACCEPT -o eth0.2 -m conntrack --ctstate INVALID -m comment --comment "!fw3: Prevent NAT leakage" -j DROP
- [9634:1315554] -A zone_wan_dest_ACCEPT -o eth0.2 -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A zone_wan_dest_ACCEPT -o eth0.3 -m conntrack --ctstate INVALID -m comment --comment "!fw3: Prevent NAT leakage" -j DROP
- [2611:229931] -A zone_wan_dest_ACCEPT -o eth0.3 -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A zone_wan_dest_ACCEPT -o eth0.4 -m conntrack --ctstate INVALID -m comment --comment "!fw3: Prevent NAT leakage" -j DROP
- [3620:289558] -A zone_wan_dest_ACCEPT -o eth0.4 -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A zone_wan_dest_REJECT -o eth0.2 -m comment --comment "!fw3" -j reject
- [0:0] -A zone_wan_dest_REJECT -o eth0.3 -m comment --comment "!fw3" -j reject
- [0:0] -A zone_wan_dest_REJECT -o eth0.4 -m comment --comment "!fw3" -j reject
- [0:0] -A zone_wan_forward -m comment --comment "!fw3: Custom wan forwarding rule chain" -j forwarding_wan_rule
- [0:0] -A zone_wan_forward -p esp -m comment --comment "!fw3: Allow-IPSec-ESP" -j zone_lan_dest_ACCEPT
- [0:0] -A zone_wan_forward -p udp -m udp --dport 500 -m comment --comment "!fw3: Allow-ISAKMP" -j zone_lan_dest_ACCEPT
- [0:0] -A zone_wan_forward -m comment --comment "!fw3: Zone wan to lan forwarding policy" -j zone_lan_dest_ACCEPT
- [0:0] -A zone_wan_forward -m comment --comment "!fw3" -j zone_wan_dest_REJECT
- [1843:140236] -A zone_wan_input -m comment --comment "!fw3: Custom wan input rule chain" -j input_wan_rule
- [0:0] -A zone_wan_input -s fc00::/6 -d fc00::/6 -p udp -m udp --dport 546 -m comment --comment "!fw3: Allow-DHCPv6" -j ACCEPT
- [155:11780] -A zone_wan_input -s fe80::/10 -p ipv6-icmp -m icmp6 --icmpv6-type 130/0 -m comment --comment "!fw3: Allow-MLD" -j ACCEPT
- [0:0] -A zone_wan_input -s fe80::/10 -p ipv6-icmp -m icmp6 --icmpv6-type 131/0 -m comment --comment "!fw3: Allow-MLD" -j ACCEPT
- [0:0] -A zone_wan_input -s fe80::/10 -p ipv6-icmp -m icmp6 --icmpv6-type 132/0 -m comment --comment "!fw3: Allow-MLD" -j ACCEPT
- [0:0] -A zone_wan_input -s fe80::/10 -p ipv6-icmp -m icmp6 --icmpv6-type 143/0 -m comment --comment "!fw3: Allow-MLD" -j ACCEPT
- [0:0] -A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 128 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
- [0:0] -A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 129 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
- [0:0] -A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 1 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
- [0:0] -A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 2 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
- [0:0] -A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 3 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
- [0:0] -A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 4/0 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
- [0:0] -A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 4/1 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
- [0:0] -A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 133 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
- [1185:85320] -A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 135 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
- [167:21632] -A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 134 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
- [336:21504] -A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 136 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
- [0:0] -A zone_wan_input -m comment --comment "!fw3" -j zone_wan_src_REJECT
- [12972:1055744] -A zone_wan_output -m comment --comment "!fw3: Custom wan output rule chain" -j output_wan_rule
- [12972:1055744] -A zone_wan_output -m comment --comment "!fw3" -j zone_wan_dest_ACCEPT
- [0:0] -A zone_wan_src_REJECT -i eth0.2 -m comment --comment "!fw3" -j reject
- [0:0] -A zone_wan_src_REJECT -i eth0.3 -m comment --comment "!fw3" -j reject
- [0:0] -A zone_wan_src_REJECT -i eth0.4 -m comment --comment "!fw3" -j reject
- COMMIT
- # Completed on Thu May 13 02:29:22 2021
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement