Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- config 'defaults'
- option 'syn_flood' '1'
- option 'input' 'ACCEPT'
- option 'output' 'ACCEPT'
- option 'forward' 'REJECT'
- option 'drop_invalid' '1'
- config 'zone'
- option 'name' 'lan'
- option 'input' 'ACCEPT'
- option 'output' 'ACCEPT'
- option 'forward' 'REJECT'
- option 'network' 'lan'
- config 'zone'
- option 'name' 'dn42'
- option 'input' 'ACCEPT'
- option 'output' 'ACCEPT'
- option 'forward' 'ACCEPT'
- list 'masq_src' '192.168.19.0/24'
- option 'masq' '1'
- option 'network' 'dn42_siska dn42_crest'
- config 'rule'
- option 'name' 'Allow-DHCP-Renew'
- option 'src' 'wan'
- option 'proto' 'udp'
- option 'dest_port' '68'
- option 'target' 'ACCEPT'
- option 'family' 'ipv4'
- config 'rule'
- option 'name' 'Allow-Ping'
- option 'src' 'wan'
- option 'proto' 'icmp'
- option 'icmp_type' 'echo-request'
- option 'family' 'ipv4'
- option 'target' 'ACCEPT'
- config 'rule'
- option 'name' 'Allow-DHCPv6'
- option 'src' 'wan'
- option 'proto' 'udp'
- option 'src_ip' 'fe80::/10'
- option 'src_port' '547'
- option 'dest_ip' 'fe80::/10'
- option 'dest_port' '546'
- option 'family' 'ipv6'
- option 'target' 'ACCEPT'
- config 'rule'
- option 'name' 'Allow-ICMPv6-Input'
- option 'src' 'wan'
- option 'proto' 'icmp'
- list 'icmp_type' 'echo-request'
- list 'icmp_type' 'destination-unreachable'
- list 'icmp_type' 'packet-too-big'
- list 'icmp_type' 'time-exceeded'
- list 'icmp_type' 'bad-header'
- list 'icmp_type' 'unknown-header-type'
- list 'icmp_type' 'router-solicitation'
- list 'icmp_type' 'neighbour-solicitation'
- option 'limit' '1000/sec'
- option 'family' 'ipv6'
- option 'target' 'ACCEPT'
- config 'rule'
- option 'name' 'Allow-ICMPv6-Forward'
- option 'src' 'wan'
- option 'dest' '*'
- option 'proto' 'icmp'
- list 'icmp_type' 'echo-request'
- list 'icmp_type' 'destination-unreachable'
- list 'icmp_type' 'packet-too-big'
- list 'icmp_type' 'time-exceeded'
- list 'icmp_type' 'bad-header'
- list 'icmp_type' 'unknown-header-type'
- option 'limit' '1000/sec'
- option 'family' 'ipv6'
- option 'target' 'ACCEPT'
- config 'include'
- option 'path' '/etc/firewall.user'
- config 'rule'
- option 'target' 'ACCEPT'
- option '_name' 'OpenVPN'
- option 'src' 'wan'
- option 'proto' 'tcpudp'
- option 'dest_port' '1194'
- config 'rule'
- option 'target' 'ACCEPT'
- option '_name' 'BGP'
- option 'src' 'wan'
- option 'proto' 'tcp'
- option 'dest_ip' '172.23.192.1'
- option 'dest_port' '179'
- config 'rule'
- option 'target' 'ACCEPT'
- option '_name' 'BitTorrent'
- option 'src' 'wan'
- option 'proto' 'tcpudp'
- option 'dest_port' '51413'
- config 'rule'
- option 'target' 'ACCEPT'
- option '_name' 'IPerf'
- option 'src' 'wan'
- option 'proto' 'tcpudp'
- option 'dest_port' '5001'
- config 'zone'
- option 'name' 'lsd'
- option 'input' 'ACCEPT'
- option 'forward' 'REJECT'
- option 'output' 'ACCEPT'
- option 'network' 'lsd'
- config 'forwarding'
- option 'dest' 'dn42'
- option 'src' 'lan'
- config 'forwarding'
- option 'dest' 'dn42'
- option 'src' 'lsd'
- config 'forwarding'
- option 'dest' 'lsd'
- option 'src' 'lan'
- config 'forwarding'
- option 'dest' 'lan'
- option 'src' 'lsd'
- config 'forwarding'
- option 'dest' 'wan'
- option 'src' 'lan'
- config 'forwarding'
- option 'dest' 'wan'
- option 'src' 'lsd'
- config 'redirect'
- option 'target' 'DNAT'
- option 'src' 'wan'
- option 'dest' 'lan'
- option 'proto' 'tcp udp'
- option 'src_dport' '5060'
- option 'dest_ip' '192.168.19.2'
- option 'dest_port' '5060'
- option 'name' 'VoIP-SIP'
- config 'redirect'
- option 'target' 'DNAT'
- option 'src' 'wan'
- option 'dest' 'lan'
- option 'proto' 'tcp udp'
- option 'src_dport' '5004'
- option 'dest_ip' '192.168.19.2'
- option 'dest_port' '5004'
- option 'name' 'VoIP-RTP'
- config 'rule'
- option 'target' 'ACCEPT'
- option 'name' '6to4'
- option 'src' 'wan'
- option 'proto' '41'
- option '_name' '6in4-in'
- config 'zone'
- option 'name' 'wan'
- option 'input' 'ACCEPT'
- option 'forward' 'REJECT'
- option 'output' 'ACCEPT'
- option 'masq' '1'
- option 'network' 'he6 wan'
Add Comment
Please, Sign In to add comment