Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- network:
- config interface 'loopback'
- option ifname 'lo'
- option proto 'static'
- option ipaddr '127.0.0.1'
- option netmask '255.0.0.0'
- config globals 'globals'
- option ula_prefix 'fd9a:9147:4d5c::/48'
- config interface 'lan'
- option type 'bridge'
- option ifname 'eth1'
- option proto 'static'
- option netmask '255.255.255.0'
- option ip6assign '60'
- option ipaddr '10.0.0.1'
- config interface 'wan2'
- option _orig_ifname 'eth0'
- option _orig_bridge 'false'
- option proto 'pppoe'
- option username 'O2'
- option password 'O2'
- option ipv6 'auto'
- option ifname 'eth0.3'
- option metric '20'
- config interface 'wan6'
- option ifname 'eth0'
- option proto 'dhcpv6'
- config switch
- option name 'switch0'
- option reset '1'
- option enable_vlan '1'
- config switch_vlan
- option device 'switch0'
- option vlan '1'
- option vid '1'
- option ports '0 2 3 4'
- config switch_vlan
- option device 'switch0'
- option vlan '2'
- option ports '5 6'
- option vid '2'
- config interface 'wan'
- option ifname 'eth0'
- option _orig_ifname 'eth0'
- option _orig_bridge 'false'
- option proto 'dhcp'
- option metric '10'
- config switch_vlan
- option device 'switch0'
- option vlan '3'
- option vid '3'
- option ports '0t 1 6t'
- mwan:
- config rule 'o2_tv'
- option dest_ip 'o2tv.cz'
- option proto 'all'
- option sticky '0'
- option use_policy 'wan2_only'
- config rule 'pref_vdsl_mila'
- option proto 'all'
- option sticky '0'
- option use_policy 'wan2_only'
- option src_ip '10.0.0.11'
- config rule 'pref_vdsl_harrier'
- option proto 'all'
- option sticky '0'
- option use_policy 'wan2_only'
- option src_ip '10.0.0.10'
- config rule 'https'
- option sticky '1'
- option dest_port '443'
- option proto 'tcp'
- option use_policy 'wan_wan2'
- config rule 'youtube_cz'
- option dest_ip 'youtube.cz'
- option proto 'all'
- option sticky '0'
- option use_policy 'wan_only'
- config rule 'youtube_com'
- option dest_ip 'youtube.com'
- option proto 'all'
- option sticky '0'
- option use_policy 'wan_only'
- config rule 'stream_cz'
- option dest_ip 'stream.cz'
- option proto 'all'
- option sticky '0'
- option use_policy 'wan_only'
- config rule 'twitch_tv'
- option dest_ip 'twitch.tv'
- option proto 'all'
- option sticky '0'
- option use_policy 'wan_only'
- config rule 'default_rule'
- option dest_ip '0.0.0.0/0'
- option proto 'all'
- option sticky '0'
- option use_policy 'wan_wan2'
- config interface 'wan'
- option enabled '1'
- list track_ip '8.8.4.4'
- list track_ip '8.8.8.8'
- list track_ip '208.67.222.222'
- list track_ip '208.67.220.220'
- option reliability '2'
- option count '1'
- option timeout '2'
- option interval '5'
- option down '3'
- option up '8'
- config interface 'wan2'
- list track_ip '8.8.8.8'
- list track_ip '208.67.220.220'
- option reliability '1'
- option count '1'
- option timeout '2'
- option interval '5'
- option down '3'
- option up '8'
- option enabled '1'
- config member 'wan_m1_w3'
- option interface 'wan'
- option metric '1'
- option weight '3'
- config member 'wan_m2_w3'
- option interface 'wan'
- option metric '2'
- option weight '3'
- config member 'wan2_m1_w2'
- option interface 'wan2'
- option metric '1'
- option weight '2'
- config member 'wan2_m2_w2'
- option interface 'wan2'
- option metric '2'
- option weight '2'
- config policy 'wan_only'
- list use_member 'wan_m1_w3'
- config policy 'wan2_only'
- list use_member 'wan2_m1_w2'
- config policy 'balanced'
- list use_member 'wan_m1_w3'
- list use_member 'wan2_m1_w2'
- config policy 'wan_wan2'
- list use_member 'wan_m1_w3'
- list use_member 'wan2_m2_w2'
- config policy 'wan2_wan'
- list use_member 'wan_m2_w3'
- list use_member 'wan2_m1_w2'
- firewall:
- config defaults
- option syn_flood '1'
- option input 'ACCEPT'
- option output 'ACCEPT'
- option forward 'REJECT'
- config zone
- option name 'lan'
- option input 'ACCEPT'
- option output 'ACCEPT'
- option forward 'ACCEPT'
- option network 'lan'
- config zone
- option name 'wan'
- option input 'REJECT'
- option output 'ACCEPT'
- option forward 'REJECT'
- option masq '1'
- option mtu_fix '1'
- option network 'wan wan6 LTE wan2 test'
- config forwarding
- option src 'lan'
- option dest 'wan'
- config rule
- option name 'Allow-DHCP-Renew'
- option src 'wan'
- option proto 'udp'
- option dest_port '68'
- option target 'ACCEPT'
- option family 'ipv4'
- config rule
- option name 'Allow-Ping'
- option src 'wan'
- option proto 'icmp'
- option icmp_type 'echo-request'
- option family 'ipv4'
- option target 'ACCEPT'
- config rule
- option name 'Allow-IGMP'
- option src 'wan'
- option proto 'igmp'
- option family 'ipv4'
- option target 'ACCEPT'
- config rule
- option name 'Allow-DHCPv6'
- option src 'wan'
- option proto 'udp'
- option src_ip 'fc00::/6'
- option dest_ip 'fc00::/6'
- option dest_port '546'
- option family 'ipv6'
- option target 'ACCEPT'
- config rule
- option name 'Allow-MLD'
- option src 'wan'
- option proto 'icmp'
- option src_ip 'fe80::/10'
- list icmp_type '130/0'
- list icmp_type '131/0'
- list icmp_type '132/0'
- list icmp_type '143/0'
- option family 'ipv6'
- option target 'ACCEPT'
- config rule
- option name 'Allow-ICMPv6-Input'
- option src 'wan'
- option proto 'icmp'
- list icmp_type 'echo-request'
- list icmp_type 'echo-reply'
- list icmp_type 'destination-unreachable'
- list icmp_type 'packet-too-big'
- list icmp_type 'time-exceeded'
- list icmp_type 'bad-header'
- list icmp_type 'unknown-header-type'
- list icmp_type 'router-solicitation'
- list icmp_type 'neighbour-solicitation'
- list icmp_type 'router-advertisement'
- list icmp_type 'neighbour-advertisement'
- option limit '1000/sec'
- option family 'ipv6'
- option target 'ACCEPT'
- config rule
- option name 'Allow-ICMPv6-Forward'
- option src 'wan'
- option dest '*'
- option proto 'icmp'
- list icmp_type 'echo-request'
- list icmp_type 'echo-reply'
- list icmp_type 'destination-unreachable'
- list icmp_type 'packet-too-big'
- list icmp_type 'time-exceeded'
- list icmp_type 'bad-header'
- list icmp_type 'unknown-header-type'
- option limit '1000/sec'
- option family 'ipv6'
- option target 'ACCEPT'
- config rule
- option name 'Allow-IPSec-ESP'
- option src 'wan'
- option dest 'lan'
- option proto 'esp'
- option target 'ACCEPT'
- config rule
- option name 'Allow-ISAKMP'
- option src 'wan'
- option dest 'lan'
- option dest_port '500'
- option proto 'udp'
- option target 'ACCEPT'
- config include
- option path '/etc/firewall.user'
- config redirect
- option target 'DNAT'
- option src 'wan'
- option dest 'lan'
- option proto 'tcp udp'
- option src_dport '60899'
- option dest_ip '10.0.0.10'
- option dest_port '60899'
- option name '60899'
- routes:
- root@LEDE:~# ip route show
- default via 192.168.1.1 dev eth0 proto static src 192.168.1.100 metric 10
- default via 88.103.200.* dev pppoe-wan2 proto static metric 20
- 10.0.0.0/24 dev br-lan proto kernel scope link src 10.0.0.1
- 88.103.200.* dev pppoe-wan2 proto kernel scope link src 90.177.49.*
- 192.168.1.0/24 dev eth0 proto static scope link metric 10
- 192.168.1.1 dev eth0 proto static scope link src 192.168.1.100 metric 10
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement