Advertisement
Guest User

Router B: Firewall

a guest
Sep 24th, 2018
100
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.98 KB | None | 0 0
  1. config rule 'cfg0c92bd'
  2. option dest_ip 'fe80::/10'
  3. option target 'ACCEPT'
  4. option dest_port '546'
  5. option src_port '547'
  6. option name 'Allow-DHCPv6'
  7. option src_ip 'fe80::/10'
  8. option family 'ipv6'
  9. option proto 'udp'
  10. option src 'wan'
  11.  
  12. config forwarding 'cfg1aad58'
  13. option dest 'ninux'
  14. option src 'lan'
  15.  
  16. config forwarding 'cfg16ad58'
  17. option dest 'wan'
  18. option src 'lan'
  19.  
  20. config zone 'cfg04dc81'
  21. option network 'lan'
  22. option output 'ACCEPT'
  23. option name 'lan'
  24. option input 'ACCEPT'
  25. option forward 'ACCEPT'
  26.  
  27. config rule 'cfg0892bd'
  28. option dest_port '68'
  29. option name 'Allow-DHCP-Renew'
  30. option family 'ipv4'
  31. option target 'ACCEPT'
  32. option proto 'udp'
  33. option src 'wan'
  34.  
  35. config rule 'cfg0e92bd'
  36. option target 'ACCEPT'
  37. list icmp_type 'destination-unreachable'
  38. list icmp_type 'time-exceeded'
  39. list icmp_type 'bad-header'
  40. list icmp_type 'echo-reply'
  41. list icmp_type 'neighbour-solicitation'
  42. list icmp_type 'echo-request'
  43. list icmp_type 'neighbour-advertisement'
  44. list icmp_type 'packet-too-big'
  45. list icmp_type 'router-advertisement'
  46. list icmp_type 'unknown-header-type'
  47. list icmp_type 'router-solicitation'
  48. option name 'Allow-ICMPv6-Input'
  49. option limit '1000/sec'
  50. option family 'ipv6'
  51. option proto 'icmp'
  52. option src 'wan'
  53.  
  54. config forwarding 'cfg18ad58'
  55. option dest 'lan'
  56. option src 'ninux'
  57.  
  58. config zone 'cfg14dc81'
  59. option output 'ACCEPT'
  60. option name 'ninux'
  61. option input 'ACCEPT'
  62. option forward 'ACCEPT'
  63. option network 'ninux vpnbas Ant1 Ant2 Ant3 Ant4 ANT_1 ANT_2'
  64.  
  65. config zone 'cfg06dc81'
  66. option network 'wan wan6'
  67. option output 'ACCEPT'
  68. option masq '1'
  69. option name 'wan'
  70. option input 'ACCEPT'
  71. option forward 'REJECT'
  72. option mtu_fix '1'
  73.  
  74. config include 'cfg12af89'
  75. option path '/etc/firewall.user'
  76.  
  77. config rule 'cfg0a92bd'
  78. option icmp_type 'echo-request'
  79. option name 'Allow-Ping'
  80. option target 'ACCEPT'
  81. option family 'ipv4'
  82. option proto 'icmp'
  83. option src 'wan'
  84.  
  85. config defaults 'cfg02e63d'
  86. option syn_flood '1'
  87. option input 'ACCEPT'
  88. option forward 'ACCEPT'
  89. option output 'ACCEPT'
  90.  
  91. config rule 'cfg1092bd'
  92. option target 'ACCEPT'
  93. option family 'ipv6'
  94. list icmp_type 'destination-unreachable'
  95. list icmp_type 'echo-request'
  96. list icmp_type 'packet-too-big'
  97. list icmp_type 'unknown-header-type'
  98. list icmp_type 'time-exceeded'
  99. list icmp_type 'bad-header'
  100. list icmp_type 'echo-reply'
  101. option name 'Allow-ICMPv6-Forward'
  102. option limit '1000/sec'
  103. option dest '*'
  104. option proto 'icmp'
  105. option src 'wan'
  106.  
  107. config zone 'HOTSPOT_zone'
  108. option name 'HOTSPOT'
  109. option network 'HOTSPOT'
  110. option output 'ACCEPT'
  111. option input 'ACCEPT'
  112. option forward 'ACCEPT'
  113.  
  114. config rule 'HOTSPOT_rule_dhcp'
  115. option name 'Allow DHCP request'
  116. option src 'HOTSPOT'
  117. option src_port '68'
  118. option dest_port '67'
  119. option proto 'udp'
  120. option target 'ACCEPT'
  121.  
  122. config forwarding 'cfg12ad58'
  123. option dest 'wan'
  124. option src 'HOTSPOT'
  125.  
  126. config forwarding 'cfg11ad58'
  127. option dest 'ninux'
  128. option src 'HOTSPOT'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement