Advertisement
Guest User

Untitled

a guest
May 11th, 2019
81
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.11 KB | None | 0 0
  1. root@turris:~# cat /etc/config/firewall
  2.  
  3. config defaults
  4. option syn_flood '1'
  5. option input 'ACCEPT'
  6. option output 'ACCEPT'
  7. option forward 'REJECT'
  8.  
  9. config zone
  10. option name 'lan'
  11. option input 'ACCEPT'
  12. option output 'ACCEPT'
  13. option forward 'ACCEPT'
  14. option network 'lan'
  15.  
  16. config zone
  17. option name 'wan'
  18. option input 'REJECT'
  19. option output 'ACCEPT'
  20. option forward 'REJECT'
  21. option masq '1'
  22. option mtu_fix '1'
  23. option network 'wan wan6'
  24.  
  25. config forwarding
  26. option src 'lan'
  27. option dest 'wan'
  28.  
  29. config rule
  30. option name 'Allow-DHCP-Renew'
  31. option src 'wan'
  32. option proto 'udp'
  33. option dest_port '68'
  34. option target 'ACCEPT'
  35. option family 'ipv4'
  36.  
  37. config rule
  38. option name 'Allow-Ping'
  39. option src 'wan'
  40. option proto 'icmp'
  41. option icmp_type 'echo-request'
  42. option family 'ipv4'
  43. option target 'ACCEPT'
  44.  
  45. config rule
  46. option name 'Allow-IGMP'
  47. option src 'wan'
  48. option proto 'igmp'
  49. option family 'ipv4'
  50. option target 'ACCEPT'
  51.  
  52. config rule
  53. option name 'Allow-DHCPv6'
  54. option src 'wan'
  55. option proto 'udp'
  56. option src_ip 'fe80::/10'
  57. option src_port '547'
  58. option dest_ip 'fe80::/10'
  59. option dest_port '546'
  60. option family 'ipv6'
  61. option target 'ACCEPT'
  62.  
  63. config rule
  64. option name 'Allow-MLD'
  65. option src 'wan'
  66. option proto 'icmp'
  67. option src_ip 'fe80::/10'
  68. list icmp_type '130/0'
  69. list icmp_type '131/0'
  70. list icmp_type '132/0'
  71. list icmp_type '143/0'
  72. option family 'ipv6'
  73. option target 'ACCEPT'
  74.  
  75. config rule
  76. option name 'Allow-ICMPv6-Input'
  77. option src 'wan'
  78. option proto 'icmp'
  79. list icmp_type 'echo-request'
  80. list icmp_type 'echo-reply'
  81. list icmp_type 'destination-unreachable'
  82. list icmp_type 'packet-too-big'
  83. list icmp_type 'time-exceeded'
  84. list icmp_type 'bad-header'
  85. list icmp_type 'unknown-header-type'
  86. list icmp_type 'router-solicitation'
  87. list icmp_type 'neighbour-solicitation'
  88. list icmp_type 'router-advertisement'
  89. list icmp_type 'neighbour-advertisement'
  90. option limit '1000/sec'
  91. option family 'ipv6'
  92. option target 'ACCEPT'
  93.  
  94. config rule
  95. option name 'Allow-ICMPv6-Forward'
  96. option src 'wan'
  97. option dest '*'
  98. option proto 'icmp'
  99. list icmp_type 'echo-request'
  100. list icmp_type 'echo-reply'
  101. list icmp_type 'destination-unreachable'
  102. list icmp_type 'packet-too-big'
  103. list icmp_type 'time-exceeded'
  104. list icmp_type 'bad-header'
  105. list icmp_type 'unknown-header-type'
  106. option limit '1000/sec'
  107. option family 'ipv6'
  108. option target 'ACCEPT'
  109.  
  110. config include
  111. option path '/etc/firewall.user'
  112.  
  113. config include
  114. option path '/usr/share/firewall/turris'
  115. option reload '1'
  116.  
  117. config include
  118. option path '/etc/firewall.d/with_reload/firewall.include.sh'
  119. option reload '1'
  120.  
  121. config include
  122. option path '/etc/firewall.d/without_reload/firewall.include.sh'
  123. option reload '0'
  124.  
  125. #config rule
  126. # option src 'wan'
  127. # option dest 'lan'
  128. # option proto 'esp'
  129. # option target 'ACCEPT'
  130.  
  131. #config rule
  132. # option src 'wan'
  133. # option dest 'lan'
  134. # option dest_port '500'
  135. # option proto 'udp'
  136. # option target 'ACCEPT'
  137.  
  138. config zone 'guest_turris'
  139. option name 'guest_turris'
  140. option input 'REJECT'
  141. option forward 'REJECT'
  142. option output 'ACCEPT'
  143. option enabled '1'
  144. list network 'guest_turris'
  145.  
  146. config forwarding 'guest_turris_forward_wan'
  147. option name 'guest to wan forward'
  148. option src 'guest_turris'
  149. option dest 'wan'
  150. option enabled '1'
  151.  
  152. config rule 'guest_turris_dns_rule'
  153. option name 'guest dns rule'
  154. option src 'guest_turris'
  155. option proto 'tcpudp'
  156. option dest_port '53'
  157. option target 'ACCEPT'
  158. option enabled '1'
  159.  
  160. config rule 'guest_turris_dhcp_rule'
  161. option name 'guest dhcp rule'
  162. option src 'guest_turris'
  163. option proto 'udp'
  164. option src_port '67-68'
  165. option dest_port '67-68'
  166. option target 'ACCEPT'
  167. option enabled '1'
  168.  
  169. config zone
  170. option input 'ACCEPT'
  171. option forward 'REJECT'
  172. option output 'ACCEPT'
  173. option name 'vpn_msq'
  174. option masq '1'
  175. option network 'vpn_msq'
  176.  
  177. config forwarding
  178. option dest 'vpn_msq'
  179. option src 'lan'
  180.  
  181. config zone
  182. option name 'vpn'
  183. option output 'ACCEPT'
  184. option network 'ipsec'
  185. option input 'ACCEPT'
  186. option mtu_fix '1'
  187. option forward 'ACCEPT'
  188.  
  189. config rule
  190. option src 'wan'
  191. option name 'IPSec ESP'
  192. option proto 'esp'
  193. option target 'ACCEPT'
  194.  
  195. config rule
  196. option src 'wan'
  197. option name 'IPSec IKE'
  198. option proto 'udp'
  199. option dest_port '500'
  200. option target 'ACCEPT'
  201.  
  202. config rule
  203. option src 'wan'
  204. option name 'IPSec NAT-T'
  205. option proto 'udp'
  206. option dest_port '4500'
  207. option target 'ACCEPT'
  208.  
  209. config rule
  210. option src 'wan'
  211. option name 'Auth Header'
  212. option proto 'ah'
  213. option target 'ACCEPT'
  214.  
  215. config forwarding
  216. option dest 'lan'
  217. option src 'vpn'
  218.  
  219. config forwarding
  220. option dest 'vpn_msq'
  221. option src 'vpn'
  222.  
  223. config forwarding
  224. option dest 'wan'
  225. option src 'vpn'
  226.  
  227. config forwarding
  228. option dest 'vpn'
  229. option src 'lan'
  230.  
  231. config include 'miniupnpd'
  232. option type 'script'
  233. option path '/usr/share/miniupnpd/firewall.include'
  234. option family 'any'
  235. option reload '1'
  236.  
  237. config redirect 'adblock_dns'
  238. option name 'Adblock DNS'
  239. option src 'lan'
  240. option proto 'tcp udp'
  241. option src_dport '53'
  242. option dest_port '53'
  243. option target 'DNAT'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement