Untitled diff

Created Diff never expires
1 removal
161 lines
1 addition
161 lines


config defaults
config defaults
option syn_flood '1'
option syn_flood '1'
option input 'ACCEPT'
option input 'ACCEPT'
option output 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
option forward 'REJECT'


config rule
config rule
option name 'Allow-DHCP-Renew'
option name 'Allow-DHCP-Renew'
option src 'wan'
option src 'wan'
option proto 'udp'
option proto 'udp'
option dest_port '68'
option dest_port '68'
option target 'ACCEPT'
option target 'ACCEPT'
option family 'ipv4'
option family 'ipv4'


config rule
config rule
option name 'Allow-Ping'
option name 'Allow-Ping'
option src 'wan'
option src 'wan'
option proto 'icmp'
option proto 'icmp'
option icmp_type 'echo-request'
option icmp_type 'echo-request'
option family 'ipv4'
option family 'ipv4'
option target 'ACCEPT'
option target 'ACCEPT'


config rule
config rule
option name 'Allow-IGMP'
option name 'Allow-IGMP'
option src 'wan'
option src 'wan'
option proto 'igmp'
option proto 'igmp'
option family 'ipv4'
option family 'ipv4'
option target 'ACCEPT'
option target 'ACCEPT'


config rule
config rule
option name 'Allow-DHCPv6'
option name 'Allow-DHCPv6'
option src 'wan'
option src 'wan'
option proto 'udp'
option proto 'udp'
option src_ip 'fe80::/10'
option src_ip 'fe80::/10'
option src_port '547'
option src_port '547'
option dest_ip 'fe80::/10'
option dest_ip 'fe80::/10'
option dest_port '546'
option dest_port '546'
option family 'ipv6'
option family 'ipv6'
option target 'ACCEPT'
option target 'ACCEPT'


config rule
config rule
option name 'Allow-MLD'
option name 'Allow-MLD'
option src 'wan'
option src 'wan'
option proto 'icmp'
option proto 'icmp'
option src_ip 'fe80::/10'
option src_ip 'fe80::/10'
list icmp_type '130/0'
list icmp_type '130/0'
list icmp_type '131/0'
list icmp_type '131/0'
list icmp_type '132/0'
list icmp_type '132/0'
list icmp_type '143/0'
list icmp_type '143/0'
option family 'ipv6'
option family 'ipv6'
option target 'ACCEPT'
option target 'ACCEPT'


config rule
config rule
option name 'Allow-ICMPv6-Input'
option name 'Allow-ICMPv6-Input'
option src 'wan'
option src 'wan'
option proto 'icmp'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option limit '1000/sec'
option family 'ipv6'
option family 'ipv6'
option target 'ACCEPT'
option target 'ACCEPT'


config rule
config rule
option name 'Allow-ICMPv6-Forward'
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option src 'wan'
option dest '*'
option dest '*'
option proto 'icmp'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option limit '1000/sec'
option family 'ipv6'
option family 'ipv6'
option target 'ACCEPT'
option target 'ACCEPT'


config include
config include
option path '/etc/firewall.user'
option path '/etc/firewall.user'


config rule
config rule
option src 'wan'
option src 'wan'
option dest 'lan'
option dest 'lan'
option proto 'esp'
option proto 'esp'
option target 'ACCEPT'
option target 'ACCEPT'


config rule
config rule
option src 'wan'
option src 'wan'
option dest 'lan'
option dest 'lan'
option dest_port '500'
option dest_port '500'
option proto 'udp'
option proto 'udp'
option target 'ACCEPT'
option target 'ACCEPT'


config include 'miniupnpd'
config include 'miniupnpd'
option type 'script'
option type 'script'
option path '/usr/share/miniupnpd/firewall.include'
option path '/usr/share/miniupnpd/firewall.include'
option family 'any'
option family 'any'
option reload '1'
option reload '1'


config zone
config zone
option name 'lan'
option name 'lan'
option input 'ACCEPT'
option input 'ACCEPT'
option output 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
option forward 'ACCEPT'
option network 'lan'
option network 'lan tvlan'


config zone
config zone
option name 'wan'
option name 'wan'
option input 'REJECT'
option input 'REJECT'
option output 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
option forward 'REJECT'
option masq '1'
option masq '1'
option mtu_fix '1'
option mtu_fix '1'
list network 'wan'
list network 'wan'
list network 'wan6'
list network 'wan6'


config forwarding
config forwarding
option src 'lan'
option src 'lan'
option dest 'wan'
option dest 'wan'


config zone
config zone
option name 'iptv'
option name 'iptv'
option input 'ACCEPT'
option input 'ACCEPT'
option output 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
option forward 'REJECT'
option network 'iptv'
option network 'iptv'
option mtu_fix '1'
option mtu_fix '1'
option masq '1'
option masq '1'


config forwarding
config forwarding
option src 'lan'
option src 'lan'
option dest 'iptv'
option dest 'iptv'


config forwarding
config forwarding
option src 'iptv'
option src 'iptv'
option dest 'lan'
option dest 'lan'


config zone
config zone
option name 'voip'
option name 'voip'
option input 'ACCEPT'
option input 'ACCEPT'
option output 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
option forward 'REJECT'
option network 'voip'
option network 'voip'
option masq '1'
option masq '1'
option mtu_fix '1'
option mtu_fix '1'


config forwarding
config forwarding
option src 'lan'
option src 'lan'
option dest 'voip'
option dest 'voip'