Új hozzászólás Aktív témák

  • szponzor

    senior tag

    válasz vargalex #135 üzenetére

    /etc/config/firewall
    config 'defaults'
    option 'syn_flood' '1'
    option 'input' 'ACCEPT'
    option 'output' 'ACCEPT'
    option 'forward' 'REJECT'
    option 'drop_invalid' '1'

    config 'zone'
    option 'name' 'lan'
    option 'network' 'lan'
    option 'input' 'ACCEPT'
    option 'output' 'ACCEPT'
    option 'forward' 'REJECT'

    config 'zone'
    option 'name' 'wan'
    option 'network' 'wan'
    option 'input' 'DROP'
    option 'output' 'ACCEPT'
    option 'forward' 'REJECT'
    option 'masq' '1'
    option 'mtu_fix' '1'

    config 'forwarding'
    option 'src' 'lan'
    option 'dest' 'wan'

    config 'rule'
    option 'src' 'wan'
    option 'proto' 'udp'
    option 'dest_port' '68'
    option 'target' 'ACCEPT'
    option 'family' 'ipv4'

    config 'rule'
    option 'src' 'wan'
    option 'proto' 'icmp'
    option 'icmp_type' 'echo-request'
    option 'family' 'ipv4'
    option 'target' 'ACCEPT'

    config 'rule'
    option 'src' 'wan'
    option 'proto' 'udp'
    option 'src_ip' 'fe80::/10'
    option 'src_port' '547'
    option 'dest_ip' 'fe80::/10'
    option 'dest_port' '546'
    option 'family' 'ipv6'
    option 'target' 'ACCEPT'

    config 'rule'
    option 'src' 'wan'
    option 'proto' 'icmp'
    list 'icmp_type' 'echo-request'
    list 'icmp_type' 'destination-unreachable'
    list 'icmp_type' 'packet-too-big'
    list 'icmp_type' 'time-exceeded'
    list 'icmp_type' 'bad-header'
    list 'icmp_type' 'unknown-header-type'
    list 'icmp_type' 'router-solicitation'
    list 'icmp_type' 'neighbour-solicitation'
    option 'limit' '1000/sec'
    option 'family' 'ipv6'
    option 'target' 'ACCEPT'

    config 'rule'
    option 'src' 'wan'
    option 'dest' '*'
    option 'proto' 'icmp'
    list 'icmp_type' 'echo-request'
    list 'icmp_type' 'destination-unreachable'
    list 'icmp_type' 'packet-too-big'
    list 'icmp_type' 'time-exceeded'
    list 'icmp_type' 'bad-header'
    list 'icmp_type' 'unknown-header-type'
    option 'limit' '1000/sec'
    option 'family' 'ipv6'
    option 'target' 'ACCEPT'

    config 'include'
    option 'path' '/etc/firewall.user'

    config 'rule' 'transmission_web'
    option 'target' 'ACCEPT'
    option '_name' 'transmission_web'
    option 'src' 'wan'
    option 'proto' 'tcp'
    option 'dest_port' '9091'

    config 'redirect'
    option '_name' 'ssh_WAN'
    option 'src' 'wan'
    option 'proto' 'tcp'
    option 'src_dport' '2222'
    option 'dest_ip' '192.168.1.1'
    option 'dest_port' '22'
    option 'target' 'DNAT'
    option 'dest' 'lan'

    config 'rule'
    option 'target' 'ACCEPT'
    option '_name' 'ssh_WAN'
    option 'src' 'wan'
    option 'proto' 'tcp'
    option 'dest_ip' '192.168.1.1'
    option 'dest_port' '22'

    config 'redirect'
    option '_name' 'ftp_WAN'
    option 'src' 'wan'
    option 'proto' 'tcp'
    option 'src_dport' '2221'
    option 'dest_ip' '192.168.1.1'
    option 'dest_port' '21'
    option 'target' 'DNAT'
    option 'dest' 'lan'

    config 'rule'
    option 'target' 'ACCEPT'
    option '_name' 'ftp_WAN'
    option 'src' 'wan'
    option 'proto' 'tcp'
    option 'dest_ip' '192.168.1.1'
    option 'dest_port' '21'

    config 'rule'
    option 'target' 'ACCEPT'
    option '_name' 'Transmission'
    option 'src' 'wan'
    option 'proto' 'tcpudp'
    option 'dest_port' '21234'

    config 'rule'
    option 'target' 'ACCEPT'
    option '_name' 'Luci_HTTPS'
    option 'src' 'wan'
    option 'proto' 'tcp'
    option 'dest_port' '443'

    config 'redirect'
    option '_name' 'bsw'
    option 'src' 'wan'
    option 'dest_ip' '192.168.1.100'
    option 'target' 'DNAT'
    option 'dest' 'lan'
    option 'proto' 'tcp'
    option 'src_dport' '8080'
    option 'dest_port' '80'

Új hozzászólás Aktív témák