firewall

config defaults option input 'ACCEPT' option output 'ACCEPT' option forward 'REJECT' option synflood_protect '1' config zone option name 'lan' option input 'ACCEPT' option output 'ACCEPT' option forward 'ACCEPT' list network 'lan' config zone option name 'wan' option input 'REJECT' option output 'ACCEPT' option forward 'REJECT' option masq '1' option mtu_fix '1' list network 'WAN' config forwarding option src 'lan' option dest 'wan' config rule option name 'Allow-ICMPv6-Forward' option src 'wan' option dest '*' option proto 'icmp' list icmp_type 'echo-request' list icmp_type 'echo-reply' list icmp_type 'destination-unreachable' list icmp_type 'packet-too-big' list icmp_type 'time-exceeded' list icmp_type 'bad-header' list icmp_type 'unknown-header-type' option limit '1000/sec' option family 'ipv6' option target 'ACCEPT' config rule option name 'Allow-IPSec-ESP' option src 'wan' option dest 'lan' option proto 'esp' option target 'ACCEPT' config rule option name 'Allow-ISAKMP' option src 'wan' option dest 'lan' option dest_port '500' option proto 'udp' option target 'ACCEPT' config include option path '/etc/firewall.user' config zone option name 'vpn' option input 'ACCEPT' option output 'ACCEPT' option forward 'ACCEPT' list network 'VPN' option masq '1' config forwarding option src 'lan' option dest 'vpn' config forwarding option src 'vpn' option dest 'lan' config rule list proto 'udp' option src 'wan' option target 'ACCEPT' option name 'Allow-WireguardServer' option dest_port '51821' config zone option name 'vpn_server' option input 'ACCEPT' option output 'ACCEPT' option forward 'ACCEPT' list network 'vpn_server' config forwarding option src 'vpn_server' option dest 'lan' config forwarding option src 'lan' option dest 'vpn_server' config rule option name 'Allow-GRE-EOIP' list proto 'gre' option src 'vpn_server' option dest '*' option target 'ACCEPT' config zone option name 'voip' option input 'ACCEPT' option output 'ACCEPT' option forward 'REJECT' option masq '1' list network 'VOIP' config zone option name 'iptv' option input 'ACCEPT' option output 'ACCEPT' option forward 'REJECT' option masq '1' option mtu_fix '1' list network 'IPTV' config forwarding option src 'lan' option dest 'voip' config forwarding option src 'iptv' option dest 'lan' config forwarding option src 'lan' option dest 'iptv' config redirect option dest 'lan' option target 'DNAT' list proto 'tcp' option src 'wan' option src_dport '80' option dest_ip '192.168.3.2' option name 'http' config redirect option dest 'lan' option target 'DNAT' list proto 'tcp' option src 'wan' option src_dport '443' option name 'https' option dest_ip '192.168.3.2'

Public Last updated: 2022-09-12 11:30:08 AM