firewall 1.5 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980
  1. config defaults
  2. option syn_flood 1
  3. option input DROP
  4. option output ACCEPT
  5. option forward DROP
  6. config zone
  7. option name lan
  8. option input ACCEPT
  9. option output ACCEPT
  10. option forward DROP
  11. config zone
  12. option name wan
  13. option input DROP
  14. option output ACCEPT
  15. option forward DROP
  16. option masq 1
  17. config forwarding
  18. option src lan
  19. option dest wan
  20. ### EXAMPLE CONFIG SECTIONS
  21. # do not allow a specific ip to access wan
  22. #config rule
  23. # option src lan
  24. # option src_ip 192.168.45.2
  25. # option dest wan
  26. # option proto tcp
  27. # option target REJECT
  28. # block a specific mac on wan
  29. #config rule
  30. # option dest wan
  31. # option src_mac 00:11:22:33:44:66
  32. # option target REJECT
  33. # block incoming ICMP traffic on a zone
  34. #config rule
  35. # option src lan
  36. # option proto ICMP
  37. # option target DROP
  38. # port redirect port coming in on wan to lan
  39. #config redirect
  40. # option src wan
  41. # option src_dport 80
  42. # option dest lan
  43. # option dest_ip 192.168.16.235
  44. # option dest_port 80
  45. # option protocol tcp
  46. # include a file with users custom iptables rules
  47. #config include
  48. # option path /etc/firewall.user
  49. ### FULL CONFIG SECTIONS
  50. #config rule
  51. # option src lan
  52. # option src_ip 192.168.45.2
  53. # option src_mac 00:11:22:33:44:55
  54. # option src_port 80
  55. # option dest wan
  56. # option dest_ip 194.25.2.129
  57. # option dest_port 120
  58. # option proto tcp
  59. # option target REJECT
  60. #config redirect
  61. # option src lan
  62. # option src_ip 192.168.45.2
  63. # option src_mac 00:11:22:33:44:55
  64. # option src_port 1024
  65. # option src_dport 80
  66. # option dest_ip 194.25.2.129
  67. # option dest_port 120
  68. # option proto tcp