当前位置:   article > 正文





9.1 防火墙配置文件

    root@Togetek:/# cat /etc/config/firewall
    config defaults
            option syn_flood        1
            option input            REJECT
            option output           ACCEPT
            option forward          REJECT
    # Uncomment this line to disable ipv6 rules
    #       option disable_ipv6     1

    config zone
            option name             lan
            list   network          'lan'
            option input            ACCEPT
            option output           ACCEPT
            option forward          ACCEPT

    config zone
            option name             wan
            list   network          'wan'
            list   network          'wan6'
            option input            ACCEPT
            option output           ACCEPT
            option forward          REJECT
            option masq             1
            option mtu_fix          1

    config forwarding
            option src              lan
            option dest             wan

    # We need to accept udp packets on port 68,
    # see https://dev.openwrt.org/ticket/4108
    config rule
            option name             Allow-DHCP-Renew
            option src              wan
            option proto            udp
            option dest_port        68
            option target           ACCEPT
            option family           ipv4

    # Allow IPv4 ping
    config rule
            option name             Allow-Ping
            option src              wan
            option proto            icmp
            option icmp_type        echo-reque
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
