aboutsummaryrefslogtreecommitdiffstats
path: root/package/firewall/files/firewall.config
diff options
context:
space:
mode:
authorJo-Philipp Wich <jow@openwrt.org>2011-12-20 01:10:15 +0000
committerJo-Philipp Wich <jow@openwrt.org>2011-12-20 01:10:15 +0000
commitd1d3cd65a847c0518448e195fd40962cf88d31c4 (patch)
tree54afd727dccae78490a9cacd3e22f28e629401d0 /package/firewall/files/firewall.config
parent1d37e5d5236639a974d38fd98d8753458ec4492f (diff)
downloadmaster-187ad058-d1d3cd65a847c0518448e195fd40962cf88d31c4.tar.gz
master-187ad058-d1d3cd65a847c0518448e195fd40962cf88d31c4.tar.bz2
master-187ad058-d1d3cd65a847c0518448e195fd40962cf88d31c4.zip
[package] firewall:
- introduce per-section "option enabled" which defaults to "1" - useful to disable rules or zones without having to delete them - annotate default traffic rules with names - bump version git-svn-id: svn://svn.openwrt.org/openwrt/trunk@29577 3c298f89-4303-0410-b956-a3cf2f4a3e73
Diffstat (limited to 'package/firewall/files/firewall.config')
-rw-r--r--package/firewall/files/firewall.config5
1 files changed, 5 insertions, 0 deletions
diff --git a/package/firewall/files/firewall.config b/package/firewall/files/firewall.config
index 4ba165fcc6..77832ffaca 100644
--- a/package/firewall/files/firewall.config
+++ b/package/firewall/files/firewall.config
@@ -29,6 +29,7 @@ config forwarding
# We need to accept udp packets on port 68,
# see https://dev.openwrt.org/ticket/4108
config rule
+ option name Allow-DHCP-Renew
option src wan
option proto udp
option dest_port 68
@@ -37,6 +38,7 @@ config rule
# Allow IPv4 ping
config rule
+ option name Allow-Ping
option src wan
option proto icmp
option icmp_type echo-request
@@ -46,6 +48,7 @@ config rule
# Allow DHCPv6 replies
# see https://dev.openwrt.org/ticket/10381
config rule
+ option name Allow-DHCPv6
option src wan
option proto udp
option src_ip fe80::/10
@@ -57,6 +60,7 @@ config rule
# Allow essential incoming IPv6 ICMP traffic
config rule
+ option name Allow-ICMPv6-Input
option src wan
option proto icmp
list icmp_type echo-request
@@ -73,6 +77,7 @@ config rule
# Allow essential forwarded IPv6 ICMP traffic
config rule
+ option name Allow-ICMPv6-Forward
option src wan
option dest *
option proto icmp