diff options
author | Steven Barth <cyrus@openwrt.org> | 2013-04-24 14:17:24 +0000 |
---|---|---|
committer | Steven Barth <cyrus@openwrt.org> | 2013-04-24 14:17:24 +0000 |
commit | 2c78c1457b2a0f44dd295bbf5fc7c6e6465409a5 (patch) | |
tree | 132dfc7d1dee8c95a3069eea91249467594d0bc9 /package/network/config/firewall3/files/firewall.config | |
parent | af30e5e6bb5dcf1b615ea862fd8bb7b902c7a852 (diff) | |
download | upstream-2c78c1457b2a0f44dd295bbf5fc7c6e6465409a5.tar.gz upstream-2c78c1457b2a0f44dd295bbf5fc7c6e6465409a5.tar.bz2 upstream-2c78c1457b2a0f44dd295bbf5fc7c6e6465409a5.zip |
firewall3: Make IPv6 ULA-Border generation dynamic
This fixes working behind another router which gives out ULAs.
SVN-Revision: 36416
Diffstat (limited to 'package/network/config/firewall3/files/firewall.config')
-rw-r--r-- | package/network/config/firewall3/files/firewall.config | 26 |
1 files changed, 7 insertions, 19 deletions
diff --git a/package/network/config/firewall3/files/firewall.config b/package/network/config/firewall3/files/firewall.config index 6acfe1e86a..fa09b6819e 100644 --- a/package/network/config/firewall3/files/firewall.config +++ b/package/network/config/firewall3/files/firewall.config @@ -95,29 +95,17 @@ config rule option family ipv6 option target ACCEPT -# Block ULA-traffic from leaking out -config rule - option name Enforce-ULA-Border-Src - option src * - option dest wan - option proto all - option src_ip fc00::/7 - option family ipv6 - option target REJECT - -config rule - option name Enforce-ULA-Border-Dest - option src * - option dest wan - option proto all - option dest_ip fc00::/7 - option family ipv6 - option target REJECT - # include a file with users custom iptables rules config include option path /etc/firewall.user +# include IPv6 ULA-border +config include + option type script + option path /usr/share/firewall/ipv6-ula-border.sh + option family IPv6 + option reload 1 + ### EXAMPLE CONFIG SECTIONS # do not allow a specific ip to access wan |