summaryrefslogtreecommitdiff
path: root/files/etc/config/firewall
diff options
context:
space:
mode:
authorDarkeye <postfach@martinmichel.info>2011-01-21 00:19:23 (GMT)
committerDarkeye <postfach@martinmichel.info>2011-01-21 00:19:23 (GMT)
commitb5d2b9aa65deda10d19a8d324674035fdeab6c13 (patch)
tree894587abe78f953c5220a4b36f8289ca77919a0a /files/etc/config/firewall
parent90fb13bf0387a639d2d27c881e2dc1fd68f9747e (diff)
fixed bug (ath0/ath1 in batman-adv)
Diffstat (limited to 'files/etc/config/firewall')
-rw-r--r--files/etc/config/firewall49
1 files changed, 49 insertions, 0 deletions
diff --git a/files/etc/config/firewall b/files/etc/config/firewall
new file mode 100644
index 0000000..9175a06
--- /dev/null
+++ b/files/etc/config/firewall
@@ -0,0 +1,49 @@
+config defaults
+ option syn_flood 1
+ option input ACCEPT
+ option output ACCEPT
+ option forward REJECT
+
+config zone
+ option name lan
+ option input ACCEPT
+ option output ACCEPT
+ option forward REJECT
+
+config zone
+ option name wan
+ option input REJECT
+ option output ACCEPT
+ option forward REJECT
+ option masq 1
+ option mtu_fix 1
+config zone
+ option name mesh
+ option input ACCEPT
+ option output ACCEPT
+ option forward REJECT
+config forwarding
+ option src lan
+ option dest wan
+config forwarding
+ option src mesh
+ option dest wan
+# We need to accept udp packets on port 68,
+# see https://dev.openwrt.org/ticket/4108
+config rule
+ option src wan
+ option proto udp
+ option dest_port 68
+ option target ACCEPT
+
+#Allow ping
+config rule
+ option src wan
+ option proto icmp
+ option icmp_type echo-request
+ option target ACCEPT
+
+# include a file with users custom iptables rules
+config include
+ option path /etc/firewall.user
+
contact: Jan Huwald // Impressum