summaryrefslogtreecommitdiff
path: root/files/common/etc/config/firewall
diff options
context:
space:
mode:
Diffstat (limited to 'files/common/etc/config/firewall')
-rw-r--r--files/common/etc/config/firewall50
1 files changed, 50 insertions, 0 deletions
diff --git a/files/common/etc/config/firewall b/files/common/etc/config/firewall
new file mode 100644
index 0000000..4b702ba
--- /dev/null
+++ b/files/common/etc/config/firewall
@@ -0,0 +1,50 @@
+config defaults
+ option syn_flood 1
+ option input ACCEPT
+ option output ACCEPT
+ option forward REJECT
+
+config zone
+ option name wan
+ option input REJECT
+ option output ACCEPT
+ option forward REJECT
+ option masq 1
+ option mtu_fix 1
+config zone
+ option name mesh
+ option input ACCEPT
+ option output ACCEPT
+ option forward REJECT
+config zone
+ option name lan
+ option input ACCEPT
+ option output ACCEPT
+ option forward REJECT
+config forwarding
+ option src mesh
+ option dest wan
+
+config forwarding
+ option src lan
+ option dest wan
+
+# We need to accept udp packets on port 68,
+# see https://dev.openwrt.org/ticket/4108
+config rule
+ option src wan
+ option proto udp
+ option dest_port 68
+ option target ACCEPT
+
+#Allow ping
+config rule
+ option src wan
+ option proto icmp
+ option icmp_type echo-request
+ option target ACCEPT
+
+# include a file with users custom iptables rules
+config include
+ option path /etc/firewall.user
+
contact: Jan Huwald // Impressum