From f7ec5e7119a84796ea180150843ae2a96492415f Mon Sep 17 00:00:00 2001 From: jow Date: Wed, 9 Nov 2011 11:10:37 +0000 Subject: [PATCH] [package] firewall: add DHCPv6 default rule (#10381) git-svn-id: svn://svn.openwrt.org/openwrt/trunk@28874 3c298f89-4303-0410-b956-a3cf2f4a3e73 --- package/firewall/Makefile | 2 +- package/firewall/files/firewall.config | 12 ++++++++++++ 2 files changed, 13 insertions(+), 1 deletion(-) diff --git a/package/firewall/Makefile b/package/firewall/Makefile index f95f73b4a..610634815 100644 --- a/package/firewall/Makefile +++ b/package/firewall/Makefile @@ -9,7 +9,7 @@ include $(TOPDIR)/rules.mk PKG_NAME:=firewall PKG_VERSION:=2 -PKG_RELEASE:=41 +PKG_RELEASE:=42 include $(INCLUDE_DIR)/package.mk diff --git a/package/firewall/files/firewall.config b/package/firewall/files/firewall.config index 5a5dfd018..4ba165fcc 100644 --- a/package/firewall/files/firewall.config +++ b/package/firewall/files/firewall.config @@ -43,6 +43,18 @@ config rule option family ipv4 option target ACCEPT +# Allow DHCPv6 replies +# see https://dev.openwrt.org/ticket/10381 +config rule + option src wan + option proto udp + option src_ip fe80::/10 + option src_port 547 + option dest_ip fe80::/10 + option dest_port 546 + option family ipv6 + option target ACCEPT + # Allow essential incoming IPv6 ICMP traffic config rule option src wan -- 2.20.1