6 # Uncomment this line to disable ipv6 rules
7 # option disable_ipv6 1
29 # We need to accept udp packets on port 68,
30 # see https://dev.openwrt.org/ticket/4108
42 option icmp_type echo-request
46 # Allow essential incoming IPv6 ICMP traffic
51 list icmp_type echo-request
52 list icmp_type destination-unreachable
53 list icmp_type packet-too-big
54 list icmp_type time-exceeded
55 list icmp_type bad-header
56 list icmp_type unknown-header-type
61 # include a file with users custom iptables rules
63 option path /etc/firewall.user
66 ### EXAMPLE CONFIG SECTIONS
67 # do not allow a specific ip to access wan
70 # option src_ip 192.168.45.2
73 # option target REJECT
75 # block a specific mac on wan
78 # option src_mac 00:11:22:33:44:66
79 # option target REJECT
81 # block incoming ICMP traffic on a zone
87 # port redirect port coming in on wan to lan
92 # option dest_ip 192.168.16.235
96 # port redirect of remapped ssh port (22001) on wan
99 # option src_dport 22001
101 # option dest_port 22
104 # allow IPsec/ESP and ISAKMP passthrough
108 # option protocol esp
109 # option target ACCEPT
114 # option src_port 500
115 # option dest_port 500
117 # option target ACCEPT
119 ### FULL CONFIG SECTIONS
122 # option src_ip 192.168.45.2
123 # option src_mac 00:11:22:33:44:55
126 # option dest_ip 194.25.2.129
127 # option dest_port 120
129 # option target REJECT
133 # option src_ip 192.168.45.2
134 # option src_mac 00:11:22:33:44:55
135 # option src_port 1024
136 # option src_dport 80
137 # option dest_ip 194.25.2.129
138 # option dest_port 120