projects
/
openwrt.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
[tools] gmp: update to 5.0.4
[openwrt.git]
/
package
/
firewall
/
files
/
firewall.config
diff --git
a/package/firewall/files/firewall.config
b/package/firewall/files/firewall.config
index
4ba165f
..
6322922
100644
(file)
--- a/
package/firewall/files/firewall.config
+++ b/
package/firewall/files/firewall.config
@@
-29,6
+29,7
@@
config forwarding
# We need to accept udp packets on port 68,
# see https://dev.openwrt.org/ticket/4108
config rule
# We need to accept udp packets on port 68,
# see https://dev.openwrt.org/ticket/4108
config rule
+ option name Allow-DHCP-Renew
option src wan
option proto udp
option dest_port 68
option src wan
option proto udp
option dest_port 68
@@
-37,6
+38,7
@@
config rule
# Allow IPv4 ping
config rule
# Allow IPv4 ping
config rule
+ option name Allow-Ping
option src wan
option proto icmp
option icmp_type echo-request
option src wan
option proto icmp
option icmp_type echo-request
@@
-46,6
+48,7
@@
config rule
# Allow DHCPv6 replies
# see https://dev.openwrt.org/ticket/10381
config rule
# Allow DHCPv6 replies
# see https://dev.openwrt.org/ticket/10381
config rule
+ option name Allow-DHCPv6
option src wan
option proto udp
option src_ip fe80::/10
option src wan
option proto udp
option src_ip fe80::/10
@@
-57,9
+60,11
@@
config rule
# Allow essential incoming IPv6 ICMP traffic
config rule
# Allow essential incoming IPv6 ICMP traffic
config rule
+ option name Allow-ICMPv6-Input
option src wan
option proto icmp
list icmp_type echo-request
option src wan
option proto icmp
list icmp_type echo-request
+ list icmp_type echo-reply
list icmp_type destination-unreachable
list icmp_type packet-too-big
list icmp_type time-exceeded
list icmp_type destination-unreachable
list icmp_type packet-too-big
list icmp_type time-exceeded
@@
-73,10
+78,12
@@
config rule
# Allow essential forwarded IPv6 ICMP traffic
config rule
# Allow essential forwarded IPv6 ICMP traffic
config rule
+ option name Allow-ICMPv6-Forward
option src wan
option dest *
option proto icmp
list icmp_type echo-request
option src wan
option dest *
option proto icmp
list icmp_type echo-request
+ list icmp_type echo-reply
list icmp_type destination-unreachable
list icmp_type packet-too-big
list icmp_type time-exceeded
list icmp_type destination-unreachable
list icmp_type packet-too-big
list icmp_type time-exceeded
This page took
0.036458 seconds
and
4
git commands to generate.