X-Git-Url: https://git.rohieb.name/openwrt.git/blobdiff_plain/9313b904536d595361703f559e34d16bc6412611..68544750068688aa48505135c23f01e055e7f6a2:/openwrt/target/default/target_skeleton/etc/init.d/S45firewall diff --git a/openwrt/target/default/target_skeleton/etc/init.d/S45firewall b/openwrt/target/default/target_skeleton/etc/init.d/S45firewall index a50663725..8f9b9404e 100755 --- a/openwrt/target/default/target_skeleton/etc/init.d/S45firewall +++ b/openwrt/target/default/target_skeleton/etc/init.d/S45firewall @@ -16,10 +16,6 @@ iptables -N forwarding_rule iptables -t nat -N prerouting_rule iptables -t nat -N postrouting_rule -### Port forwarding -# iptables -t nat -A prerouting_rule -i $WAN -p tcp --dport 22 -j DNAT --to 192.168.1.2 -# iptables -A forwarding_rule -i $WAN -p tcp --dport 22 -d 192.168.1.2 -j ACCEPT - ### INPUT ### (connections with the router as destination) @@ -67,8 +63,8 @@ iptables -t nat -N postrouting_rule # base case iptables -P FORWARD DROP iptables -A FORWARD -m state --state INVALID -j DROP - iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT iptables -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu + iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT # allow iptables -A FORWARD -i br0 -o br0 -j ACCEPT @@ -85,3 +81,6 @@ iptables -t nat -N postrouting_rule iptables -t nat -A PREROUTING -j prerouting_rule iptables -t nat -A POSTROUTING -j postrouting_rule iptables -t nat -A POSTROUTING -o $WAN -j MASQUERADE + +## USER RULES +. /etc/firewall.user