- introduce per-section "option enabled" which defaults to "1" - useful to disable rules or zones without having to delete them
- annotate default traffic rules with names
- bump version
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@29577
3c298f89-4303-0410-b956-
a3cf2f4a3e73
PKG_NAME:=firewall
PKG_VERSION:=2
PKG_NAME:=firewall
PKG_VERSION:=2
include $(INCLUDE_DIR)/package.mk
include $(INCLUDE_DIR)/package.mk
# We need to accept udp packets on port 68,
# see https://dev.openwrt.org/ticket/4108
config rule
# We need to accept udp packets on port 68,
# see https://dev.openwrt.org/ticket/4108
config rule
+ option name Allow-DHCP-Renew
option src wan
option proto udp
option dest_port 68
option src wan
option proto udp
option dest_port 68
# Allow IPv4 ping
config rule
# Allow IPv4 ping
config rule
option src wan
option proto icmp
option icmp_type echo-request
option src wan
option proto icmp
option icmp_type echo-request
# Allow DHCPv6 replies
# see https://dev.openwrt.org/ticket/10381
config rule
# Allow DHCPv6 replies
# see https://dev.openwrt.org/ticket/10381
config rule
+ option name Allow-DHCPv6
option src wan
option proto udp
option src_ip fe80::/10
option src wan
option proto udp
option src_ip fe80::/10
# Allow essential incoming IPv6 ICMP traffic
config rule
# Allow essential incoming IPv6 ICMP traffic
config rule
+ option name Allow-ICMPv6-Input
option src wan
option proto icmp
list icmp_type echo-request
option src wan
option proto icmp
list icmp_type echo-request
# Allow essential forwarded IPv6 ICMP traffic
config rule
# Allow essential forwarded IPv6 ICMP traffic
config rule
+ option name Allow-ICMPv6-Forward
option src wan
option dest *
option proto icmp
option src wan
option dest *
option proto icmp
export ${NO_EXPORT:+-n} -- "${prefix}NAME"="${config}"
config_get "${prefix}TYPE" "$config" TYPE
}
export ${NO_EXPORT:+-n} -- "${prefix}NAME"="${config}"
config_get "${prefix}TYPE" "$config" TYPE
}
+
+ local enabled
+ config_get_bool enabled "$config" enabled 1
+ [ $enabled -eq 1 ] || return 1
+
[ "$1" == '{' ] && shift
while [ $# -ge 3 ]; do
local type=$1
[ "$1" == '{' ] && shift
while [ $# -ge 3 ]; do
local type=$1