[backfire] merge r32127
[openwrt-10.03/.git] / package / firewall / files / firewall.config
index d6a125d49ba9d85e2138a9b613fb068c49bdfd4f..8ee9db2781de532544a2573745df6123a2ce9bbb 100644 (file)
@@ -29,6 +29,7 @@ config forwarding
 # We need to accept udp packets on port 68,
 # see https://dev.openwrt.org/ticket/4108
 config rule
+       option name             Allow-DHCP-Renew
        option src              wan
        option proto            udp
        option dest_port        68
@@ -37,6 +38,7 @@ config rule
 
 # Allow IPv4 ping
 config rule
+       option name             Allow-Ping
        option src              wan
        option proto            icmp
        option icmp_type        echo-request
@@ -46,6 +48,7 @@ config rule
 # Allow DHCPv6 replies
 # see https://dev.openwrt.org/ticket/10381
 config rule
+       option name             Allow-DHCPv6
        option src              wan
        option proto            udp
        option src_ip           fe80::/10
@@ -57,6 +60,7 @@ config rule
 
 # Allow essential incoming IPv6 ICMP traffic
 config rule
+       option name             Allow-ICMPv6-Input
        option src              wan
        option proto    icmp
        list icmp_type          echo-request
@@ -67,12 +71,15 @@ config rule
        list icmp_type          unknown-header-type
        list icmp_type          router-solicitation
        list icmp_type          neighbour-solicitation
+       list icmp_type          router-advertisement
+       list icmp_type          neighbour-advertisement
        option limit            1000/sec
        option family           ipv6
        option target           ACCEPT
 
 # Allow essential forwarded IPv6 ICMP traffic
 config rule                                   
+       option name             Allow-ICMPv6-Forward
        option src              wan
        option dest             *
        option proto            icmp