projects
/
openwrt-10.03
/
.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
[backfire] merge r26961
[openwrt-10.03/.git]
/
package
/
firewall
/
files
/
firewall.config
diff --git
a/package/firewall/files/firewall.config
b/package/firewall/files/firewall.config
index 5a4b5af43657d3508e582b2bacea8893941d12c2..f842a970e0aae97aa61d7d3f509b28762d7a1b05 100644
(file)
--- a/
package/firewall/files/firewall.config
+++ b/
package/firewall/files/firewall.config
@@
-3,24
+3,28
@@
config defaults
option input ACCEPT
option output ACCEPT
option forward REJECT
option input ACCEPT
option output ACCEPT
option forward REJECT
+# Uncomment this line to disable ipv6 rules
+# option disable_ipv6 1
config zone
option name lan
config zone
option name lan
+ option network 'lan'
option input ACCEPT
option output ACCEPT
option forward REJECT
config zone
option name wan
option input ACCEPT
option output ACCEPT
option forward REJECT
config zone
option name wan
+ option network 'wan'
option input REJECT
option output ACCEPT
option forward REJECT
option masq 1
option input REJECT
option output ACCEPT
option forward REJECT
option masq 1
+ option mtu_fix 1
config forwarding
option src lan
option dest wan
config forwarding
option src lan
option dest wan
- option mtu_fix 1
# We need to accept udp packets on port 68,
# see https://dev.openwrt.org/ticket/4108
# We need to accept udp packets on port 68,
# see https://dev.openwrt.org/ticket/4108
@@
-29,6
+33,14
@@
config rule
option proto udp
option dest_port 68
option target ACCEPT
option proto udp
option dest_port 68
option target ACCEPT
+ option family ipv4
+
+#Allow ping
+config rule
+ option src wan
+ option proto icmp
+ option icmp_type echo-request
+ option target ACCEPT
# include a file with users custom iptables rules
config include
# include a file with users custom iptables rules
config include