|
|
@ -48,27 +48,16 @@ config rule |
|
|
|
option src wan |
|
|
|
option src wan |
|
|
|
option dest * |
|
|
|
option dest * |
|
|
|
option proto icmp |
|
|
|
option proto icmp |
|
|
|
list icmp_type router-solicitation |
|
|
|
|
|
|
|
list icmp_type router-advertisement |
|
|
|
|
|
|
|
list icmp_type neighbour-solicitation |
|
|
|
|
|
|
|
list icmp_type neighbour-advertisement |
|
|
|
|
|
|
|
list icmp_type echo-request |
|
|
|
list icmp_type echo-request |
|
|
|
list icmp_type destination-unreachable |
|
|
|
list icmp_type destination-unreachable |
|
|
|
list icmp_type packet-too-big |
|
|
|
list icmp_type packet-too-big |
|
|
|
list icmp_type time-exceeded |
|
|
|
list icmp_type time-exceeded |
|
|
|
|
|
|
|
list icmp_type bad-header |
|
|
|
|
|
|
|
list icmp_type unknown-header-type |
|
|
|
option limit 1000/sec |
|
|
|
option limit 1000/sec |
|
|
|
option family ipv6 |
|
|
|
option family ipv6 |
|
|
|
option target ACCEPT |
|
|
|
option target ACCEPT |
|
|
|
|
|
|
|
|
|
|
|
# Drop leaking router advertisements on WAN |
|
|
|
|
|
|
|
config rule |
|
|
|
|
|
|
|
option src * |
|
|
|
|
|
|
|
option dest wan |
|
|
|
|
|
|
|
option proto icmp |
|
|
|
|
|
|
|
option icmp_type router-advertisement |
|
|
|
|
|
|
|
option family ipv6 |
|
|
|
|
|
|
|
option target DROP |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# include a file with users custom iptables rules |
|
|
|
# include a file with users custom iptables rules |
|
|
|
config include |
|
|
|
config include |
|
|
|
option path /etc/firewall.user |
|
|
|
option path /etc/firewall.user |
|
|
|