Keresés

Hirdetés

Új hozzászólás Aktív témák

  • doberman

    senior tag

    válasz Szita1 #23254 üzenetére

    szia nekem is van olyan... ne de nem tudom mi az.. sőt én ilyet is leltem benne:

    IPv4 and IPv6 TCP+UDP *:0.0.0.0/0:* Device:0.0.0.0/0:*

    z

    8lnu

  • vargalex

    Topikgazda

    válasz Szita1 #23254 üzenetére

    Hi!

    Ha az eredeti /etc/config/firewall tartalmát nézed, akkor ott van comment-ben, hogy mire való:

    # Allow DHCPv6 replies
    # see https://dev.openwrt.org/ticket/10381
    config rule
    option src wan
    option proto udp
    option src_ip fe80::/10
    option src_port 547
    option dest_ip fe80::/10
    option dest_port 546
    option family ipv6
    option target ACCEPT

    Sőt, van még néhány:

    # We need to accept udp packets on port 68,
    # see https://dev.openwrt.org/ticket/4108
    config rule
    option src wan
    option proto udp
    option dest_port 68
    option target ACCEPT
    option family ipv4

    # Allow IPv4 ping
    config rule
    option src wan
    option proto icmp
    option icmp_type echo-request
    option family ipv4
    option target ACCEPT

    # Allow DHCPv6 replies
    # see https://dev.openwrt.org/ticket/10381
    config rule
    option src wan
    option proto udp
    option src_ip fe80::/10
    option src_port 547
    option dest_ip fe80::/10
    option dest_port 546
    option family ipv6
    option target ACCEPT

    # Allow essential incoming IPv6 ICMP traffic
    config rule
    option src wan
    option proto icmp
    list icmp_type echo-request
    list icmp_type destination-unreachable
    list icmp_type packet-too-big
    list icmp_type time-exceeded
    list icmp_type bad-header
    list icmp_type unknown-header-type
    list icmp_type router-solicitation
    list icmp_type neighbour-solicitation
    option limit 1000/sec
    option family ipv6
    option target ACCEPT

    # Allow essential forwarded IPv6 ICMP traffic
    config rule
    option src wan
    option dest *
    option proto icmp
    list icmp_type echo-request
    list icmp_type destination-unreachable
    list icmp_type packet-too-big
    list icmp_type time-exceeded
    list icmp_type bad-header
    list icmp_type unknown-header-type
    option limit 1000/sec
    option family ipv6
    option target ACCEPT

    [ Szerkesztve ]

    Alex

Új hozzászólás Aktív témák