Changeset b68978d in freewrt for package/iptables/files
- Timestamp:
- Aug 17, 2025, 12:45:07 PM (4 months ago)
- Branches:
- freewrt_2_0
- Children:
- f15c9543
- Parents:
- b07a1b5
- git-author:
- Waldemar Brodkorb <wbx@…> (08/17/25 12:44:26)
- git-committer:
- Waldemar Brodkorb <wbx@…> (08/17/25 12:45:07)
- File:
-
- 1 edited
-
package/iptables/files/firewall.conf (modified) (4 diffs)
Legend:
- Unmodified
- Added
- Removed
-
package/iptables/files/firewall.conf
rb07a1b5 rb68978d 4 4 exit 1 5 5 ### Interfaces 6 WAN= ppp07 LAN= br08 WLAN= eth16 WAN=eth0.1 7 LAN=eth0.0 8 WLAN=wlan0 9 9 10 10 ###################################################################### … … 26 26 27 27 # base case 28 iptables -A INPUT -m state --state INVALID -j DROP29 iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT30 iptables -A INPUT -p tcp --tcp-flags SYN SYN --tcp-option \!2 -j DROP28 iptables -A INPUT -m conntrack --ctstate INVALID -j DROP 29 iptables -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT 30 iptables -A INPUT -p tcp --tcp-flags SYN SYN \! --tcp-option 2 -j DROP 31 31 32 32 # custom rules … … 46 46 47 47 # base case 48 iptables -A OUTPUT -m state --state INVALID -j DROP49 iptables -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT48 iptables -A OUTPUT -m conntrack --ctstate INVALID -j DROP 49 iptables -A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT 50 50 51 51 ### FORWARD … … 53 53 54 54 # base case 55 iptables -A FORWARD -m state --state INVALID -j DROP55 iptables -A FORWARD -m conntrack --ctstate INVALID -j DROP 56 56 iptables -A FORWARD -p tcp -o $WAN --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu 57 iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT57 iptables -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT 58 58 59 59 # custom rules
Note:
See TracChangeset
for help on using the changeset viewer.
