Changeset b68978d in freewrt for package/iptables/files


Ignore:
Timestamp:
Aug 17, 2025, 12:45:07 PM (4 months ago)
Author:
Waldemar Brodkorb <wbx@…>
Branches:
freewrt_2_0
Children:
f15c9543
Parents:
b07a1b5
git-author:
Waldemar Brodkorb <wbx@…> (08/17/25 12:44:26)
git-committer:
Waldemar Brodkorb <wbx@…> (08/17/25 12:45:07)
Message:

make the FreeWRT firewall script work, needs more cleanup

File:
1 edited

Legend:

Unmodified
Added
Removed
  • package/iptables/files/firewall.conf

    rb07a1b5 rb68978d  
    44exit 1
    55### Interfaces
    6 WAN=ppp0
    7 LAN=br0
    8 WLAN=eth1
     6WAN=eth0.1
     7LAN=eth0.0
     8WLAN=wlan0
    99
    1010######################################################################
     
    2626
    2727# base case
    28 iptables -A INPUT -m state --state INVALID -j DROP
    29 iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
    30 iptables -A INPUT -p tcp --tcp-flags SYN SYN --tcp-option \! 2 -j DROP
     28iptables -A INPUT -m conntrack --ctstate INVALID -j DROP
     29iptables -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
     30iptables -A INPUT -p tcp --tcp-flags SYN SYN \! --tcp-option 2 -j DROP
    3131
    3232# custom rules
     
    4646
    4747# base case
    48 iptables -A OUTPUT -m state --state INVALID -j DROP
    49 iptables -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
     48iptables -A OUTPUT -m conntrack --ctstate INVALID -j DROP
     49iptables -A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
    5050
    5151### FORWARD
     
    5353
    5454# base case
    55 iptables -A FORWARD -m state --state INVALID -j DROP
     55iptables -A FORWARD -m conntrack --ctstate INVALID -j DROP
    5656iptables -A FORWARD -p tcp -o $WAN --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
    57 iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
     57iptables -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
    5858
    5959# custom rules
Note: See TracChangeset for help on using the changeset viewer.