本帖最後由 角色 於 2013-3-2 12:16 編輯
Default /etc/config/firewall (removed settings for IP6)- config defaults
- option syn_flood 1
- option input ACCEPT
- option output ACCEPT
- option forward REJECT
- config zone
- option name lan
- option network 'lan'
- option input ACCEPT
- option output ACCEPT
- option forward REJECT
- config zone
- option name wan
- option network 'wan'
- option input REJECT
- option output ACCEPT
- option forward REJECT
- option masq 1
- option mtu_fix 1
- config forwarding
- option src lan
- option dest wan
- # We need to accept udp packets on port 68,
- # see https://dev.openwrt.org/ticket/4108
- config rule
- option name Allow-DHCP-Renew
- option src wan
- option proto udp
- option dest_port 68
- option target ACCEPT
- option family ipv4
- # Allow IPv4 ping
- config rule
- option name Allow-Ping
- option src wan
- option proto icmp
- option icmp_type echo-request
- option family ipv4
- option target ACCEPT
- # include a file with users custom iptables rules
- config include
- option path /etc/firewall.user
複製代碼 但是用iptables -L去查看整个firewall是怎样,真的吓一大跳! |