· 6 years ago · Feb 12, 2020, 12:38 PM
1./ 0000755 0000000 0000000 00000000000 13576167314 007700 5 ustar ubnt ubnt ./firewall 0000644 0000000 0000000 00000003263 13576167314 011434 0 ustar ubnt ubnt
2config defaults 'default'
3 option syn_flood '1'
4 option input 'ACCEPT'
5 option output 'ACCEPT'
6 option forward 'REJECT'
7
8config zone 'lan'
9 option name 'lan'
10 list network 'lan'
11 option input 'ACCEPT'
12 option output 'ACCEPT'
13 option forward 'ACCEPT'
14
15config zone 'wan'
16 option name 'wan'
17 list network 'wan'
18 list network 'wan6'
19 option input 'REJECT'
20 option output 'ACCEPT'
21 option forward 'REJECT'
22 option masq '1'
23 option mtu_fix '1'
24
25config forwarding 'lan2wanfwd'
26 option enabled '1'
27 option src 'lan'
28 option dest 'wan'
29
30config forwarding 'wan2lanfwd'
31 option enabled '0'
32 option src 'wan'
33 option dest 'lan'
34
35config rule 'wan_icmp'
36 option name 'Allow-Ping'
37 option src 'wan'
38 option proto 'icmp'
39 option icmp_type 'echo-request'
40 option family 'ipv4'
41 option target 'ACCEPT'
42 option enabled '0'
43
44config rule 'wan_ssh'
45 option name 'Allow-SSH'
46 option src 'wan'
47 option dest_port '22'
48 option target 'ACCEPT'
49 option proto 'tcp'
50 option enabled '0'
51
52config rule 'wan_www'
53 option name 'Allow-Web'
54 option src 'wan'
55 option dest_port '80 443'
56 option target 'ACCEPT'
57 option proto 'tcp'
58 option enabled '0'
59
60config rule 'wan_discovery'
61 option name 'Allow-Discovery'
62 option src 'wan'
63 option dest_port '10001'
64 option target 'ACCEPT'
65 option proto 'all'
66 option enabled '0'
67
68config zone 'mgt'
69 option name 'mgt'
70 list network 'mgt'
71 list network 'mgt6'
72 option input 'ACCEPT'
73 option output 'ACCEPT'
74 option forward 'DROP'
75 option enabled '1'
76
77config include 'ubnt'
78 option type 'script'
79 option path '/etc/firewall.ubnt'
80 option family 'any'
81 option reload '1'
82
83config include 'miniupnpd'
84 option type 'script'
85 option path '/usr/share/miniupnpd/firewall.include'
86 option family 'any'
87 option reload '1'
88
89