Buona sera, apro un topic dedicato al caso, magari poi può interessare anche a qualcun'altro...
In poche parole, avrei uan becessità un pò particolare: DGA4132 con modulo SFP in bridge con DSLAM, dalla SFP passa tutto il traffico ad un router mikrotik ( sempre SFP) che mi fa autenticazione pppoe verso il mio gestore.
Pe ril momento, dopo averlo ribaltato come un calzino, perso un paio di volte il root, dovuto downgradare etc etc, mi sono limitato a fare alcuni test e a fare poche piccole modifiche, per vitare di perdere la connessione al router. Premetto che il router è rooted e installata Luci, anche se a poco mi serve.
Intanto, ho messo la eth4 (che dovrebbe essere la porta SFP) sul bridge LAN delle porte ethernet, assieme a ptm0 che mi serve per connettermi al dslam.
IN questo modo, passando dalal SFP, riesco ad accedere al router in ssh, ma non ho conessione verso la dslam. Se faccio un pppoe-scan dal router mikrotik, non vedo la macchina server pppoe del mio gestore e quindi non mi connetto.
Se invece mi collego in eth tramite una delle porte eth, facendo pppoe-scan vedo la macchina server del mio gestore, quindi il bridge con ptm0 è instaurato e ovviamente mi connetto anche, ma la mia necessità è quella di fare il medesimo lavoro ma usando la SFP.
dopo aver fatto diversi casini e ripristinato di conseguenza, mi sono accorto che un punto fondamentale per il quale perdevo accesso dalla porta SFP era agendo sul file /etc/config/ethernet
config port 'eth0'
option enable '1'
option speed 'auto'
option duplex 'full'
config port 'eth1'
option enable '1'
option speed 'auto'
option duplex 'full'
config port 'eth2'
option enable '1'
option speed 'auto'
option duplex 'full'
config port 'eth3'
option enable '1'
option speed 'auto'
option duplex 'full'
config port 'eth4'
option enable '1'
option speed 'auto'
option duplex 'full'
option wan '1'
config port 'eth5'
option enable '1'
option speed 'auto'
option duplex 'full'
config mapping
option port 'eth5'
option wlan_remote '1'
config globals 'globals'
option eth4lanwanmode '0'
ho pensato di eliminare quella voce
option wan '1' dalla porta eth4, ma eliminantolo o semplicemente modificando il '1' in '0', perdo la connessione dalla SFP. Non riesco a capire il perchè, avendola messa in bridge LAN.
Grazie infinite per gli eventuali aiuti, se riesco in questa opera, mi rispario di sacrificare un porta eth del router mikrotik, che mi servirebbe per altro.
Posto anche il resto delle config:
/etc/config/network
config interface 'loopback'
option ifname 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config globals 'globals'
option ula_prefix 'none'
option default_ps '0'
#config device 'waneth4'
# option type '8021q'
# option name 'waneth4'
# option macaddr 'A4:91:B1:33:B8:B8'
# option ifname 'eth4'
# option vid '835'
# option ipv6 '0'
config device 'wanptm0'
option type '8021q'
option name 'wanptm0'
option macaddr 'A4:91:B1:33:B8:B8'
option ifname 'ptm0'
option vid '835'
option ipv6 '0'
config interface 'wan'
option proto 'pppoe'
option demand '0'
option ifname '<set by script>'
option username '[email protected]'
option password 'alicenewag'
option macaddr 'A4:91:B1:33:B8:B8'
option ipv6 '0'
option peerdns '1'
option reqopts '1 3 6 15 33 42 51 121 249'
option keepalive_adaptive '0'
option dns_metric '0'
option enabled '0'
option auto '0'
config config 'config'
option wan_mode 'bridge'
config interface 'wwan'
option auto '1'
option proto 'mobiled'
option session_id '0'
option profile '1'
option enabled '0'
config interface 'wan6'
option proto 'dhcpv6'
option reqopts '12 21 22 23 24 25 31 56 64 67 82 83'
option noslaaconly '1'
option iface_464xlat '0'
option auto '0'
option dns_metric '20'
option ifname '@wan_ipv6'
option enabled '0'
config interface 'lan'
option type 'bridge'
option proto 'static'
option netmask '255.255.255.0'
option ip6assign '64'
option force_link '0'
option ipv6 '0'
option pppoerelay '<set by script>'
option ipaddr '192.168.20.1'
option _orig_ifname 'eth0 eth1 eth2 eth3 eth5 ptm0.835 radio_2G.network1 radio_5G.network1'
option _orig_bridge 'true'
option ifname 'eth0 eth1 eth2 eth3 eth4 eth5 ptm0 ptm0.835 radio_2G.network1 radio_5G.network1'
config switch 'bcmsw'
option reset '1'
option enable_vlan '0'
option qosimppauseenable '0'
option jumbo '0'
config interface 'wlnet_b_24'
option proto 'static'
option ip6assign '64'
option ipv6 '0'
option ip6hint '1'
option netmask '255.255.255.128'
option ipaddr '192.168.168.1'
option ifname 'wl0_1'
option force_link '0'
option name 'Ospiti-TIM-20166841'
config interface 'wlnet_b_5'
option proto 'static'
option ip6assign '64'
option ipv6 '0'
option ip6hint '2'
option netmask '255.255.255.128'
option ipaddr '192.168.168.129'
option ifname 'wl1_1'
option force_link '0'
option name 'Ospiti-TIM-20166841'
config device 'wlnet_b_5eth5'
option type '8021q'
option name 'wl1_1'
option enabled '1'
option ifname 'eth5'
option vid '3'
option ipv6 '0'
config interface 'wan_ipv6'
option auto '0'
option proto 'pppoe'
option demand '0'
option password 'IPV6@alice6'
option macaddr 'A4:91:B1:33:B8:B8'
option ipv6 '1'
option peerdns '1'
option keepalive_adaptive '0'
option dns_metric '0'
option ifname 'wanptm0'
option username '[email protected]'
option metric '10'
config interface 'ipoe'
option proto 'dhcp'
option metric '1'
option reqopts '1 3 6 43 51 58 59'
option release '1'
option neighreachabletime '1200000'
option neighgcstaletime '2400'
option ipv6 '1'
/etc/config/qos
#Internal Classification Labels
config label 'Normal'
option trafficid '1'
config label 'Interactive'
option trafficid '2'
config label 'Network_Control'
option trafficid '3'
config label 'Video_Data'
option trafficid '4'
config label 'Video_Sig'
option trafficid '5'
config label 'Management'
option trafficid '6'
config label 'Voice_Data'
option trafficid '7'
config label 'Voice_Sig'
option trafficid '8'
#Qos Class Definition (queue's)
#TO_WAN
config class 'W_Q0'
option weight '7'
config class 'W_Q1'
list trafficid '2'
option weight '7'
config class 'W_Q2'
list trafficid '3'
option weight '14'
config class 'W_Q3'
list trafficid '4'
option weight '14'
config class 'W_Q4'
list trafficid '5'
option weight '27'
config class 'W_Q5'
list trafficid '6'
option weight '27'
config class 'W_Q6'
list trafficid '7'
option priority '1'
option weight '52'
config class 'W_Q7'
list trafficid '8'
option priority '1'
option weight '52'
#TO_LAN
config class 'L_Q0'
option priority '0'
config class 'L_Q1'
list trafficid '4'
list trafficid '5'
option priority '1'
config class 'L_Q2'
list trafficid '6'
option priority '2'
config class 'L_Q3'
list trafficid '7'
list trafficid '8'
option priority '3'
#TO_WLAN
config class 'WMM_BK_Q0'
option priority '0'
config class 'WMM_BK_Q1'
option priority '1'
config class 'WMM_BE_Q0'
option priority '2'
config class 'WMM_BE_Q1'
list trafficid '4'
option priority '3'
config class 'WMM_VI_Q0'
list trafficid '5'
option priority '4'
config class 'WMM_VI_Q1'
list trafficid '6'
option priority '5'
config class 'WMM_VO_Q0'
list trafficid '7'
option priority '6'
config class 'WMM_VO_Q1'
list trafficid '8'
option priority '7'
#Qos Classgroup Definition
config classgroup 'TO_WAN'
option classes 'W_Q0 W_Q1 W_Q2 W_Q3 W_Q4 W_Q5 W_Q6 W_Q7'
option default 'W_Q0'
option policy 'sp_wrr'
config classgroup 'TO_LAN'
option classes 'L_Q0 L_Q1 L_Q2 L_Q3'
option default 'L_Q0'
option policy 'sp'
config classgroup 'TO_WLAN'
option classes 'WMM_BE_Q0 WMM_BK_Q0 WMM_BK_Q1 WMM_BE_Q1 WMM_VI_Q0 WMM_VI_Q1 WMM_VO_Q0 WMM_VO_Q1'
option default 'WMM_BE_Q0'
option policy 'sp'
config interface 'lan'
option classgroup 'TO_LAN'
config interface 'wan'
option classgroup 'TO_WAN'
config interface 'wlnet_b_24'
option classgroup 'TO_WLAN'
config interface 'wlnet_b_5'
option classgroup 'TO_WLAN'
# Devices
#config device 'waneth4'
# option pcp '5'
# option force_pcp '0'
config device 'atmwan'
option classgroup 'TO_WAN'
config device 'ptm0'
option classgroup 'TO_WAN'
#config device 'eth4'
# option classgroup 'TO_WAN'
config device 'wl0'
option classgroup 'TO_WLAN'
config device 'wl1'
option classgroup 'TO_WLAN'
#QoS classification rules (only IPv4 classification present due to lack of IPv6 configuration plane)
#IMPORTANT NOTE: Make sure that the order in which the rules are defined is from Lowest Priority to Highest Priority!
config classify
option target 'Interactive'
option dstports '20,21,25,80,109,110,143,201,202,203,204,205,206,220,387'
option proto 'tcp'
config classify
option target 'Interactive'
option dstports '20,21,25,80,109,110,143,201,202,203,204,205,206,220,387'
option proto 'udp'
config classify
option target 'Interactive'
option dstports '443,500,993,995,1701,1935,3074,3478,3479,3480,3658,4500,8080,37483'
option proto 'tcp'
config classify
option target 'Interactive'
option dstports '443,500,993,995,1701,1935,3074,3478,3479,3480,3658,4500,8080,37483'
option proto 'udp'
config classify
option target 'Network_Control'
option proto 'icmp'
option proto_option 'icmp-type=redirect'
config classify
option target 'Network_Control'
option proto 'igmp'
config classify
option target 'Network_Control'
option dstports '22,23,53,67,68,123'
option proto 'tcp'
config classify
option target 'Network_Control'
option dstports '22,23,53,67,68,123'
option proto 'udp'
config classify
option target 'Network_Control'
option proto 'esp'
config classify
option target 'Network_Control'
option proto 'ah'
#VPN's
config classify
option target 'Network_Control'
option proto 'gre'
# helper match requires reclassify
config reclassify
option target 'Video_Data'
option helper 'rtsp'
config classify
option target 'Video_Sig'
option dstports '554'
option proto 'tcp'
#IMPORTANT NOTE: Static config of dport 7170 for cwmpd is broken once acs url is provisioned using another port via dhcpv4 option 43
config classify
option target 'Management'
option ports '7170,10500,10700'
option proto 'tcp'
list srcif 'loopback'
list dstif 'wan'
# helper match requires reclassify
config reclassify
option target 'Voice_Data'
option helper 'sip'
config classify
option target 'Voice_Sig'
option dstports '5060'
option proto 'tcp'
config classify
option target 'Voice_Sig'
option dstports '5060'
option proto 'udp'
# for TI WAN side
#R.122
config classify
option target 'Video_Data'
list dscp '0x18'
list srcif 'lan'
list dstif 'wan'
#R.122
config classify
option target 'Voice_Sig'
list dscp '0x28'
list srcif 'lan'
list dstif 'wan'
config classify
option target 'Voice_Sig'
list dscp '0x28'
list srcif 'loopback'
list dstif 'wan'
# DSCP overwrite requires reclassify for TI
config label 'dscp_Zero'
option dscp '0'
option pcp '0'
config reclassify
option target 'dscp_Zero'
list dscp '!0x18'
list dscp '!0x28'
list srcif 'loopback'
list srcif 'lan'
list srcif 'wl0'
list srcif 'wl1'
list srcif 'wlnet_b_24'
list srcif 'wlnet_b_5'
list dstif 'wan'
config label 'pcp_5'
option pcp '5'
config reclassify
option target 'pcp_5'
list dscp '0x28'
list dstif 'wan'
config label 'pcp_3'
option pcp '3'
config reclassify
option target 'pcp_3'
list dscp '0x18'
list dstif 'wan'
config label 'pcp_6'
option pcp '6'
config reclassify
option target 'pcp_6'
option ports '7170,10500,10700'
option proto 'tcp'
list srcif 'loopback'
list dstif 'wan'
/etc/config/firewall
config defaults
option syn_flood '1'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
option drop_invalid '1'
config zone 'lan'
option name 'lan'
list network 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
option mtu_fix '1'
option wan '0'
config zone 'wan'
option name 'wan'
list network 'wan'
list network 'wan6'
list network 'wwan'
option input 'DROP'
option output 'ACCEPT'
option forward 'DROP'
option masq '1'
option conntrack '1'
option mtu_fix '1'
option wan '1'
config forwarding 'lan_wan'
option src 'lan'
option dest 'wan'
config zone 'z_wlnetb24'
option name 'z_wlnetb24'
list network 'wlnet_b_24'
option input 'DROP'
option output 'ACCEPT'
option forward 'REJECT'
option mtu_fix '1'
option wan '0'
config forwarding 'for_wlnetb24'
option src 'z_wlnetb24'
option dest 'wan'
config rule 'Drop_non_TCP_SYN'
option name 'Drop_non_TCP_SYN'
option src 'wan'
option dest '*'
option proto 'tcp'
option target 'DROP'
option extra '! --tcp-flags ALL SYN'
config rule 'drop_lan_2_z_wlnetb24'
option name 'drop_lan_2_z_wlnetb24'
option src 'lan'
option dest 'z_wlnetb24'
option proto 'all'
option target 'DROP'
config rule 'drop_z_wlnetb24_2_lan'
option name 'drop_z_wlnetb24_2_lan'
option src 'z_wlnetb24'
option dest 'lan'
option proto 'all'
option target 'DROP'
config rule 'drop_lan_2_z_wlnetb24_GW'
option name 'drop-lan_2_z_wlnetb24_GW'
option src 'lan'
option proto 'all'
option target 'DROP'
option family 'ipv4'
option dest_ip '192.168.168.1'
config rule 'Allow_z_wlnetb24_ICMP'
option name 'Allow_z_wlnetb24_ICMP'
option src 'z_wlnetb24'
option proto 'igmp'
option target 'ACCEPT'
option family 'ipv4'
option dest_ip '192.168.168.1'
config rule 'Allow_z_wlnetb24_DHCP'
option name 'Allow_z_wlnetb24_DHCP'
option src 'z_wlnetb24'
option proto 'udp'
option dest_port '67'
option target 'ACCEPT'
option family 'ipv4'
config rule 'Allow_z_wlnetb24_DNS'
option name 'Allow_z_wlnetb24_DNS'
option src 'z_wlnetb24'
option proto 'udp'
option dest_port '53'
option target 'ACCEPT'
option family 'ipv4'
config rule 'Allow_z_wlnetb24_ICMPv6'
option name 'Allow-z_wlnetb24_ICMPv6'
option src 'z_wlnetb24'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config zone 'z_wlnetb5'
option name 'z_wlnetb5'
list network 'wlnet_b_5'
option input 'DROP'
option output 'ACCEPT'
option forward 'REJECT'
option wan '0'
config forwarding 'for_wlnetb5'
option src 'z_wlnetb5'
option dest 'wan'
config rule 'drop_lan_2_z_wlnetb5'
option name 'drop_lan_2_z_wlnetb5'
option src 'lan'
option dest 'z_wlnetb5'
option proto 'all'
option target 'DROP'
config rule 'drop_z_wlnetb5_2_lan'
option name 'drop_z_wlnetb5_2_lan'
option src 'z_wlnetb5'
option dest 'lan'
option proto 'all'
option target 'DROP'
config rule 'drop_lan_2_z_wlnetb5_GW'
option name 'drop-lan_2_z_wlnetb5_GW'
option src 'lan'
option proto 'all'
option target 'DROP'
option family 'ipv4'
option dest_ip '192.168.168.129'
config rule 'Allow_z_wlnetb5_ICMP'
option name 'Allow_z_wlnetb5_ICMP'
option src 'z_wlnetb5'
option proto 'igmp'
option target 'ACCEPT'
option family 'ipv4'
option dest_ip '192.168.168.129'
config rule 'Allow_z_wlnetb5_DHCP'
option name 'Allow_z_wlnetb5_DHCP'
option src 'z_wlnetb5'
option proto 'udp'
option dest_port '67'
option target 'ACCEPT'
option family 'ipv4'
config rule 'Allow_z_wlnetb5_DNS'
option name 'Allow_z_wlnetb5_DNS'
option src 'z_wlnetb5'
option proto 'udp'
option dest_port '53'
option target 'ACCEPT'
option family 'ipv4'
config rule 'Allow_z_wlnetb5_ICMPv6'
option name 'Allow-z_wlnetb5_ICMPv6'
option src 'z_wlnetb5'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule 'rule1'
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule 'rule2'
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule 'rule3'
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option src_ip 'fc00::/6'
option dest_ip 'fc00::/6'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule 'rule4'
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule 'rule5'
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule 'rule6'
option name 'access_2_LAN_IP'
option src 'lan'
option proto 'tcp'
option family 'ipv4'
option extra '-m multiport --dports 80,22,8080,443,8443 -m addrtype --limit-iface-in ! --dst-type LOCAL'
option target 'REJECT'
config rule 'rule7'
option name 'close_port_139'
option src 'wan'
option proto 'tcp'
option dest_port '139'
option family 'ipv4'
option target 'DROP'
config rule 'rule8'
option name 'close_port_445'
option src 'wan'
option proto 'tcp'
option dest_port '445'
option family 'ipv4'
option target 'DROP'
config rule 'rule9'
option name 'Deny-CUPS-lan'
option src 'lan'
option proto 'tcp'
option dest_port '631'
option family 'ipv4'
option target 'DROP'
config rule 'rule10'
option name 'Deny-CUPS-wan'
option src 'wan'
option proto 'tcp'
option dest_port '631'
option family 'ipv4'
option target 'DROP'
config rule 'rule11'
option name 'Deny-CUPS-lan-v6'
option src 'lan'
option proto 'tcp'
option dest_port '631'
option family 'ipv6'
option target 'DROP'
config rule 'rule12'
option name 'Deny-CUPS-wan-v6'
option src 'wan'
option proto 'tcp'
option dest_port '631'
option family 'ipv6'
option target 'DROP'
config rule 'rule13'
option name 'Allow-Ping6'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
option family 'ipv6'
option target 'ACCEPT'
option enabled '0'
config rule 'SSH_wan'
option name 'SSH_wan'
option src 'wan'
option proto 'tcp'
option dest_port '22'
option target 'DROP'
option family 'ipv4'
config rule
option name 'Restrict-TCP-LAN-Input'
option src 'lan'
option dest_ip '!lan'
option proto 'tcp'
option family 'ipv4'
option extra '-m mark --mark 0/0x8000000'
option target 'REJECT'
config include
option path '/etc/firewall.user'
config include 'tchext_restart'
option type 'script'
option path '/lib/functions/firewall-restart-ext-tch.sh'
config include 'tchext'
option type 'script'
option path '/lib/functions/firewall-ext-tch.sh'
option reload '1'
config cone 'cone1'
option name 'PS and XBox Live 1'
option src 'wan'
option dest_port '88'
config cone 'cone2'
option name 'PS and XBox Live 2'
option src 'wan'
option dest_port '3074:3658'
config cone 'cone3'
option name 'PS and XBox Live 3'
option src 'wan'
option dest_port '10070'
config cone 'cone4'
option name 'PS and XBox Live 4'
option src 'wan'
option dest_port '4500'
config include 'tod'
option type 'script'
option path '/lib/functions/tod.sh'
option reload '1'
config include 'intercept'
option type 'script'
option path '/usr/lib/intercept/firewall.sh'
config fwconfig 'fwconfig'
option defaultoutgoing_lax 'ACCEPT'
option defaultoutgoing_normal 'ACCEPT'
option defaultoutgoing_high 'DROP'
option defaultoutgoing_user 'ACCEPT'
option defaultincoming_lax 'REJECT'
option defaultincoming_normal 'DROP'
option defaultincoming_high 'DROP'
option defaultincoming_user 'DROP'
option level 'normal'
config rulesgroup 'pinholerules'
option enabled '1'
option name 'FW rules for opening pinholes'
option type 'pinholerule'
config redirectsgroup 'userredirects'
option enabled '1'
option name 'FW redirects defined by the user'
option type 'userredirect'
config redirectsgroup 'dmzredirects'
option enabled '0'
option name 'FW redirects for the DMZ functionality'
option type 'dmzredirect'
config dmzredirect 'dmzredirect'
option name 'DMZ rule'
option src 'wan'
option dest 'lan'
option family 'ipv4'
option target 'DNAT'
option proto 'tcpudp'
config rulesgroup 'normalrules'
option enabled '1'
option name 'FW rules for normal level'
option type 'normalrule'
config rulesgroup 'laxrules'
option enabled '0'
option name 'FW rules for lax level'
option type 'laxrule'
config rulesgroup 'highrules'
option enabled '0'
option name 'FW rules for high level'
option type 'highrule'
config rulesgroup 'userrules'
option enabled '0'
option name 'FW rules for user level'
option type 'userrule'
config rulesgroup 'userrules_v6'
option enabled '0'
option name 'FW rules for user level IPv6'
option type 'userrule_v6'
config rulesgroup 'defaultrules'
option enabled '1'
option name 'FW rules for default behavior'
option type 'defaultrule'
config highrule 'highrule1'
option name 'HTTP'
option src 'lan'
option dest 'wan'
option proto 'tcp'
option dest_port '80'
option target 'ACCEPT'
config highrule 'highrule2'
option name 'HTTPS'
option src 'lan'
option dest 'wan'
option proto 'tcp'
option dest_port '443'
option target 'ACCEPT'
config highrule 'highrule3'
option name 'SMTP'
option src 'lan'
option dest 'wan'
option proto 'tcp'
option dest_port '25'
option target 'ACCEPT'
config highrule 'highrule4'
option name 'POP3'
option src 'lan'
option dest 'wan'
option proto 'tcp'
option dest_port '110'
option target 'ACCEPT'
config highrule 'highrule5'
option name 'IMAP'
option src 'lan'
option dest 'wan'
option proto 'tcp'
option dest_port '445'
option target 'ACCEPT'
config highrule 'highrule6'
option name 'SSH'
option src 'lan'
option dest 'wan'
option proto 'tcp'
option dest_port '22'
option target 'ACCEPT'
config defaultrule 'defaultipv6incoming'
option name 'Default action for incoming IPv6 traffic'
option src 'wan'
option dest 'lan'
option proto 'all'
option family 'ipv6'
option target 'ACCEPT'
option enabled '0'
config defaultrule 'defaultipv6outgoing'
option name 'Default action for outgoing IPv6 traffic'
option src 'lan'
option dest 'wan'
option proto 'all'
option family 'ipv6'
option target 'ACCEPT'
option enabled '0'
config defaultrule 'defaultoutgoing'
option name 'Default action for outgoing NAT'
option src 'lan'
option dest 'wan'
option proto 'all'
option target 'ACCEPT'
config helper 'ftphelper'
option helper 'ftp'
option dest_port '21'
option proto 'tcp'
config helper 'tftphelper'
option helper 'tftp'
option dest_port '69'
option proto 'udp'
config helper 'snmphelper'
option helper 'snmp'
option family 'ipv4'
option dest_port '161'
option proto 'udp'
config helper 'pptphelper'
option helper 'pptp'
option family 'ipv4'
option dest_port '1723'
option proto 'tcp'
config helper 'siphelper'
option enable '0'
option helper 'sip'
option dest_port '5060'
option proto 'udp'
config helper 'siploopback'
option helper 'sip'
option dest_port '5060'
option proto 'udp'
option intf 'loopback'
config helper 'irchelper'
option helper 'irc'
option family 'ipv4'
option dest_port '6667'
option proto 'tcp'
config helper 'amandahelper'
option helper 'amanda'
option dest_port '10080'
option proto 'udp'
config helper 'rtsphelper'
option helper 'rtsp'
option dest_port '554'
option family 'ipv4'
option proto 'tcp'
config include 'dhcpsnooper'
option type 'script'
option path '/lib/functions/firewall-dhcpsnooper.sh'
option reload '0'
config include 'mmpbx'
option type 'script'
option path '/lib/functions/firewall-mmpbx.sh'
option reload '1'
config include 'dropbear'
option type 'script'
option path '/lib/functions/firewall-dropbear.sh'
option reload '1'
config include 'miniupnpd'
option type 'script'
option path '/usr/share/miniupnpd/firewall.include'
option family 'any'
option reload '1'