summaryrefslogtreecommitdiff
path: root/package/firewall
diff options
context:
space:
mode:
authorJo-Philipp Wich <jow@openwrt.org>2011-12-20 01:10:15 +0000
committerJo-Philipp Wich <jow@openwrt.org>2011-12-20 01:10:15 +0000
commit77dda8d67ac852b73bf60c8dec0fbb958168b7ea (patch)
tree1ee2443e5727863411a478e424734cfa625660ab /package/firewall
parent0cd03df3b12e7aa533239ef544bdd69c5512a433 (diff)
downloadmtk-20170518-77dda8d67ac852b73bf60c8dec0fbb958168b7ea.zip
mtk-20170518-77dda8d67ac852b73bf60c8dec0fbb958168b7ea.tar.gz
mtk-20170518-77dda8d67ac852b73bf60c8dec0fbb958168b7ea.tar.bz2
firewall: - introduce per-section "option enabled" which defaults to "1" - useful to disable rules or zones without having to delete them - annotate default traffic rules with names - bump version
SVN-Revision: 29577
Diffstat (limited to 'package/firewall')
-rw-r--r--package/firewall/Makefile2
-rw-r--r--package/firewall/files/firewall.config5
-rw-r--r--package/firewall/files/lib/config.sh6
3 files changed, 11 insertions, 2 deletions
diff --git a/package/firewall/Makefile b/package/firewall/Makefile
index 6106348..3c5e10f 100644
--- a/package/firewall/Makefile
+++ b/package/firewall/Makefile
@@ -9,7 +9,7 @@ include $(TOPDIR)/rules.mk
PKG_NAME:=firewall
PKG_VERSION:=2
-PKG_RELEASE:=42
+PKG_RELEASE:=43
include $(INCLUDE_DIR)/package.mk
diff --git a/package/firewall/files/firewall.config b/package/firewall/files/firewall.config
index 4ba165f..77832ff 100644
--- a/package/firewall/files/firewall.config
+++ b/package/firewall/files/firewall.config
@@ -29,6 +29,7 @@ config forwarding
# We need to accept udp packets on port 68,
# see https://dev.openwrt.org/ticket/4108
config rule
+ option name Allow-DHCP-Renew
option src wan
option proto udp
option dest_port 68
@@ -37,6 +38,7 @@ config rule
# Allow IPv4 ping
config rule
+ option name Allow-Ping
option src wan
option proto icmp
option icmp_type echo-request
@@ -46,6 +48,7 @@ config rule
# Allow DHCPv6 replies
# see https://dev.openwrt.org/ticket/10381
config rule
+ option name Allow-DHCPv6
option src wan
option proto udp
option src_ip fe80::/10
@@ -57,6 +60,7 @@ config rule
# Allow essential incoming IPv6 ICMP traffic
config rule
+ option name Allow-ICMPv6-Input
option src wan
option proto icmp
list icmp_type echo-request
@@ -73,6 +77,7 @@ config rule
# Allow essential forwarded IPv6 ICMP traffic
config rule
+ option name Allow-ICMPv6-Forward
option src wan
option dest *
option proto icmp
diff --git a/package/firewall/files/lib/config.sh b/package/firewall/files/lib/config.sh
index 996cef8..8b2399f 100644
--- a/package/firewall/files/lib/config.sh
+++ b/package/firewall/files/lib/config.sh
@@ -34,7 +34,11 @@ fw_config_get_section() { # <config> <prefix> <type> <name> <default> ...
export ${NO_EXPORT:+-n} -- "${prefix}NAME"="${config}"
config_get "${prefix}TYPE" "$config" TYPE
}
-
+
+ local enabled
+ config_get_bool enabled "$config" enabled 1
+ [ $enabled -eq 1 ] || return 1
+
[ "$1" == '{' ] && shift
while [ $# -ge 3 ]; do
local type=$1