summaryrefslogtreecommitdiff
path: root/root/etc/firewall.sh
diff options
context:
space:
mode:
authorMike Baker <mbm@openwrt.org>2004-03-28 00:20:21 +0000
committerMike Baker <mbm@openwrt.org>2004-03-28 00:20:21 +0000
commitfee8556c06c10bfed0af070b604f47554a24306f (patch)
tree04569b929ee1a66b3a55263f075e6249870af6b6 /root/etc/firewall.sh
parent71112885432bfe29b67e802d8995566b652c2b20 (diff)
downloadmtk-20170518-fee8556c06c10bfed0af070b604f47554a24306f.zip
mtk-20170518-fee8556c06c10bfed0af070b604f47554a24306f.tar.gz
mtk-20170518-fee8556c06c10bfed0af070b604f47554a24306f.tar.bz2
inital commit of 20040316
SVN-Revision: 4
Diffstat (limited to 'root/etc/firewall.sh')
-rwxr-xr-xroot/etc/firewall.sh26
1 files changed, 26 insertions, 0 deletions
diff --git a/root/etc/firewall.sh b/root/etc/firewall.sh
new file mode 100755
index 0000000..805aa3f
--- /dev/null
+++ b/root/etc/firewall.sh
@@ -0,0 +1,26 @@
+#!/bin/sh
+
+IPT=/usr/sbin/iptables
+
+for T in filter nat mangle ; do
+ $IPT -t $T -F
+ $IPT -t $T -X
+done
+
+$IPT -t filter -A INPUT -m state --state INVALID -j DROP
+$IPT -t filter -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
+$IPT -t filter -A INPUT -p icmp -j ACCEPT
+$IPT -t filter -A INPUT -i vlan1 -p tcp -j REJECT --reject-with tcp-reset
+$IPT -t filter -A INPUT -i vlan1 -j REJECT --reject-with icmp-port-unreachable
+$IPT -t filter -A FORWARD -m state --state INVALID -j DROP
+$IPT -t filter -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
+$IPT -t filter -A FORWARD -i vlan1 -m state --state NEW,INVALID -j DROP
+
+$IPT -t nat -A POSTROUTING -o vlan1 -j MASQUERADE
+
+echo "1" >/proc/sys/net/ipv4/ip_forward
+echo "1" >/proc/sys/net/ipv4/icmp_echo_ignore_broadcasts
+echo "1" >/proc/sys/net/ipv4/icmp_ignore_bogus_error_responses
+echo "30" >/proc/sys/net/ipv4/tcp_fin_timeout
+echo "120" >/proc/sys/net/ipv4/tcp_keepalive_time
+echo "0" >/proc/sys/net/ipv4/tcp_timestamps