diff options
Diffstat (limited to 'package/network/config/firewall/files')
-rw-r--r-- | package/network/config/firewall/files/firewall.config | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/package/network/config/firewall/files/firewall.config b/package/network/config/firewall/files/firewall.config index a87413904..6acfe1e86 100644 --- a/package/network/config/firewall/files/firewall.config +++ b/package/network/config/firewall/files/firewall.config @@ -95,6 +95,25 @@ config rule option family ipv6 option target ACCEPT +# Block ULA-traffic from leaking out +config rule + option name Enforce-ULA-Border-Src + option src * + option dest wan + option proto all + option src_ip fc00::/7 + option family ipv6 + option target REJECT + +config rule + option name Enforce-ULA-Border-Dest + option src * + option dest wan + option proto all + option dest_ip fc00::/7 + option family ipv6 + option target REJECT + # include a file with users custom iptables rules config include option path /etc/firewall.user |