diff options
Diffstat (limited to 'package/network')
| -rw-r--r-- | package/network/config/firewall/Makefile | 2 | ||||
| -rw-r--r-- | package/network/config/firewall/files/firewall.config | 19 | 
2 files changed, 20 insertions, 1 deletions
diff --git a/package/network/config/firewall/Makefile b/package/network/config/firewall/Makefile index 4d7970a50..1cfc734a3 100644 --- a/package/network/config/firewall/Makefile +++ b/package/network/config/firewall/Makefile @@ -9,7 +9,7 @@ include $(TOPDIR)/rules.mk  PKG_NAME:=firewall  PKG_VERSION:=2 -PKG_RELEASE:=55 +PKG_RELEASE:=56  include $(INCLUDE_DIR)/package.mk diff --git a/package/network/config/firewall/files/firewall.config b/package/network/config/firewall/files/firewall.config index a87413904..6acfe1e86 100644 --- a/package/network/config/firewall/files/firewall.config +++ b/package/network/config/firewall/files/firewall.config @@ -95,6 +95,25 @@ config rule  	option family		ipv6  	option target		ACCEPT +# Block ULA-traffic from leaking out +config rule +	option name		Enforce-ULA-Border-Src +	option src		* +	option dest		wan +	option proto		all +	option src_ip		fc00::/7 +	option family		ipv6 +	option target		REJECT + +config rule +	option name		Enforce-ULA-Border-Dest +	option src		* +	option dest		wan +	option proto		all +	option dest_ip		fc00::/7 +	option family		ipv6 +	option target		REJECT +  # include a file with users custom iptables rules  config include  	option path /etc/firewall.user  | 
