Name
Allow-DHCP-Renew
|
Match
IPv4-udp From any host in wan To any router IP at port 68 on this device
|
Action
Accept input
|
|
off
on
|
Name
Allow-Ping
|
Match
IPv4-icmp with type echo-request From any host in wan To any router IP on this device
|
Action
Accept input
|
|
off
on
|
Name
Allow-IGMP
|
Match
IPv4-igmp From any host in wan To any router IP on this device
|
Action
Accept input
|
|
off
on
|
Name
Allow-DHCPv6
|
Match
IPv6-udp From IP range fc00::/6 in wan To IP range fc00::/6 at port 546 on this device
|
Action
Accept input
|
|
off
on
|
Name
Allow-MLD
|
Match
IPv6-icmp with types 130/0, 131/0, 132/0, 143/0 From IP range fe80::/10 in wan To any router IP on this device
|
Action
Accept input
|
|
off
on
|
Name
Allow-ICMPv6-Input
|
Match
IPv6-icmp with types echo-request, echo-reply, destination-unreachable, packet-too-big, time-exceeded, bad-header, unknown-header-type, router-solicitation, neighbour-solicitation, router-advertisement, neighbour-advertisement From any host in wan To any router IP on this device
|
Action
Accept input and limit to 1000 pkts. per second
|
|
off
on
|
Name
Allow-ICMPv6-Forward
|
Match
IPv6-icmp with types echo-request, echo-reply, destination-unreachable, packet-too-big, time-exceeded, bad-header, unknown-header-type From any host in wan To any host in any zone
|
Action
Accept forward and limit to 1000 pkts. per second
|
|
off
on
|
Name
Allow-IPSec-ESP
|
Match
Any esp From any host in wan To any host in lan
|
Action
Accept forward
|
|
off
on
|
Name
Allow-ISAKMP
|
Match
Any udp From any host in wan To any host, port 500 in lan
|
Action
Accept forward
|
|
off
on
|
Name
Enable_SSH_WAN
|
Match
Any tcp From any host in wan To any router IP at port 22 on this device
|
Action
Accept input
|
|
off
on
|
Name
Enable_HTTP_WAN
|
Match
Any tcp From any host in wan To any router IP at port 80 on this device
|
Action
Accept input
|
|
off
on
|
Name
Enable_HTTPS_WAN
|
Match
Any tcp From any host in wan To any router IP at port 443 on this device
|
Action
Accept input
|
|
off
on
|
Name
Enable_CLI_WAN
|
Match
Any tcp From any host in wan To any router IP at ports 4200-4220 on this device
|
Action
Accept input
|
|
off
on
|
Name
Allow-openvpn-traffic
|
Match
IPv4-tcp, udp From any host in wan To any router IP at port 2295 on this device
|
Action
Accept input
|
|
off
on
|