Milí majitelé routerů Turris,
toto fórum bylo 9. 12. 2016 zmrazeno a nahrazeno naším novým Turris fórem. Ještě chvíli bude dostupné k prohlížení, ale již zde není možné přispívat. Více informací naleznete v oznámení o uzavření fóra.
Dear Turris routers users,
this forum has been frozen on Dec 9th, 2016 and replaced by our new Turris forum. It will be read-only accessible for some time after. For more information, read the announcement about closing the forum.
config rule
option name 'Allow-DNS-reply'
option src 'wan'
option proto 'tcpudp'
option src_port '53'
option target 'ACCEPT'
Chain delegate_forward (1 references) pkts bytes target prot opt in out source destination 46889 18M forwarding_rule all -- * * 0.0.0.0/0 0.0.0.0/0 /* user chain for forwarding */ 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED 21927 14M zone_lan_forward all -- br-lan * 0.0.0.0/0 0.0.0.0/0 24962 3935K zone_wan_forward all -- eth2 * 0.0.0.0/0 0.0.0.0/0 0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0 Chain delegate_input (1 references) pkts bytes target prot opt in out source destination 173 44083 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0 1794 252K input_rule all -- * * 0.0.0.0/0 0.0.0.0/0 /* user chain for input */ 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED 74 3300 syn_flood tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02 1794 252K ucollect_fake_accept all -- * * 0.0.0.0/0 0.0.0.0/0 869 82493 zone_lan_input all -- br-lan * 0.0.0.0/0 0.0.0.0/0 925 169K zone_wan_input all -- eth2 * 0.0.0.0/0 0.0.0.0/0 0 0 accept all -- * * 0.0.0.0/0 0.0.0.0/0 Chain delegate_output (1 references) pkts bytes target prot opt in out source destination 173 44083 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0 3426 830K output_rule all -- * * 0.0.0.0/0 0.0.0.0/0 /* user chain for output */ 196 56260 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED 1061 587K zone_lan_output all -- * br-lan 0.0.0.0/0 0.0.0.0/0 2169 187K zone_wan_output all -- * eth2 0.0.0.0/0 0.0.0.0/0 0 0 accept all -- * * 0.0.0.0/0 0.0.0.0/0
option conntrack '1'
do nastavení zón a začne to fungovat správně. Dá se to opravdu vyčíst v dokumentaci nastavení firewallu na stránkách OpenWRT.
Powered by mwForum 2.29.3 © 1999-2013 Markus Wichitill