@
internelp #23 只是能 ping 吧,这是我 padavan 里面默认的 ip6tables 规则,只允许转发了 ICMP6.,546 547 是 DHCPv6 用,没有其他能用的规则。
想要指定特定地址可被访问,需要加入
-A FORWARD -d ::xxxx/::ffff:ffff:ffff:ffff -j ACCEPT
# ip6tables-save
# Generated by ip6tables-save v1.4.16.3 on Mon Dec 24 19:10:59 2018
*filter
:INPUT DROP [0:0]
:FORWARD DROP [19:2254]
:OUTPUT ACCEPT [35640:5842391]
:bfplimit - [0:0]
:upnp - [0:0]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i br0 -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p ipv6-icmp -j ACCEPT
-A INPUT -m state --state INVALID -j DROP
-A INPUT -p udp -m udp --sport 547 --dport 546 -j ACCEPT
-A FORWARD -i br0 -o br0 -j ACCEPT
-A FORWARD ! -o br0 -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -p ipv6-icmp -j ACCEPT
-A FORWARD -m state --state INVALID -j DROP
-A FORWARD -i br0 -j ACCEPT
-A FORWARD -j upnp