ericbize
2021-07-04 22:15:04 +08:00
[admin@Home] > ipv6 firewall filter print
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; defconf: accept established,related,untracked
chain=input action=accept connection-state=established,related,untracked
1 ;;; defconf: drop invalid
chain=input action=drop connection-state=invalid
2 ;;; defconf: accept ICMPv6
chain=input action=accept protocol=icmpv6
3 ;;; defconf: accept UDP traceroute
chain=input action=accept protocol=udp port=33434-33534
4 ;;; defconf: accept DHCPv6-Client prefix delegation.
chain=input action=accept protocol=udp src-address=fe80::/16 dst-port=546
5 ;;; defconf: accept IKE
chain=input action=accept protocol=udp dst-port=500,4500
6 ;;; defconf: accept ipsec AH
chain=input action=accept protocol=ipsec-ah
7 ;;; defconf: accept ipsec ESP
chain=input action=accept protocol=ipsec-esp
8 ;;; defconf: accept all that matches ipsec policy
chain=input action=accept ipsec-policy=in,ipsec
9 ;;; defconf: drop everything else not coming from LAN
chain=input action=drop in-interface-list=!LAN
10 ;;; defconf: accept established,related,untracked
chain=forward action=accept connection-state=established,related,untracked
11 ;;; defconf: drop invalid
chain=forward action=drop connection-state=invalid
12 ;;; defconf: drop packets with bad src ipv6
chain=forward action=drop src-address-list=bad_ipv6
13 ;;; defconf: drop packets with bad dst ipv6
chain=forward action=drop dst-address-list=bad_ipv6
14 ;;; defconf: rfc4890 drop hop-limit=1
chain=forward action=drop protocol=icmpv6 hop-limit=equal:1
15 ;;; defconf: accept ICMPv6
chain=forward action=accept protocol=icmpv6
16 ;;; defconf: accept HIP
chain=forward action=accept protocol=139
17 ;;; defconf: accept IKE
chain=forward action=accept protocol=udp dst-port=500,4500
18 ;;; defconf: accept ipsec AH
chain=forward action=accept protocol=ipsec-ah
19 ;;; defconf: accept ipsec ESP
chain=forward action=accept protocol=ipsec-esp
20 ;;; defconf: accept all that matches ipsec policy
chain=forward action=accept ipsec-policy=in,ipsec
21 ;;; defconf: drop everything else not coming from LAN
chain=forward action=drop in-interface-list=!LAN