forked from DGNum/liminix
allow dhcp client on wan
This commit is contained in:
parent
8affb151b5
commit
1f1164cc98
1 changed files with 11 additions and 0 deletions
|
@ -106,6 +106,16 @@ in {
|
||||||
(accept "tcp dport 22")
|
(accept "tcp dport 22")
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
|
input-wan = {
|
||||||
|
type = "filter";
|
||||||
|
family = "ip6";
|
||||||
|
|
||||||
|
rules = [
|
||||||
|
(accept "udp dport 546") # dhcp client, needed for prefix delegation
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
input-ip6 = {
|
input-ip6 = {
|
||||||
type = "filter";
|
type = "filter";
|
||||||
family = "ip6";
|
family = "ip6";
|
||||||
|
@ -114,6 +124,7 @@ in {
|
||||||
rules = [
|
rules = [
|
||||||
(accept "meta l4proto icmpv6")
|
(accept "meta l4proto icmpv6")
|
||||||
"iifname int jump input-lan"
|
"iifname int jump input-lan"
|
||||||
|
"iifname ppp0 jump input-wan"
|
||||||
(if allow-incoming
|
(if allow-incoming
|
||||||
then accept "oifname \"int\" iifname \"ppp0\""
|
then accept "oifname \"int\" iifname \"ppp0\""
|
||||||
else "oifname \"int\" iifname \"ppp0\" jump incoming-allowed-ip6"
|
else "oifname \"int\" iifname \"ppp0\" jump incoming-allowed-ip6"
|
||||||
|
|
Loading…
Reference in a new issue