firewall
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| firewall [2018/05/09 00:41] – [4. rule段:规则配置] midas_zhou | firewall [2025/10/14 06:22] (current) – external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 11: | Line 11: | ||
| 域(zone)是一组网络接口,域可作为IP转发的源地或目的地来进行相应配置。这里主要是对wan域和lan域的策略进行配置,选项有: | 域(zone)是一组网络接口,域可作为IP转发的源地或目的地来进行相应配置。这里主要是对wan域和lan域的策略进行配置,选项有: | ||
| | | ||
| - | | + | |
| | | ||
| | | ||
| Line 17: | Line 17: | ||
| | | ||
| | | ||
| - | ==== 3. forwarding段;转发配置 ==== | + | ==== 3. forwarding段:转发配置 ==== |
| 配置2个域之间的路由转发。选项有: | 配置2个域之间的路由转发。选项有: | ||
| | | ||
| | | ||
| ==== 4. rule段:规则配置 ==== | ==== 4. rule段:规则配置 ==== | ||
| - | Rule段可以对特定的端口或主机设置基本的" | + | Rule段可以对特定的端口或主机设置基本的" |
| + | src | ||
| + | src_ip | ||
| + | src_port | ||
| + | dest 数据包目的地所属域(zone) | ||
| + | dest_ip | ||
| + | dest_port | ||
| + | proto | ||
| + | target | ||
| + | |||
| + | 例子, | ||
| + | config rule | ||
| + | option name Allow-wan-SSH | ||
| + | option src wan | ||
| + | option dest_port 22 | ||
| + | option proto tcp | ||
| + | option target ACCEPT | ||
| ==== 5. redirect段:端口转发配置 ==== | ==== 5. redirect段:端口转发配置 ==== | ||
| - | 最后执行命令/ | + | 如果从外域来访的数据包符合转发规则, |
| + | | ||
| + | | ||
| + | | ||
| + | | ||
| + | | ||
| + | | ||
| + | | ||
| + | | ||
| + | | ||
| - | 更详细的配置参见: | + | |
| + | |||
| + | |||
| + | 最后执行命令/ | ||
| + | 更详细的配置参见: | ||
firewall.1525826500.txt.gz · Last modified: (external edit)
