Differences

This shows you the differences between two versions of the page.

ru:doc:uci:firewall [2013/10/17 08:58]
datasheet
ru:doc:uci:firewall [2013/10/17 09:14] (current)
datasheet
Line 18: Line 18:
A minimal firewall configuration for a router usually consists of one //defaults// section, at least two //zones// (''lan'' and ''wan'') and one //forwarding// to allow traffic from ''lan'' to ''wan''. (The forwarding section is not strictly required when there are no more than two zones as the rule can then be set as the 'global default' for that zone.) A minimal firewall configuration for a router usually consists of one //defaults// section, at least two //zones// (''lan'' and ''wan'') and one //forwarding// to allow traffic from ''lan'' to ''wan''. (The forwarding section is not strictly required when there are no more than two zones as the rule can then be set as the 'global default' for that zone.)
-==== Defaults ==== +==== Значения "по-умолчанию" ==== 
-The ''defaults'' section declares global firewall settings which do not belong to specific zones+Секция ''defaults'' ((т.е. секция "по-умолчанию", секция "дефолтных" настроек)) определяет глобальные установки файрвола, которые не принадлежат каким-либо конкретным //зонам//
-The following options are defined within this section:+В этой секции определяются следующие опции:
-^ Name ^ Type ^ Required ^ Default ^ Description +^ Имя ^ Тип ^ Обязательная опция ^ Значение "по-умолчанию" ^ Описание
-| ''input'' | string | no | ''REJECT'' | Set policy for the ''INPUT'' chain of the ''filter'' table. | +| ''input'' | string | нет | ''REJECT'' | Set policy for the ''INPUT'' chain of the ''filter'' table. | 
-| ''output'' | string | no | ''REJECT'' | Set policy for the ''OUTPUT'' chain of the ''filter'' table. | +| ''output'' | string | нет | ''REJECT'' | Set policy for the ''OUTPUT'' chain of the ''filter'' table. | 
-| ''forward'' | string | no | ''REJECT'' | Set policy for the ''FORWARD'' chain of the ''filter'' table.  | +| ''forward'' | string | нет | ''REJECT'' | Set policy for the ''FORWARD'' chain of the ''filter'' table.  | 
-| ''drop_invalid'' | boolean | no | ''0'' | Drop invalid packets (e.g. not matching any active connection). | +| ''drop_invalid'' | boolean | нет | ''0'' | Drop invalid packets (e.g. not matching any active connection). | 
-| ''syn_flood'' | boolean | no | ''0'' | Enable [[wp>SYN flood]] protection (obsoleted by ''synflood_protect'' setting). | +| ''syn_flood'' | boolean | нет | ''0'' | Enable [[wp>SYN flood]] protection (obsoleted by ''synflood_protect'' setting). | 
-| ''synflood_protect'' | boolean | no | ''0'' | Enable [[wp>SYN flood]] protection. | +| ''synflood_protect'' | boolean | нет | ''0'' | Enable [[wp>SYN flood]] protection. | 
-| ''synflood_rate'' | string | no | ''25'' | Set rate limit (packets/second) for SYN packets above which the traffic is considered a flood. | +| ''synflood_rate'' | string | нет | ''25'' | Set rate limit (packets/second) for SYN packets above which the traffic is considered a flood. | 
-| ''synflood_burst'' | string | no | ''50'' | Set burst limit for SYN packets above which the traffic is considered a flood if it exceeds the allowed rate. | +| ''synflood_burst'' | string | нет | ''50'' | Set burst limit for SYN packets above which the traffic is considered a flood if it exceeds the allowed rate. | 
-| ''tcp_syncookies'' | boolean | no | ''1'' | Enable the use of [[wp>SYN cookies]]. | +| ''tcp_syncookies'' | boolean | нет | ''1'' | Enable the use of [[wp>SYN cookies]]. | 
-| ''tcp_ecn'' | boolean | no | ''0'' |  | +| ''tcp_ecn'' | boolean | нет | ''0'' |  | 
-| ''tcp_westwood'' | boolean | no | ''0'' |  | +| ''tcp_westwood'' | boolean | нет | ''0'' |  | 
-| ''tcp_window_scaling'' | boolean | no | ''1'' | Enable TCP window scaling. | +| ''tcp_window_scaling'' | boolean | нет | ''1'' | Enable TCP window scaling. | 
-| ''accept_redirects'' | boolean | no | ''0'' |  | +| ''accept_redirects'' | boolean | нет | ''0'' |  | 
-| ''accept_source_route'' | boolean | no | ''0'' |  | +| ''accept_source_route'' | boolean | нет | ''0'' |  | 
-| ''custom_chains'' | boolean | no | ''1'' |  | +| ''custom_chains'' | boolean | нет | ''1'' |  | 
-| ''disable_ipv6'' | boolean | no | ''0'' | Disable IPv6 firewall rules. |+| ''disable_ipv6'' | boolean | нет | ''0'' | Disable IPv6 firewall rules. |
==== Zones ==== ==== Zones ====

Back to top

ru/doc/uci/firewall.txt · Last modified: 2013/10/17 09:14 by datasheet