Differences

This shows you the differences between two versions of the page.

zh-cn:doc:uci:firewall [2013/03/16 06:34]
zh-cn:doc:uci:firewall [2014/07/18 10:17] (current)
tanyingyu
Line 13: Line 13:
     这是 firewall 文件的第一个小节      这是 firewall 文件的第一个小节
    zone     zone
-     可以有数个 zone , zone 又可以包含数个 networ interfaces+     可以有数个 zone , zone 又可以包含数个 network interfaces
    forwarding     forwarding
-     位于的 zone 下面, 主要作用是允许数据封包的流动+     位于的 zone 下面, 主要作用是允许数据封包转发
    rule 以及 redirect     rule 以及 redirect
     可以看作是 zone 子集, 用来扩展进一步的封包限制.      可以看作是 zone 子集, 用来扩展进一步的封包限制.
Line 32: Line 32:
-===== Sections =====+===== =====
-Below is an overview of the section types that may be defined in the firewall configuration. +下面是防火墙可以定义的配置项概要。最小的防火墙配置通常包含一个default节,至少两个//zones//''lan'' ''wan'')和一个//forwarding//允许数据包由''lan''转发到''wan''
-A minimal firewall configuration for a router usually consists of one //defaults// section, at least two //zones// (''lan'' and ''wan'') and one //forwarding// to allow traffic from ''lan'' to ''wan''.+
==== Defaults ==== ==== Defaults ====
-The ''defaults'' section declares global firewall settings which do not belong to specific zones. +''defaults''节定义了不依赖于特定区域的防火墙全局设置。 
-The following options are defined within this section:+本节可以定义以下选项:
^ 名称 ^ 类型 ^ 是否必需 ^ 缺省 ^ 描述 ^ ^ 名称 ^ 类型 ^ 是否必需 ^ 缺省 ^ 描述 ^
-| ''syn_flood'' | boolean | no | ''1'' | Enable [[http://en.wikipedia.org/wiki/SYN_flood|SYN flood]] protection +| ''syn_flood'' | boolean | no | ''1'' | 允许 [[http://en.wikipedia.org/wiki/SYN_flood|SYN flood]] 保护
-| ''drop_invalid'' | boolean | no | ''1'' | Drop packets not matching any active connection +| ''drop_invalid'' | boolean | no | ''1'' | 丢弃任何没有匹配到已有连接的包
-| ''disable_ipv6'' | boolean | no | ''0'' | Disables IPv6 firewall rules if set to ''1'' (Firewall v2 and later) | +| ''disable_ipv6'' | boolean | no | ''0'' | 禁用IPv6防火墙设置 ''1'' (Firewall v2 and later) | 
-| ''input'' | string | no | ''DROP'' | Default policy (''ACCEPT'', ''REJECT'', ''DROP'') for the ''INPUT'' chain +| ''input'' | string | no | ''DROP'' | ''INPUT''链缺省策略(''ACCEPT'', ''REJECT'', ''DROP'') | 
-| ''forward'' | string | no | ''DROP'' | Default policy (''ACCEPT'', ''REJECT'', ''DROP'') for the ''FORWARD'' chain +| ''forward'' | string | no | ''DROP'' | ''FORWARD''链缺省策略(''ACCEPT'', ''REJECT'', ''DROP'') | 
-| ''output'' | string | no | ''DROP'' | Default policy (''ACCEPT'', ''REJECT'', ''DROP'') for the ''OUTPUT'' chain |+| ''output'' | string | no | ''DROP'' | ''OUTPUT''缺省策略(''ACCEPT'', ''REJECT'', ''DROP'') |
==== Zones ==== ==== Zones ====

Back to top

zh-cn/doc/uci/firewall.1363412049.txt.bz2 · Last modified: 2013/03/16 06:34 (external edit)