Merge branch 'restrict-respondd'

This commit is contained in:
Matthias Schiffer 2016-02-05 19:18:40 +01:00
commit e0e96b7b28
1 changed files with 12 additions and 0 deletions

View File

@ -16,5 +16,17 @@ uci:section('firewall', 'rule', 'wan_respondd',
}
)
-- Restrict respondd queries to link-local addresses to prevent amplification attacks from outside
uci:section('firewall', 'rule', 'client_respondd',
{
name = 'client_respondd',
src = 'client',
src_ip = '!fe80::/64',
dest_port = '1001',
proto = 'udp',
target = 'REJECT',
}
)
uci:save('firewall')
uci:commit('firewall')