端口转发设置无效

zhcn7】 在 https://github.com/istoreos/istoreos/issues/330 发布:

config defaults
option input ‘ACCEPT’
option output ‘ACCEPT’
option fullcone ‘1’
option synflood_protect ‘1’
option forward ‘ACCEPT’

config zone
option name ‘lan’
option input ‘ACCEPT’
option output ‘ACCEPT’
option forward ‘ACCEPT’
option auto_helper ‘0’
option network ‘lan docker_A’

config zone
option name ‘wan’
option output ‘ACCEPT’
option masq ‘1’
option mtu_fix ‘1’
option input ‘ACCEPT’
option forward ‘ACCEPT’
option network ‘wan wan6’

config forwarding
option src ‘lan’
option dest ‘wan’

config rule
option name ‘Allow-DHCP-Renew’
option src ‘wan’
option proto ‘udp’
option dest_port ‘68’
option target ‘ACCEPT’
option family ‘ipv4’

config rule
option name ‘Allow-Ping’
option src ‘wan’
option proto ‘icmp’
option icmp_type ‘echo-request’
option family ‘ipv4’
option target ‘ACCEPT’

config rule
option name ‘Allow-IGMP’
option src ‘wan’
option proto ‘igmp’
option family ‘ipv4’
option target ‘ACCEPT’

config rule
option name ‘Allow-DHCPv6’
option src ‘wan’
option proto ‘udp’
option src_ip ‘fc00::/6’
option dest_ip ‘fc00::/6’
option dest_port ‘546’
option family ‘ipv6’
option target ‘ACCEPT’

config rule
option name ‘Allow-MLD’
option src ‘wan’
option proto ‘icmp’
option src_ip ‘fe80::/10’
list icmp_type ‘130/0’
list icmp_type ‘131/0’
list icmp_type ‘132/0’
list icmp_type ‘143/0’
option family ‘ipv6’
option target ‘ACCEPT’

config rule
option name ‘Allow-ICMPv6-Input’
option src ‘wan’
option proto ‘icmp’
list icmp_type ‘echo-request’
list icmp_type ‘echo-reply’
list icmp_type ‘destination-unreachable’
list icmp_type ‘packet-too-big’
list icmp_type ‘time-exceeded’
list icmp_type ‘bad-header’
list icmp_type ‘unknown-header-type’
list icmp_type ‘router-solicitation’
list icmp_type ‘neighbour-solicitation’
list icmp_type ‘router-advertisement’
list icmp_type ‘neighbour-advertisement’
option limit ‘1000/sec’
option family ‘ipv6’
option target ‘ACCEPT’

config rule
option name ‘Allow-ICMPv6-Forward’
option src ‘wan’
option dest ‘*’
option proto ‘icmp’
list icmp_type ‘echo-request’
list icmp_type ‘echo-reply’
list icmp_type ‘destination-unreachable’
list icmp_type ‘packet-too-big’
list icmp_type ‘time-exceeded’
list icmp_type ‘bad-header’
list icmp_type ‘unknown-header-type’
option limit ‘1000/sec’
option family ‘ipv6’
option target ‘ACCEPT’

config rule
option name ‘Allow-IPSec-ESP’
option src ‘wan’
option dest ‘lan’
option proto ‘esp’
option target ‘ACCEPT’

config rule
option name ‘Allow-ISAKMP’
option src ‘wan’
option dest ‘lan’
option dest_port ‘500’
option proto ‘udp’
option target ‘ACCEPT’

config rule
option name ‘Support-UDP-Traceroute’
option src ‘wan’
option dest_port ‘33434:33689’
option proto ‘udp’
option family ‘ipv4’
option target ‘REJECT’
option enabled ‘false’

config include
option path ‘/etc/firewall.user’

config include ‘miniupnpd’
option type ‘script’
option path ‘/usr/share/miniupnpd/firewall.include’
option family ‘any’
option reload ‘1’

config zone ‘docker’
option name ‘docker’
option input ‘ACCEPT’
option output ‘ACCEPT’
option forward ‘ACCEPT’
option auto_helper ‘0’
list network ‘docker’

config include ‘vssr’
option type ‘script’
option path ‘/var/etc/vssr.include’
option reload ‘1’

config redirect
option dest ‘lan’
option target ‘DNAT’
option name ‘forword’
option src ‘wan’
option dest_ip ‘172.17.0.1’
list proto ‘all’

config redirect
option dest ‘lan’
option target ‘DNAT’
option name ‘forword’
list proto ‘all’
option src ‘wan’
option dest_ip ‘172.17.0.7’

config redirect
option dest ‘lan’
option target ‘DNAT’
option name ‘forword’
list proto ‘all’
option src ‘wan’
option dest_ip ‘172.17.0.8’

config redirect
option dest ‘lan’
option target ‘DNAT’
option name ‘outin’
list proto ‘tcp’
list proto ‘udp’
list proto ‘icmp’
option src ‘wan’
option src_dport ‘1234’
option dest_ip ‘192.168.100.1’
option dest_port ‘80’