You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The following was entered in LuCI and confirmed by looking at /etc/config/firewall:
config rule
option enabled '1'
option family 'ipv4'
option proto 'all'
option src '*'
option src_ip '! 192.168.1.0/24'
option target 'DROP'
option name 'Drop_OUT_InvalidSRC'
option dest '*'
option extra '-o eth0.2'
I've also made the rule without option extra, and by specifying the dest WAN. The rule never appears on my firewall; but adding it via the Custom Firewall rule is works.
The text was updated successfully, but these errors were encountered:
"option src_ip" must have no space between the "!" and the IP address.
Since "option src_ip" is parsed as space separated list for "config rule" sections,
your "option src_ip '! 192.168.1.0/24'" is interpreted as list src_ip '!'
list src_ip '192.168.1.0/24' which leads to an error like Warning: Option @rule[0].src_ip has invalid value '!'
A workaround is to remove the space between the exclamation mark and the address.
The work around (removing the space) places the rule on my iptables!
It seems to hit all packets, but calls the thats WAN's drop chain. I see zero drops, which is expected (since I have a Custom RAW table rule dropping incoming from the LAN bridge also not equaling the SRC address).
I will test the space parsing in the next release.
lleachii:
The following was entered in LuCI and confirmed by looking at /etc/config/firewall:
config rule option enabled '1' option family 'ipv4' option proto 'all' option src '*' option src_ip '! 192.168.1.0/24' option target 'DROP' option name 'Drop_OUT_InvalidSRC' option dest '*' option extra '-o eth0.2'
I've also made the rule without option extra, and by specifying the dest WAN. The rule never appears on my firewall; but adding it via the Custom Firewall rule is works.
The text was updated successfully, but these errors were encountered: