Skip to content

Commit 20a1421

Browse files
committed
config: Make DHCP and DHCPv6 response rules strict
Non-server DHCPx responses indicated by non-standard sport are already discarded by client, reflect that in firewall rule avoiding unnecessary ct state buildup wasting ct resources Signed-off-by: Andris PE <neandris@gmail.com>
1 parent b6e5157 commit 20a1421

File tree

1 file changed

+18
-0
lines changed

1 file changed

+18
-0
lines changed

root/etc/config/firewall

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,10 +33,19 @@ config rule
3333
option name Allow-DHCP-Renew
3434
option src wan
3535
option proto udp
36+
option src_port 67
3637
option dest_port 68
3738
option target ACCEPT
3839
option family ipv4
3940

41+
config rule
42+
option name Drop-DHCP-Unsolicited
43+
option src wan
44+
option proto udp
45+
option dst_port 68
46+
option target DROP
47+
option family ipv4
48+
4049
# Allow IPv4 ping
4150
config rule
4251
option name Allow-Ping
@@ -59,10 +68,19 @@ config rule
5968
option name Allow-DHCPv6
6069
option src wan
6170
option proto udp
71+
option src_port 547
6272
option dest_port 546
6373
option family ipv6
6474
option target ACCEPT
6575

76+
config ruke
77+
option name Drop-DHCPv6-Unsolicited
78+
option src wan
79+
option proto udp
80+
option dest_port 546
81+
option family ipv6
82+
option target DROP
83+
6684
config rule
6785
option name Allow-MLD
6886
option src wan

0 commit comments

Comments
 (0)