[backfire] firewall: merge r29577
authorJo-Philipp Wich <jow@openwrt.org>
Tue, 20 Dec 2011 01:12:04 +0000 (01:12 +0000)
committerJo-Philipp Wich <jow@openwrt.org>
Tue, 20 Dec 2011 01:12:04 +0000 (01:12 +0000)
SVN-Revision: 29578

package/firewall/Makefile
package/firewall/files/firewall.config
package/firewall/files/lib/config.sh

index 5feba56..5b87114 100644 (file)
@@ -9,7 +9,7 @@ include $(TOPDIR)/rules.mk
 PKG_NAME:=firewall
 
 PKG_VERSION:=2
-PKG_RELEASE:=34.7
+PKG_RELEASE:=34.8
 
 include $(INCLUDE_DIR)/package.mk
 
index d6a125d..ed26829 100644 (file)
@@ -29,6 +29,7 @@ config forwarding
 # We need to accept udp packets on port 68,
 # see https://dev.openwrt.org/ticket/4108
 config rule
+       option name             Allow-DHCP-Renew
        option src              wan
        option proto            udp
        option dest_port        68
@@ -37,6 +38,7 @@ config rule
 
 # Allow IPv4 ping
 config rule
+       option name             Allow-Ping
        option src              wan
        option proto            icmp
        option icmp_type        echo-request
@@ -46,6 +48,7 @@ config rule
 # Allow DHCPv6 replies
 # see https://dev.openwrt.org/ticket/10381
 config rule
+       option name             Allow-DHCPv6
        option src              wan
        option proto            udp
        option src_ip           fe80::/10
@@ -57,6 +60,7 @@ config rule
 
 # Allow essential incoming IPv6 ICMP traffic
 config rule
+       option name             Allow-ICMPv6-Input
        option src              wan
        option proto    icmp
        list icmp_type          echo-request
@@ -73,6 +77,7 @@ config rule
 
 # Allow essential forwarded IPv6 ICMP traffic
 config rule                                   
+       option name             Allow-ICMPv6-Forward
        option src              wan
        option dest             *
        option proto            icmp
index 996cef8..8b2399f 100644 (file)
@@ -34,7 +34,11 @@ fw_config_get_section() { # <config> <prefix> <type> <name> <default> ...
                export ${NO_EXPORT:+-n} -- "${prefix}NAME"="${config}"
                config_get "${prefix}TYPE" "$config" TYPE
        }
-       
+
+       local enabled
+       config_get_bool enabled "$config" enabled 1
+       [ $enabled -eq 1 ] || return 1
+
        [ "$1" == '{' ] && shift
        while [ $# -ge 3 ]; do
                local type=$1