瀏覽代碼

gluon-core: firewall: remove redundant ICMPv6 output rules

OUTPUT is always accepted, no need to allow ICMPv6 explicitly.
Matthias Schiffer 6 年之前
父節點
當前提交
a252383918
共有 1 個文件被更改,包括 2 次插入20 次删除
  1. 2 20
      package/gluon-core/luasrc/lib/gluon/upgrade/140-firewall-rules

+ 2 - 20
package/gluon-core/luasrc/lib/gluon/upgrade/140-firewall-rules

@@ -59,26 +59,8 @@ for _, zone in ipairs ({ 'mesh', 'local_client' } ) do
 		target = 'ACCEPT',
 	})
 
-	uci:section('firewall', 'rule', zone .. '_ICMPv6_out', {
-		dest = zone,
-		proto = 'icmp',
-		icmp_type = {
-			'echo-request',
-			'echo-reply',
-			'destination-unreachable',
-			'packet-too-big',
-			'time-exceeded',
-			'bad-header',
-			'unknown-header-type',
-			'router-solicitation',
-			'neighbour-solicitation',
-			'router-advertisement',
-			'neighbour-advertisement',
-		},
-		limit = '1000/sec',
-		family = 'ipv6',
-		target = 'ACCEPT',
-	})
+	-- Can be removed soon: was never in a release
+	uci:delete('firewall', zone .. '_ICMPv6_out')
 end
 
 uci:save('firewall')