Skip to content
Snippets Groups Projects
Commit e0e96b7b authored by Matthias Schiffer's avatar Matthias Schiffer
Browse files

Merge branch 'restrict-respondd'

parents 8bfb5fe1 2f499dbf
No related branches found
No related tags found
No related merge requests found
...@@ -16,5 +16,17 @@ uci:section('firewall', 'rule', 'wan_respondd', ...@@ -16,5 +16,17 @@ uci:section('firewall', 'rule', 'wan_respondd',
} }
) )
-- Restrict respondd queries to link-local addresses to prevent amplification attacks from outside
uci:section('firewall', 'rule', 'client_respondd',
{
name = 'client_respondd',
src = 'client',
src_ip = '!fe80::/64',
dest_port = '1001',
proto = 'udp',
target = 'REJECT',
}
)
uci:save('firewall') uci:save('firewall')
uci:commit('firewall') uci:commit('firewall')
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment