Export Firewall Rules, for a new Install

Hi, is there a way, and if not available, which should be implimented.

A way of Exporting Current Firewall Rules; without having a full Settings download to import, im finding certain settings are being imported on a fresh install taking settings from old components which are irrelevant to my new install.

I want a new install of OpenWRT, with my current Firewall Rules.

Backup & Restore needs to be more specific on what needs to be restored.

This is my current list of BAD DNS Servers:

Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 212.159.13.49
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 212.159.13.50
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 212.159.6.10
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 212.159.6.9
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.6.40.162
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.6.40.178
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 216.146.35.35
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 206.165.6.11
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.72.0.98
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.72.0.144
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.72.6.51
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.6.40.162
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.6.40.178
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 74.82.42.42
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.72.9.38
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 85.90.229.188
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 141.1.27.249
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.27.1.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 185.43.192.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.72.0.98
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.6.40.162
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.6.40.178
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.6.40.162
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.6.40.178
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 74.82.42.42
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 67.17.215.132
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 4.2.2.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 4.2.2.6
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 209.244.0.4
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 9.9.9.9
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 129.250.35.250
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 129.250.35.251
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 8.8.8.8
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 8.8.4.4
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 4.2.2.5
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 4.2.2.4
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 4.2.2.3
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 4.2.2.2
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 209.250.230.218
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 45.32.177.161
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 209.250.230.218
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 64.215.98.148
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 24.113.32.29
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 24.113.32.30
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 87.117.196.200
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 154.32.105.18
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.72.0.114
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 64.212.106.84
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 83.137.225.121
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.58.204.159
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.72.6.57
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.72.9.34
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.73.82.242
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.74.65.68
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.74.65.69
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 141.1.1.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 206.165.6.12
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 209.244.0.3
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 209.130.139.2
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 206.165.4.12
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 209.244.0.3
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 64.212.106.84
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 83.137.225.121
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 209.244.0.3
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 206.165.6.12
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 206.165.6.12
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 209.244.0.3
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 141.1.1.1
Reject forward
Forwarded IPv4 and IPv6
From wan
To lan, IP 206.165.6.12
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.99.66.220
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.111.200.191
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.40.32.33
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 216.146.36.36
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 156.154.70.22
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 156.154.70.25
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 156.154.71.22
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 156.154.71.25
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 198.153.192.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 198.153.194.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 81.17.66.13
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.186.4.107
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.186.4.108
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.111.200.191
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 204.194.232.200
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 204.194.234.200
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 204.117.214.10
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 199.2.252.10
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 204.97.212.10
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.134.11.4
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 66.28.0.45
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 170.56.58.53
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 158.43.128.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 158.43.128.72
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 158.43.192.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 213.52.192.198
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 212.111.32.7
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.186.1.107
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.186.1.109
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.108.1.108
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.186.1.110
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.2.0.50
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 212.118.241.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 212.118.241.33
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 213.251.133.164
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 156.154.70.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.58.204.59
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 156.154.71.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.182.110.132
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.2.64.45
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.238.40.45
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.30.0.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 74.118.212.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 74.118.212.2
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 9.9.9.9
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 64.81.111.2
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 24.113.32.29
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 24.113.32.30
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 158.43.240.3
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 158.43.240.4
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 192.76.144.66
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.150.168.168
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.25.0.68
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.40.32.34
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 212.94.32.32
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.67.79.39
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.186.4.109
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.30.0.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.94.0.42
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.94.0.41
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 4.69.217.250
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.230.161.4
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 205.171.3.25
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.25.0.52
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.25.0.60
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 217.14.128.50
Drop forward
Forwarded IPv4 and IPv6
From wan
To lan, IP 217.14.128.50
Drop forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 31.53.202.190
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 158.234.8.70
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 109.74.194.20
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 217.144.6.6
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 80.237.7.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.95.93.77
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.226.61.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.150.168.168
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.2.0.50
Reject forward
Forwarded IPv4 and IPv6
From wan, IP 194.2.0.50
To lan
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 80.73.1.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 80.237.7.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.89.248.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.25.0.68
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 212.36.64.17
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 216.194.28.33
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 213.244.72.31
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.177.210.210
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.205.130.253
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 205.171.3.65
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 205.171.2.65
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 82.151.90.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.251.169.83
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 212.73.140.66
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 204.95.160.4
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.186.1.109
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.186.1.110
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 163.121.2.2
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.196.2.70
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 216.254.141.13
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 216.254.141.2
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.101.111.20
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.129.12.122
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.101.111.20
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.129.12.122
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 212.145.4.98
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 151.202.0.84
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 207.68.32.38
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 151.198.0.39
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 151.196.0.38
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 62.233.128.17
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 8.15.12.5
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 64.94.1.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 216.52.94.33
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 216.52.94.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.113.144.194
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.230.161.3
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 213.33.99.70
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 86.162.39.230
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 216.170.153.146
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 64.119.60.5
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 64.119.60.9
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 66.163.0.161
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 66.163.0.173
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 204.95.160.2
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 208.48.253.106
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 208.72.120.204
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 208.79.56.204
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 212.147.10.10
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 216.52.65.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 193.22.119.22
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 194.77.8.1
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 195.158.7.98
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 198.82.247.34
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 199.166.6.2
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 209.239.11.98
Accept forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 64.233.207.2
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 64.233.207.16
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 217.150.35.129
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 69.60.160.203
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 12.127.16.67
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 12.127.17.71
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 24.201.245.77
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 91.186.192.3
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 83.143.8.249
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 209.250.128.6
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 212.96.1.70
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 217.29.16.250
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 216.17.128.2
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 208.78.24.238
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 216.229.0.25
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 69.169.190.211
Reject forward
Forwarded IPv4 and IPv6
From lan
To wan, IP 69.60.160.196

These are very BAD DNS Servers, and are not Secure.

Copy /etc/config/firewall?

or you could create a set of rules, (re)directing all DNS request to a DNS server that isn't bad...

2 Likes

Will this process import into the new 20.03? If so whats the import and export process, this isnt made easy.

Should be individual export backups, everything or each thing you want you want, especially Firewall Rules. The new update is not compatible with my backups now.

Like CSV updates for this kind of thing to make it simple, i dont mind hard processes but blummin ekk, this should of been thought of to at least make Firewall Rules be updated easily. Think im updating a thousand IP Ranges, ISP`s that need to be banned, PAIN.

Can they update impliment an update export option from update to 20.02 to export Firewall Rules to be compatible to import to 20.03

Everything else is simple.

If you had expressed your firewall rules purely in fw3/ uci syntax before, they would have worked as-is. Manual iptables invocations are free-form and will need (mostly-) manual translation into nftables/ fw4 compatible rule sets - this is not simple, both have different semantics, different capabilities and quirks. The simpler you keep your rules (and the more uci), the easier - more complex stuff means more complex migrations.

For me, with a pure fw3/ uci config and ~two dozen additional (uci-)rules, it was simple - nothing to do, fw4 took them verbatim.

1 Like

I dont use IPTables. They are ancient.

CSV Export to import Current Rules that was in place before, thats compatible with the new OS. Simple. Ive Rules that over rule IPTables.

I can go through all the SSH to extract all this, but a GUI can accomplish this, saves the hastle. If i have do i have do as OpenWRT is the best Routing Software ive used so far.

If i have to put put it into Assembly, you`ll understand Syntax.

Just i want a simple export of the Firewall Rules. Simple

There massive my Firewall rules, no simple shit. Take blummin hours.