Configuration
Belkin RT3200
ubus call system board
{
"kernel": "6.6.119",
"hostname": "banderson-rt32",
"system": "ARMv8 Processor rev 4",
"model": "Linksys E8450 (UBI)",
"board_name": "linksys,e8450-ubi",
"rootfs_type": "squashfs",
"release": {
"distribution": "OpenWrt",
"version": "24.10.5",
"revision": "r29087-d9c5716d1d",
"target": "mediatek/mt7622",
"description": "OpenWrt 24.10.5 r29087-d9c5716d1d",
"builddate": "1766005702"
}
}
ip link show
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1504 qdisc mq state UP mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:26 brd ff:ff:ff:ff:ff:ff
3: lan1@eth0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue master br-sw state LOWERLAYERDOWN mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:26 brd ff:ff:ff:ff:ff:ff
4: lan2@eth0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue master br-sw state LOWERLAYERDOWN mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:26 brd ff:ff:ff:ff:ff:ff
5: lan3@eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-sw state UP mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:26 brd ff:ff:ff:ff:ff:ff
6: lan4@eth0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue master br-sw state DOWN mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:26 brd ff:ff:ff:ff:ff:ff
7: wan@eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:25 brd ff:ff:ff:ff:ff:ff
8: ip6tnl0@NONE: <NOARP> mtu 1452 qdisc noop state DOWN mode DEFAULT group default qlen 1000
link/tunnel6 :: brd :: permaddr e6be:f375:e28a::
9: gre0@NONE: <NOARP> mtu 1476 qdisc noop state DOWN mode DEFAULT group default qlen 1000
link/gre 0.0.0.0 brd 0.0.0.0
10: gretap0@NONE: <BROADCAST,MULTICAST> mtu 1462 qdisc noop state DOWN mode DEFAULT group default qlen 1000
link/ether 00:00:00:00:00:00 brd ff:ff:ff:ff:ff:ff
11: erspan0@NONE: <BROADCAST,MULTICAST> mtu 1450 qdisc noop state DOWN mode DEFAULT group default qlen 1000
link/ether 00:00:00:00:00:00 brd ff:ff:ff:ff:ff:ff
12: ip6gre0@NONE: <NOARP> mtu 1448 qdisc noop state DOWN mode DEFAULT group default qlen 1000
link/gre6 :: brd :: permaddr ca58:21ff:e4b5::
209: br-adm: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue state UP mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:26 brd ff:ff:ff:ff:ff:ff
210: br-sw: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue state UP mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:26 brd ff:ff:ff:ff:ff:ff
211: br-sw.1@br-sw: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue master br-adm state UP mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:26 brd ff:ff:ff:ff:ff:ff
212: br-iot: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue state UP mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:26 brd ff:ff:ff:ff:ff:ff
213: br-sw.30@br-sw: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue master br-iot state UP mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:26 brd ff:ff:ff:ff:ff:ff
218: wl0-ap1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-adm state UP mode DEFAULT group default qlen 1000
link/ether da:ec:5e:43:34:27 brd ff:ff:ff:ff:ff:ff permaddr d8:ec:5e:43:34:27
219: wl0-ap2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-iot state UP mode DEFAULT group default qlen 1000
link/ether de:ec:5e:43:34:27 brd ff:ff:ff:ff:ff:ff permaddr d8:ec:5e:43:34:27
220: wl0-ap3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP mode DEFAULT group default qlen 1000
link/ether d2:ec:5e:43:34:27 brd ff:ff:ff:ff:ff:ff permaddr d8:ec:5e:43:34:27
221: wl1-ap1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-adm state UP mode DEFAULT group default qlen 1000
link/ether da:ec:5e:43:34:28 brd ff:ff:ff:ff:ff:ff permaddr d8:ec:5e:43:34:28
222: gre4t-gt0@NONE: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc fq_codel master br-sw state UNKNOWN mode DEFAULT group default qlen 1000
link/ether 2a:41:a8:f5:4a:86 brd ff:ff:ff:ff:ff:ff
223: wl1-ap2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-iot state UP mode DEFAULT group default qlen 1000
link/ether de:ec:5e:43:34:28 brd ff:ff:ff:ff:ff:ff permaddr d8:ec:5e:43:34:28
230: wl1-ap0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-lan state UP mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:28 brd ff:ff:ff:ff:ff:ff
231: wl0-ap0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-lan state UP mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:27 brd ff:ff:ff:ff:ff:ff
234: br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue state UP mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:26 brd ff:ff:ff:ff:ff:ff
235: br-sw.20@br-sw: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue master br-lan state UP mode DEFAULT group default qlen 1000
link/ether d8:ec:5e:43:34:26 brd ff:ff:ff:ff:ff:ff
network
config interface 'loopback'
option device 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config globals 'globals'
option ula_prefix 'fd3b:1654:54dc::/48'
option packet_steering '1'
config interface 'wan'
option device 'wan'
option proto 'dhcp'
config interface 'wan6'
option device 'wan'
option proto 'dhcpv6'
config device
option type 'bridge'
option name 'br-sw'
list ports 'lan1'
list ports 'lan2'
list ports 'lan3'
list ports 'lan4'
list ports 'gre4t-gt0'
config bridge-vlan
option device 'br-sw'
option vlan '1'
list ports 'gre4t-gt0:t*'
list ports 'lan1:t*'
config bridge-vlan
option device 'br-sw'
option vlan '10'
list ports 'lan1:t'
config bridge-vlan
option device 'br-sw'
option vlan '20'
list ports 'gre4t-gt0:t'
list ports 'lan1:t'
list ports 'lan2'
list ports 'lan4'
config bridge-vlan
option device 'br-sw'
option vlan '30'
list ports 'gre4t-gt0:t'
list ports 'lan1:t'
list ports 'lan3'
list ports 'lan4:t'
config bridge-vlan
option device 'br-sw'
option vlan '40'
list ports 'lan1:t'
config bridge-vlan
option device 'br-sw'
option vlan '50'
list ports 'lan1:t'
config device
option type 'bridge'
option name 'br-adm'
option igmp_snooping '1'
option stp '1'
list ports 'br-sw.1'
config interface 'adm'
option proto 'static'
option device 'br-adm'
option ipaddr '192.168.201.1'
option netmask '255.255.255.0'
config device
option type 'bridge'
option name 'br-lan'
option igmp_snooping '1'
list ports 'br-sw.20'
option stp '1'
config interface 'lan'
option proto 'static'
option device 'br-lan'
option ipaddr '192.168.220.1'
option netmask '255.255.255.0'
config device
option type 'bridge'
option name 'br-iot'
option igmp_snooping '1'
option stp '1'
list ports 'br-sw.30'
config interface 'iot'
option proto 'static'
option device 'br-iot'
option ipaddr '192.168.230.1'
option netmask '255.255.255.0'
config interface 'wtun'
option proto 'static'
option ipaddr '192.168.20.10'
option netmask '255.255.255.0'
config interface 'gt0'
option proto 'gretap'
option peeraddr '192.168.10.20'
option ipaddr '192.168.10.10'
option mtu '1452'
option df '0'
config interface 'gre_lo'
option proto 'static'
option device 'lo'
option ipaddr '192.168.10.10'
option netmask '255.255.255.255'
config route
option interface 'wtun'
option target '192.168.10.20/32'
option gateway '192.168.20.20'
firewall
config defaults
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
option synflood_protect '1'
config zone
option name 'z_lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
list network 'lan'
config zone
option name 'z_wan'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option masq '1'
option mtu_fix '1'
list network 'wan'
list network 'wan6'
config forwarding
option src 'z_lan'
option dest 'z_wan'
config rule
option name 'Allow-DHCP-Renew'
option src 'z_wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'z_wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-IGMP'
option src 'z_wan'
option proto 'igmp'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-DHCPv6'
option src 'z_wan'
option proto 'udp'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-MLD'
option src 'z_wan'
option proto 'icmp'
option src_ip 'fe80::/10'
list icmp_type '130/0'
list icmp_type '131/0'
list icmp_type '132/0'
list icmp_type '143/0'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Input'
option src 'z_wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'z_wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-IPSec-ESP'
option src 'z_wan'
option dest 'z_lan'
option proto 'esp'
option target 'ACCEPT'
config rule
option name 'Allow-ISAKMP'
option src 'z_wan'
option dest 'z_lan'
option dest_port '500'
option proto 'udp'
option target 'ACCEPT'
config zone
option name 'z_adm'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
list network 'adm'
config forwarding
option src 'z_adm'
option dest 'z_wan'
config forwarding
option src 'z_adm'
option dest 'z_lan'
config forwarding
option src 'z_adm'
option dest 'z_iot'
config zone
option name 'z_iot'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
list network 'iot'
config forwarding
option src 'z_iot'
option dest 'z_wan'
config forwarding
option src 'z_lan'
option dest 'z_iot'
config zone
option name 'z_tun'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
list network 'wtun'
config forwarding
option src 'z_tun'
option dest 'z_adm'
config forwarding
option src 'z_tun'
option dest 'z_iot'
config forwarding
option src 'z_tun'
option dest 'z_lan'
config forwarding
option src 'z_adm'
option dest 'z_tun'
config forwarding
option src 'z_iot'
option dest 'z_tun'
config forwarding
option src 'z_lan'
option dest 'z_tun'
dhcp
config dnsmasq
option domainneeded '1'
option localise_queries '1'
option rebind_protection '1'
option rebind_localhost '1'
option local '/lan/'
option domain 'lan'
option expandhosts '1'
option authoritative '1'
option readethers '1'
option leasefile '/tmp/dhcp.leases'
option resolvfile '/tmp/resolv.conf.d/resolv.conf.auto'
option localservice '1'
option ednspacket_max '1232'
config dhcp 'wan'
option interface 'wan'
option ignore '1'
config odhcpd 'odhcpd'
option maindhcp '0'
option leasefile '/tmp/hosts/odhcpd'
option leasetrigger '/usr/sbin/odhcpd-update'
option loglevel '4'
option piofolder '/tmp/odhcpd-piofolder'
config host
option dns '1'
option ip '192.168.201.10'
option name 'banderson-gs1900'
option mac 'D8:EC:E5:8D:FB:74'
config host
option dns '1'
option mac 'B8:EC:A3:E2:61:24'
option ip '192.168.201.15'
option name 'banderson-nwa50ax'
config dhcp 'adm'
option interface 'adm'
option start '100'
option limit '150'
option leasetime '12h'
config dhcp 'iot'
option interface 'iot'
option start '100'
option limit '150'
option leasetime '12h'
config dhcp 'lan'
option interface 'lan'
option start '100'
option limit '150'
option leasetime '12h'
config host
option name 'einstein'
option mac '48:e7:da:87:77:67'
option ip '192.168.230.110'
config host
option name 'ha-rv'
list mac '00:1E:06:42:83:48'
option ip '192.168.230.101'
config host
option name 'ha-dev'
list mac '08:00:27:79:A5:58'
option ip '192.168.230.102'
OpenWrt One
ubus call system board
{
"kernel": "6.6.119",
"hostname": "banderson-owrtone",
"system": "ARMv8 Processor rev 4",
"model": "OpenWrt One",
"board_name": "openwrt,one",
"rootfs_type": "squashfs",
"release": {
"distribution": "OpenWrt",
"version": "24.10.5",
"revision": "r29087-d9c5716d1d",
"target": "mediatek/filogic",
"description": "OpenWrt 24.10.5 r29087-d9c5716d1d",
"builddate": "1766005702"
}
}
ip link show
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: eth0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc mq state DOWN mode DEFAULT group default qlen 1000
link/ether 20:05:b6:01:10:d0 brd ff:ff:ff:ff:ff:ff
3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq master br-sw state UP mode DEFAULT group default qlen 1000
link/ether 20:05:b6:01:10:d1 brd ff:ff:ff:ff:ff:ff
4: ip6tnl0@NONE: <NOARP> mtu 1452 qdisc noop state DOWN mode DEFAULT group default qlen 1000
link/tunnel6 :: brd :: permaddr 61b:a170:2096::
5: gre0@NONE: <NOARP> mtu 1476 qdisc noop state DOWN mode DEFAULT group default qlen 1000
link/gre 0.0.0.0 brd 0.0.0.0
6: gretap0@NONE: <BROADCAST,MULTICAST> mtu 1462 qdisc noop state DOWN mode DEFAULT group default qlen 1000
link/ether 00:00:00:00:00:00 brd ff:ff:ff:ff:ff:ff
7: erspan0@NONE: <BROADCAST,MULTICAST> mtu 1450 qdisc noop state DOWN mode DEFAULT group default qlen 1000
link/ether 00:00:00:00:00:00 brd ff:ff:ff:ff:ff:ff
8: ip6gre0@NONE: <NOARP> mtu 1448 qdisc noop state DOWN mode DEFAULT group default qlen 1000
link/gre6 :: brd :: permaddr ca6a:38d3:f9ee::
9: br-adm: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue state UP mode DEFAULT group default qlen 1000
link/ether 20:05:b6:01:10:d1 brd ff:ff:ff:ff:ff:ff
10: br-sw: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue state UP mode DEFAULT group default qlen 1000
link/ether 20:05:b6:01:10:d1 brd ff:ff:ff:ff:ff:ff
11: br-sw.1@br-sw: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue master br-adm state UP mode DEFAULT group default qlen 1000
link/ether 20:05:b6:01:10:d1 brd ff:ff:ff:ff:ff:ff
12: br-iot: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue state UP mode DEFAULT group default qlen 1000
link/ether 20:05:b6:01:10:d1 brd ff:ff:ff:ff:ff:ff
13: br-sw.30@br-sw: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue master br-iot state UP mode DEFAULT group default qlen 1000
link/ether 20:05:b6:01:10:d1 brd ff:ff:ff:ff:ff:ff
14: br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue state UP mode DEFAULT group default qlen 1000
link/ether 20:05:b6:01:10:d1 brd ff:ff:ff:ff:ff:ff
15: br-sw.20@br-sw: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc noqueue master br-lan state UP mode DEFAULT group default qlen 1000
link/ether 20:05:b6:01:10:d1 brd ff:ff:ff:ff:ff:ff
16: gre4t-gt0@NONE: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1452 qdisc fq_codel master br-sw state UNKNOWN mode DEFAULT group default qlen 1000
link/ether 36:04:cd:98:ad:c4 brd ff:ff:ff:ff:ff:ff
17: phy0-ap0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-lan state UP mode DEFAULT group default qlen 1000
link/ether 20:05:b6:01:10:d2 brd ff:ff:ff:ff:ff:ff
18: phy0-sta0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP mode DORMANT group default qlen 1000
link/ether 20:05:b6:01:10:d5 brd ff:ff:ff:ff:ff:ff
19: phy0-ap1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-adm state UP mode DEFAULT group default qlen 1000
link/ether 20:05:b6:01:10:d3 brd ff:ff:ff:ff:ff:ff permaddr 20:05:b6:01:10:d2
20: phy0-ap2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-iot state UP mode DEFAULT group default qlen 1000
link/ether 20:05:b6:01:10:d4 brd ff:ff:ff:ff:ff:ff permaddr 20:05:b6:01:10:d2
network
config interface 'loopback'
option device 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config globals 'globals'
option ula_prefix 'fd34:2b45:f4ab::/48'
option packet_steering '1'
config interface 'wan'
option device 'eth0'
option proto 'dhcp'
config interface 'wan6'
option device 'eth0'
option proto 'dhcpv6'
config device
option type 'bridge'
option name 'br-sw'
option igmp_snooping '1'
option stp '1'
list ports 'eth1'
list ports 'gre4t-gt0'
config bridge-vlan
option device 'br-sw'
option vlan '1'
list ports 'gre4t-gt0:t*'
config bridge-vlan
option device 'br-sw'
option vlan '20'
list ports 'eth1:u*'
list ports 'gre4t-gt0:t'
config bridge-vlan
option device 'br-sw'
option vlan '30'
list ports 'eth1:t'
list ports 'gre4t-gt0:t'
config interface 'wtun'
option proto 'static'
option ipaddr '192.168.20.20'
option netmask '255.255.255.0'
config interface 'gt0'
option proto 'gretap'
option ipaddr '192.168.10.20'
option peeraddr '192.168.10.10'
option mtu '1452'
option df '0'
config device
option type 'bridge'
option name 'br-adm'
option igmp_snooping '1'
option stp '1'
list ports 'br-sw.1'
config interface 'adm'
option proto 'static'
option device 'br-adm'
option ipaddr '192.168.201.2'
option netmask '255.255.255.0'
option gateway '192.168.201.1'
config device
option name 'br-lan'
option type 'bridge'
option igmp_snooping '1'
option stp '1'
list ports 'br-sw.20'
config interface 'lan'
option device 'br-lan'
option proto 'static'
option ipaddr '192.168.220.2'
option netmask '255.255.255.0'
option gateway '192.168.220.1'
config device
option type 'bridge'
option name 'br-iot'
option igmp_snooping '1'
option stp '1'
list ports 'br-sw.30'
config interface 'iot'
option proto 'static'
option device 'br-iot'
option ipaddr '192.168.230.2'
option netmask '255.255.255.0'
option gateway '192.168.230.1'
config interface 'gre_lo'
option proto 'static'
option device 'lo'
option ipaddr '192.168.10.20'
option netmask '255.255.255.255'
config route
option interface 'wtun'
option target '192.168.10.10/32'
option gateway '192.168.20.10'
firewall
config defaults
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option synflood_protect '1'
config zone
option name 'z_lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
list network 'lan'
config zone
option name 'z_wan'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option masq '1'
option mtu_fix '1'
list network 'wan'
list network 'wan6'
config forwarding
option src 'z_lan'
option dest 'z_wan'
config rule
option name 'Allow-DHCP-Renew'
option src 'z_wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'z_wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-IGMP'
option src 'z_wan'
option proto 'igmp'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-DHCPv6'
option src 'z_wan'
option proto 'udp'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-MLD'
option src 'z_wan'
option proto 'icmp'
option src_ip 'fe80::/10'
list icmp_type '130/0'
list icmp_type '131/0'
list icmp_type '132/0'
list icmp_type '143/0'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Input'
option src 'z_wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'z_wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-IPSec-ESP'
option src 'z_wan'
option dest 'z_lan'
option proto 'esp'
option target 'ACCEPT'
config rule
option name 'Allow-ISAKMP'
option src 'z_wan'
option dest 'z_lan'
option dest_port '500'
option proto 'udp'
option target 'ACCEPT'
config zone
option name 'z_tun'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
list network 'wtun'
config forwarding
option src 'z_tun'
option dest 'z_lan'
config forwarding
option src 'z_lan'
option dest 'z_tun'
config zone
option name 'z_adm'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
list network 'adm'
config forwarding
option src 'z_adm'
option dest 'z_lan'
config forwarding
option src 'z_adm'
option dest 'z_tun'
config forwarding
option src 'z_tun'
option dest 'z_adm'
config forwarding
option src 'z_adm'
option dest 'z_wan'
config zone
option name 'z_iot'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
list network 'iot'
config forwarding
option src 'z_iot'
option dest 'z_tun'
config forwarding
option src 'z_iot'
option dest 'z_wan'
config forwarding
option src 'z_adm'
option dest 'z_iot'
config forwarding
option src 'z_tun'
option dest 'z_iot'
config forwarding
option src 'z_lan'
option dest 'z_iot'
dhcp
config dnsmasq
option domainneeded '1'
option localise_queries '1'
option rebind_protection '0'
option domain 'lan'
option expandhosts '1'
option cachesize '1000'
option readethers '1'
option leasefile '/tmp/dhcp.leases'
option localservice '1'
option ednspacket_max '1232'
option local '/lan/'
option noresolv '1'
list server '/lan/192.168.201.1'
list server '192.168.201.1'
config dhcp 'lan'
option interface 'lan'
option start '100'
option limit '150'
option leasetime '12h'
option dhcpv4 'server'
option dhcpv6 'hybrid'
option ra 'hybrid'
list ra_flags 'managed-config'
list ra_flags 'other-config'
option ignore '1'
config dhcp 'wan'
option interface 'wan'
option ignore '1'
config odhcpd 'odhcpd'
option maindhcp '0'
option leasefile '/tmp/hosts/odhcpd'
option leasetrigger '/usr/sbin/odhcpd-update'
option loglevel '4'
option piofolder '/tmp/odhcpd-piofolder'
config dhcp 'adm'
option interface 'adm'
option ignore '1'
option start '100'
option limit '150'
option leasetime '12h'
config dhcp 'iot'
option interface 'iot'
option ignore '1'
option start '100'
option limit '150'
option leasetime '12h'
config dhcp 'gt0'
option interface 'gt0'
option ignore '1'
config dhcp 'wtun'
option interface 'wtun'
option start '100'
option limit '150'
option leasetime '12h'
option ignore '1'