|
感谢回复!
1. DHCP静态地址绑定昨晚发现问题后已经删除了,等防火墙搞定后,再慢慢研究
2. 语法上是“list proto 'tcp'”,还是“option proto 'tcp'”?
A. src_port:Match incoming traffic from the specified source port or port range, if relevant proto is specified. Multiple ports can be specified like ‘80 443 465’
对于port是可以一个规则,多个port,所以可以写成:
- option dest_port '5000 5001 7000 7001 8000 8001 10002 10003'
复制代码
B. proto:Match incoming traffic using the given protocol. Can be one (or several when using list syntax) of tcp, udp, udplite, icmp, esp, ah, sctp, or all or it can be a numeric value, representing one of these protocols or a different one. A protocol name from /etc/protocols is also allowed. The number 0 is equivalent to all.
对proto,对个协议只能用一个一个list,所以要写成:
- list proto 'tcp'
- list proto 'udp'
复制代码 而不可以写成:
我的理解对么?
以下是我准备放进/etc/config/firewall
- config rule
- option name 'Synology Http(s), FS Web, DS Web, Drive Web'
- option target 'ACCEPT'
- option dest_port '5000 5001 7000 7001 8000 8001 10002 10003'
- list proto 'tcp'
- option dest 'lan'
- option src 'wan'
- list dest_ip '::211:32ff:fe86:2aa6/::ffff:ffff:ffff:ffff'
- config rule
- option name 'Synology Cloud Station'
- option target 'ACCEPT'
- option dest_port '6690'
- list proto 'tcp'
- option dest 'lan'
- option src 'wan'
- list dest_ip '::211:32ff:fe86:2aa6/::ffff:ffff:ffff:ffff'
- config rule
- option name 'Synology Download Station'
- option target 'ACCEPT'
- option dest_port '13001 13002'
- list proto 'tcp'
复制代码 感谢指教!!!!
|
|