找回密码
 立即注册

QQ登录

只需一步,快速开始

搜索
广告投放联系QQ68610888
查看: 1362|回复: 14

[求助] 360 V6的IPv6防火墙转发端口 Ip6tables可以这样写么?

[复制链接]
背景:
手上三个360 V5M,三母套装,,和官方要了定制固件:1. 禁止母路由作为子路由Mesh时,依旧下发IPv6 网关(实测还是有问题);IPv4的端口转发,对IPv6也生效(实测TCP可以,UDP不行)

网上看到360 V6已经流出了Telnet插件和账户密码了,有Telnet不等于SSH么,有SSH还刷什么固件,原厂的Mesh是最好的!且360 V6原厂固件也是基于Openwrt改的。随入手个二手360 V6调试,看如何转发NAS的端口。

目的:
开放1234端口,TCP,UDP协议的出站和入栈。

具体操作:
根据群晖的日志,网卡共获得过三种类型的地址其中X表示动态值,具体数字表示始终固定数值:
1. 2409:8a55:30XX:XXXX::114,针对这种类型,如下这样写,可以么:
ip6tables -I FORWARD -p tcp udp -d 2409:8a55:30FF:FFFF::114 --dport 1234 -j ACCEPT
ip6tables -I FORWARD -p tcp udp -s 2409:8a55:30FF:FFFF::114 --sport 1234 -j ACCEPT

2. 2409:8a55:30XX:XXXX::2,2022年2月前是2409:8a55:30XX:XXXX::114;之后就是2409:8a55:30XX:XXXX::2,原因不知道,机器没有换过。
ip6tables -I FORWARD -p tcp udp -d 2409:8a55:30FF:FFFF::2--dport 1234 -j ACCEPT
ip6tables -I FORWARD -p tcp udp -s 2409:8a55:30FF:FFFF::2--sport 1234 -j ACCEPT

3. 2409:8a55:30XX:XXXX:211:32ff:fe86:2aa6;其实第一种和第二种应该是一个类型,只是不知道为什么突然尾缀的最后一段变动了,有大神知道的帮忙科普下。谢谢!
ip6tables -I FORWARD -p tcp udp -d 2409:8a55:30FF:FFFF:211:32ff:fe86:2aa6 --dport 1234 -j ACCEPT
ip6tables -I FORWARD -p tcp udp -s 2409:8a55:30FF:FFFF:211:32ff:fe86:2aa6 --sport 1234 -j ACCEPT


另,大家应该应该看出来了,这是移动的网络,IPv4公网无望,但是还请大神帮写下iptables 开放1234端口,TCP,UDP协议的出站和入栈,假设群晖IPv4的地址是192.168.0.2

另2,360 v6 telnet进去了,cd /etc/config/,是显示的是/tmp/etc/config/, 那么这样写的IPv6防火墙规则,重启是否失效了?

谢谢,折腾好几天了。

我的恩山、我的无线 The best wifi forum is right here.
1. 2409:8a55:30XX:XXXX::114
2. 2409:8a55:30XX:XXXX::2
说明NAS用的DHCPV6方式分发的地址,对应V4的LANIP应该是XXX.XXX.XXX.114和XXX.XXX.XXX.2,一般默认不改设置,V6的地址最后面16位和V4局域网最后的IP对应
3. 2409:8a55:30XX:XXXX:211:32ff:fe86:2aa6
ff:fe的标志说明你把NASV6分配设置了EUI64/privacy off的选项,这样V6地址是根据NAS网卡生成的,后64位不会变动
如果有ttl,看看
  1. cat /etc/config/firewall
复制代码

有没有结果,有的话说不定可以直接套用openwrt的防火墙规则

点评

另,向/etc/config/dhcp添加: 会导致上述两个设备IP在192.168.0.x和169.254.x.x间跳,应该是哪里冲突了  详情 回复 发表于 2022-8-23 21:39
编辑了下,要审核了 用这个吧:  详情 回复 发表于 2022-8-23 21:36
cat /etc/config/dhcp config dnsmasq option domainneeded '1' option boguspriv '1' option filterwin2k '0' option localise_queries '1' option rebind_localhos  详情 回复 发表于 2022-8-23 21:28
多谢提醒,我觉得这里可以做点工作:config zone option name 'wan' list network 'wan' list network 'wan6' option input 'REJECT' option output 'ACCEPT' option forward 'REJECT' 另,又发现个奇怪的  详情 回复 发表于 2022-8-23 21:23
我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

 楼主| | 显示全部楼层
本帖最后由 once375ml2 于 2022-8-23 21:34 编辑
avin4 发表于 2022-8-23 14:29
1. 2409:8a55:30XX:XXXX::114
2. 2409:8a55:30XX:XXXX::2
说明NAS用的DHCPV6方式分发的地址,对应V4的LAN ...
  1. cat /etc/config/firewall

  2. config defaults
  3. option syn_flood '1'
  4. option input 'ACCEPT'
  5. option output 'ACCEPT'
  6. option forward 'REJECT'
  7. option disabled '0'

  8. config zone
  9. option name 'lan'
  10. list network 'lan'
  11. option input 'ACCEPT'
  12. option output 'ACCEPT'
  13. option forward 'ACCEPT'

  14. config zone
  15. option name 'wan'
  16. list network 'wan'
  17. list network 'wan6'
  18. option input 'REJECT'
  19. option output 'ACCEPT'
  20. option forward 'REJECT'
  21. option masq '1'
  22. option mtu_fix '1'

  23. config forwarding
  24. option src 'lan'
  25. option dest 'wan'

  26. config rule
  27. option name 'Allow-DHCP-Renew'
  28. option src 'wan'
  29. option proto 'udp'
  30. option dest_port '68'
  31. option target 'ACCEPT'
  32. option family 'ipv4'

  33. config rule
  34. option name 'Allow-Ping'
  35. option src 'wan'
  36. option proto 'icmp'
  37. option icmp_type 'echo-request'
  38. option family 'ipv4'
  39. option target 'DROP'

  40. config rule
  41. option name 'Allow-IGMP'
  42. option src 'wan'
  43. option proto 'igmp'
  44. option family 'ipv4'
  45. option target 'ACCEPT'

  46. config rule
  47. option name 'Allow-DHCPv6'
  48. option src 'wan'
  49. option proto 'udp'
  50. option src_ip 'fe80::/10'
  51. option src_port '547'
  52. option dest_ip 'fe80::/10'
  53. option dest_port '546'
  54. option family 'ipv6'
  55. option target 'ACCEPT'

  56. config rule
  57. option name 'Allow-MLD'
  58. option src 'wan'
  59. option proto 'icmp'
  60. option src_ip 'fe80::/10'
  61. list icmp_type '130/0'
  62. list icmp_type '131/0'
  63. list icmp_type '132/0'
  64. list icmp_type '143/0'
  65. option family 'ipv6'
  66. option target 'ACCEPT'

  67. config rule
  68. option name 'Allow-ICMPv6-Input'
  69. option src 'wan'
  70. option proto 'icmp'
  71. list icmp_type 'echo-request'
  72. list icmp_type 'echo-reply'
  73. list icmp_type 'destination-unreachable'
  74. list icmp_type 'packet-too-big'
  75. list icmp_type 'time-exceeded'
  76. list icmp_type 'bad-header'
  77. list icmp_type 'unknown-header-type'
  78. list icmp_type 'router-solicitation'
  79. list icmp_type 'neighbour-solicitation'
  80. list icmp_type 'router-advertisement'
  81. list icmp_type 'neighbour-advertisement'
  82. option limit '1000/sec'
  83. option family 'ipv6'
  84. option target 'ACCEPT'

  85. config rule
  86. option name 'Allow-ICMPv6-Forward'
  87. option src 'wan'
  88. option dest '*'
  89. option proto 'icmp'
  90. list icmp_type 'echo-request'
  91. list icmp_type 'echo-reply'
  92. list icmp_type 'destination-unreachable'
  93. list icmp_type 'packet-too-big'
  94. list icmp_type 'time-exceeded'
  95. list icmp_type 'bad-header'
  96. list icmp_type 'unknown-header-type'
  97. option limit '1000/sec'
  98. option family 'ipv6'
  99. option target 'ACCEPT'

  100. config include
  101. option path '/etc/firewall.user'

  102. config rule
  103. option src 'wan'
  104. option dest 'lan'
  105. option proto 'esp'
  106. option target 'ACCEPT'

  107. config rule
  108. option src 'wan'
  109. option dest 'lan'
  110. option dest_port '500'
  111. option proto 'udp'
  112. option target 'ACCEPT'

  113. config include 'map'
  114. option type 'script'
  115. option path '/etc/firewall.d/map_firewall'
  116. option family 'any'
  117. option reload '1'

  118. config include 'qiot_speedtest'
  119. option type 'script'
  120. option path '/etc/firewall.d/qiot_speedtest'

  121. config include 'miniupnpd'
  122. option type 'script'
  123. option path '/usr/share/miniupnpd/firewall.include'
  124. option family 'any'
  125. option reload '1'

  126. config include 'qcanssecm'
  127. option type 'script'
  128. option path '/etc/firewall.d/qca-nss-ecm'
  129. option family 'any'
  130. option reload '1'
复制代码
多谢提醒,我觉得这里可以做点工作:
config zone
option name 'wan'
list network 'wan'
list network 'wan6'

option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'


另,又发现个奇怪的问题,因为360 v6没有静态DHCP地址(反而360 V5M有,主要想固定IPv6地址,进而好固定IPv6掩码,如上述的2409:8a55:30XX:XXXX::2)。想通过命令行DHCP添加,但是添加static lease会导致下述两个客户端分不到IPv4地址(在169.254.x.x和192.168.0.x间反复跳,应该是哪里冲突了),添加代码如下:
  1. vi /etc/config/dhcp

  2. # Static Dhcp for DS218j
  3. config host
  4.         option name 'DS218j'
  5.         option ip '192.168.0.2'
  6.         option mac '00:11:32:86:XX:XX'
  7.         
  8. # Static Dhcp for HP Printer
  9. config host
  10.         option name 'HPLASERMFP136WM'
  11.         option ip '192.168.0.3'
  12.         option mac 'B0:22:7A:59:XX:XX'
  13.         
复制代码

默认DHCP配置如下:
  1. cat /etc/config/dhcp
  2. config dnsmasq
  3.         option domainneeded '1'
  4.         option boguspriv '1'
  5.         option filterwin2k '0'
  6.         option localise_queries '1'
  7.         option rebind_localhost '1'
  8.         option local '/lan/'
  9.         option domain 'lan'
  10.         option expandhosts '1'
  11.         option nonegcache '0'
  12.         option authoritative '1'
  13.         option readethers '1'
  14.         option leasefile '/tmp/dhcp.leases'
  15.         option resolvfile '/tmp/resolv.conf.auto'
  16.         option localservice '1'
  17.         option rebind_protection '0'

  18. config dhcp 'lan'
  19.         option interface 'lan'
  20.         option leasetime '12h'
  21.         option force '1'
  22.         option dhcpv6 'server'
  23.         option ra 'server'
  24.         list dhcp_option '224,360MESH'
  25.         option start '2'
  26.         option limit '253'

  27. config dhcp 'wan'
  28.         option interface 'wan'
  29.         option ignore '1'

  30. config odhcpd 'odhcpd'
  31.         option maindhcp '0'
  32.         option leasefile '/tmp/hosts/odhcpd'
  33.         option leasetrigger '/usr/sbin/odhcpd-update'
复制代码
我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

 楼主| | 显示全部楼层
avin4 发表于 2022-8-23 14:29
1. 2409:8a55:30XX:XXXX::114
2. 2409:8a55:30XX:XXXX::2
说明NAS用的DHCPV6方式分发的地址,对应V4的LAN ...

cat /etc/config/dhcp
config dnsmasq
        option domainneeded '1'
        option boguspriv '1'
        option filterwin2k '0'
        option localise_queries '1'
        option rebind_localhost '1'
        option local '/lan/'
        option domain 'lan'
        option expandhosts '1'
        option nonegcache '0'
        option authoritative '1'
        option readethers '1'
       option leasefile '/tmp/dhcp.leases'
        option resolvfile '/tmp/resolv.conf.auto'
        option localservice '1'
        option rebind_protection '0'



option readethers '1' 这是不是暗示我可以通过/etc/ethers来指定ARP的同时,也指定静态DHCP?
还是,我要找到这个临时option leasefile '/tmp/dhcp.leases',对应的DHCP文件??



我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

 楼主| | 显示全部楼层
avin4 发表于 2022-8-23 14:29
1. 2409:8a55:30XX:XXXX::114
2. 2409:8a55:30XX:XXXX::2
说明NAS用的DHCPV6方式分发的地址,对应V4的LAN ...

编辑了下,要审核了

用这个吧:
  1. cat /etc/config/firewall

  2. config defaults
  3.         option syn_flood '1'
  4.         option input 'ACCEPT'
  5.         option output 'ACCEPT'
  6.         option forward 'REJECT'
  7.         option disabled '0'

  8. config zone
  9.         option name 'lan'
  10.         list network 'lan'
  11.         option input 'ACCEPT'
  12.         option output 'ACCEPT'
  13.         option forward 'ACCEPT'

  14. config zone
  15.         option name 'wan'
  16.         list network 'wan'
  17.         list network 'wan6'
  18.         option input 'REJECT'
  19.         option output 'ACCEPT'
  20.         option forward 'REJECT'
  21.         option masq '1'
  22.         option mtu_fix '1'

  23. config forwarding
  24.         option src 'lan'
  25.         option dest 'wan'

  26. config rule
  27.         option name 'Allow-DHCP-Renew'
  28.         option src 'wan'
  29.         option proto 'udp'
  30.         option dest_port '68'
  31.         option target 'ACCEPT'
  32.         option family 'ipv4'

  33. config rule
  34.         option name 'Allow-Ping'
  35.         option src 'wan'
  36.         option proto 'icmp'
  37.         option icmp_type 'echo-request'
  38.         option family 'ipv4'
  39.         option target 'DROP'

  40. config rule
  41.         option name 'Allow-IGMP'
  42.         option src 'wan'
  43.         option proto 'igmp'
  44.         option family 'ipv4'
  45.         option target 'ACCEPT'

  46. config rule
  47.         option name 'Allow-DHCPv6'
  48.         option src 'wan'
  49.         option proto 'udp'
  50.         option src_ip 'fe80::/10'
  51.         option src_port '547'
  52.         option dest_ip 'fe80::/10'
  53.         option dest_port '546'
  54.         option family 'ipv6'
  55.         option target 'ACCEPT'

  56. config rule
  57.         option name 'Allow-MLD'
  58.         option src 'wan'
  59.         option proto 'icmp'
  60.         option src_ip 'fe80::/10'
  61.         list icmp_type '130/0'
  62.         list icmp_type '131/0'
  63.         list icmp_type '132/0'
  64.         list icmp_type '143/0'
  65.         option family 'ipv6'
  66.         option target 'ACCEPT'

  67. config rule
  68.         option name 'Allow-ICMPv6-Input'
  69.         option src 'wan'
  70.         option proto 'icmp'
  71.         list icmp_type 'echo-request'
  72.         list icmp_type 'echo-reply'
  73.         list icmp_type 'destination-unreachable'
  74.         list icmp_type 'packet-too-big'
  75.         list icmp_type 'time-exceeded'
  76.         list icmp_type 'bad-header'
  77.         list icmp_type 'unknown-header-type'
  78.         list icmp_type 'router-solicitation'
  79.         list icmp_type 'neighbour-solicitation'
  80.         list icmp_type 'router-advertisement'
  81.         list icmp_type 'neighbour-advertisement'
  82.         option limit '1000/sec'
  83.         option family 'ipv6'
  84.         option target 'ACCEPT'

  85. config rule
  86.         option name 'Allow-ICMPv6-Forward'
  87.         option src 'wan'
  88.         option dest '*'
  89.         option proto 'icmp'
  90.         list icmp_type 'echo-request'
  91.         list icmp_type 'echo-reply'
  92.         list icmp_type 'destination-unreachable'
  93.         list icmp_type 'packet-too-big'
  94.         list icmp_type 'time-exceeded'
  95.         list icmp_type 'bad-header'
  96.         list icmp_type 'unknown-header-type'
  97.         option limit '1000/sec'
  98.         option family 'ipv6'
  99.         option target 'ACCEPT'

  100. config include
  101.         option path '/etc/firewall.user'

  102. config rule
  103.         option src 'wan'
  104.         option dest 'lan'
  105.         option proto 'esp'
  106.         option target 'ACCEPT'

  107. config rule
  108.         option src 'wan'
  109.         option dest 'lan'
  110.         option dest_port '500'
  111.         option proto 'udp'
  112.         option target 'ACCEPT'

  113. config include 'map'
  114.         option type 'script'
  115.         option path '/etc/firewall.d/map_firewall'
  116.         option family 'any'
  117.         option reload '1'

  118. config include 'qiot_speedtest'
  119.         option type 'script'
  120.         option path '/etc/firewall.d/qiot_speedtest'

  121. config include 'miniupnpd'
  122.         option type 'script'
  123.         option path '/usr/share/miniupnpd/firewall.include'
  124.         option family 'any'
  125.         option reload '1'

  126. config include 'qcanssecm'
  127.         option type 'script'
  128.         option path '/etc/firewall.d/qca-nss-ecm'
  129.         option family 'any'
  130.         option reload '1'
复制代码
我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

 楼主| | 显示全部楼层
avin4 发表于 2022-8-23 14:29
1. 2409:8a55:30XX:XXXX::114
2. 2409:8a55:30XX:XXXX::2
说明NAS用的DHCPV6方式分发的地址,对应V4的LAN ...

另,向/etc/config/dhcp添加:
  1. # Static Dhcp for DS218j
  2. config host
  3.         option name 'DS218j'
  4.         option ip '192.168.0.2'
  5.         option mac '00:11:32:86:XX:XX'
  6.         
  7. # Static Dhcp for HP Printer
  8. config host
  9.         option name 'HPLASERMFP136WM'
  10.         option ip '192.168.0.3'
  11.         option mac 'B0:22:7A:59:XX:XX'
  12.         
复制代码


会导致上述两个设备IP在192.168.0.x和169.254.x.x间跳,应该是哪里冲突了


  1. cat /etc/config/dhcp
  2. config dnsmasq
  3.         option domainneeded '1'
  4.         option boguspriv '1'
  5.         option filterwin2k '0'
  6.         option localise_queries '1'
  7.         option rebind_localhost '1'
  8.         option local '/lan/'
  9.         option domain 'lan'
  10.         option expandhosts '1'
  11.         option nonegcache '0'
  12.         option authoritative '1'
  13.         option readethers '1'
  14.         option leasefile '/tmp/dhcp.leases'
  15.         option resolvfile '/tmp/resolv.conf.auto'
  16.         option localservice '1'
  17.         option rebind_protection '0'

  18. config dhcp 'lan'
  19.         option interface 'lan'
  20.         option leasetime '12h'
  21.         option force '1'
  22.         option dhcpv6 'server'
  23.         option ra 'server'
  24.         list dhcp_option '224,360MESH'
  25.         option start '2'
  26.         option limit '253'

  27. config dhcp 'wan'
  28.         option interface 'wan'
  29.         option ignore '1'

  30. config odhcpd 'odhcpd'
  31.         option maindhcp '0'
  32.         option leasefile '/tmp/hosts/odhcpd'
  33.         option leasetrigger '/usr/sbin/odhcpd-update'
复制代码



我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

问题一个一个来,先解决防火墙,固定IP分配后面再说,为排除问题先把你固定IP的段落删了重启dnsmasq

看起来基本的防火墙规则有的,V4的NAT转发好搞定但你是移动,也不用再理会NAT了,直接搞V6,把下面的加入你的防火墙,意思是开放V6 地址后64位为::211:32ff:fe86:2aa6设备的TCP 38000端口给外网,
  1. config rule
  2.         option target 'ACCEPT'
  3.         option name 'NAS'
  4.         option dest_port '38000'
  5.         list proto 'tcp'
  6.         option dest 'lan'
  7.         option src 'wan'
  8.         list dest_ip '::211:32ff:fe86:2aa6/::ffff:ffff:ffff:ffff'
复制代码


然后假设你在NAS上38000架设了HTTP服务器,你用ISP分配的前缀补齐前64位,用手机网络访问这个V6地址,格式是

  1. http://[aaaa:bbbb:cccc:dddd:211:32ff:fe86:2aa6]:38000
复制代码


只要可以访问就开放成功了,这是动态掩码规则,只要保证你的NAS开了EUI64/privacy off,后64位地址不变,就算移动分配的V6前缀变了,防火墙规则依然有效。

具体端口和TCP/UDP你自己改,记得不要碰默认的80 443 8080,ISP肯定是封掉的

点评

再反馈,IPv4的DNAT,IPv6的Forward都搞定了 目前还差IPv4地址静态绑定了,/etc/config/DHCP如下: 目前是只要贴上 config host option mac '00:11:XX:XX:XX:XX' option name 'DS218j' option ip '1  详情 回复 发表于 2022-8-24 19:54
我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

 楼主| | 显示全部楼层
avin4 发表于 2022-8-24 10:19
问题一个一个来,先解决防火墙,固定IP分配后面再说,为排除问题先把你固定IP的段落删了重启dnsmasq

看 ...


感谢回复!

1. DHCP静态地址绑定昨晚发现问题后已经删除了,等防火墙搞定后,再慢慢研究

2. 语法上是“list proto 'tcp'”,还是“option proto 'tcp'”?
A. src_port:Match incoming traffic from the specified source port or port range, if relevant proto is specified. Multiple ports can be specified like ‘80 443 465’
对于port是可以一个规则,多个port,所以可以写成:
  1. option dest_port '5000 5001 7000 7001 8000 8001 10002 10003'
复制代码


B. proto:Match incoming traffic using the given protocol. Can be one (or several when using list syntax) of tcp, udp, udplite, icmp, esp, ah, sctp, or all or it can be a numeric value, representing one of these protocols or a different one. A protocol name from /etc/protocols is also allowed. The number 0 is equivalent to all.
proto,对个协议只能用一个一个list,所以要写成:
  1. list proto 'tcp'
  2. list proto 'udp'
复制代码
而不可以写成:
  1. option proto 'tcp udp'
复制代码
我的理解对么?


以下是我准备放进/etc/config/firewall
  1. config rule
  2.         option name 'Synology Http(s), FS Web, DS Web, Drive Web'
  3.         option target 'ACCEPT'
  4.         option dest_port '5000 5001 7000 7001 8000 8001 10002 10003'
  5.         list proto 'tcp'
  6.         option dest 'lan'
  7.         option src 'wan'
  8.         list dest_ip '::211:32ff:fe86:2aa6/::ffff:ffff:ffff:ffff'

  9. config rule
  10.         option name 'Synology Cloud Station'
  11.         option target 'ACCEPT'
  12.         option dest_port '6690'
  13.         list proto 'tcp'
  14.         option dest 'lan'
  15.         option src 'wan'
  16.         list dest_ip '::211:32ff:fe86:2aa6/::ffff:ffff:ffff:ffff'


  17. config rule
  18.         option name 'Synology Download Station'
  19.         option target 'ACCEPT'
  20.         option dest_port '13001 13002'
  21.         list proto 'tcp'
复制代码
感谢指教!!!!


我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

 楼主| | 显示全部楼层
反馈,按8#语句写好了,telnet反馈如下:
  1. * Rule 'Synology Http(s), FS Web, DS Web, Drive Web'
  2.      ! Skipping due to different family of ip address
  3.      ! Skipping due to different family of ip address
  4.      ! Skipping due to different family of ip address
  5.      ! Skipping due to different family of ip address
  6.      ! Skipping due to different family of ip address
  7.      ! Skipping due to different family of ip address
  8.      ! Skipping due to different family of ip address
  9.      ! Skipping due to different family of ip address
  10.    * Rule 'Synology Cloud Station'
  11.      ! Skipping due to different family of ip address
  12.    * Rule 'Synology Download Station'
  13.      ! Skipping due to different family of ip address
  14.      ! Skipping due to different family of ip address
  15.      ! Skipping due to different family of ip address
  16.      ! Skipping due to different family of ip address
复制代码


我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

 楼主| | 显示全部楼层
avin4 发表于 2022-8-24 10:19
问题一个一个来,先解决防火墙,固定IP分配后面再说,为排除问题先把你固定IP的段落删了重启dnsmasq

看 ...

反馈,按8#语句写好了,telnet反馈如下:
  1. * Rule 'Synology Http(s), FS Web, DS Web, Drive Web'
  2.      ! Skipping due to different family of ip address
  3.      ! Skipping due to different family of ip address
  4.      ! Skipping due to different family of ip address
  5.      ! Skipping due to different family of ip address
  6.      ! Skipping due to different family of ip address
  7.      ! Skipping due to different family of ip address
  8.      ! Skipping due to different family of ip address
  9.      ! Skipping due to different family of ip address
  10.    * Rule 'Synology Cloud Station'
  11.      ! Skipping due to different family of ip address
  12.    * Rule 'Synology Download Station'
  13.      ! Skipping due to different family of ip address
  14.      ! Skipping due to different family of ip address
  15.      ! Skipping due to different family of ip address
  16.      ! Skipping due to different family of ip address
复制代码

每条规则都添加 option family 'ipv6' 后,/etc/init.d/firewall restart 反馈正常了。


用手机关掉wifi,用移动5G,访问http://[aaaa:bbbb:cccc:dddd:211:32ff:fe86:2aa6]:5000,群晖Http管理端口正常了,其他端口应该可以了。

非常感谢。还请指导A. IPv4 DHCP静态地址,B. 为“2409:8a55:30XX:XXXX::2”这样的地址配置掩码规则



我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

 楼主| | 显示全部楼层
avin4 发表于 2022-8-24 10:19
问题一个一个来,先解决防火墙,固定IP分配后面再说,为排除问题先把你固定IP的段落删了重启dnsmasq

看 ...

再反馈,IPv4的DNAT,IPv6的Forward都搞定了

目前还差IPv4地址静态绑定了,/etc/config/DHCP如下:
  1. config dnsmasq
  2.         option domainneeded '1'
  3.         option boguspriv '1'
  4.         option filterwin2k '0'
  5.         option localise_queries '1'
  6.         option rebind_localhost '1'
  7.         option local '/lan/'
  8.         option domain 'lan'
  9.         option expandhosts '1'
  10.         option nonegcache '0'
  11.         option authoritative '1'
  12.         option readethers '1'
  13.         option leasefile '/tmp/dhcp.leases'
  14.         option resolvfile '/tmp/resolv.conf.auto'
  15.         option localservice '1'
  16.         option rebind_protection '0'

  17. config dhcp 'lan'
  18.         option interface 'lan'
  19.         option leasetime '12h'
  20.         option force '1'
  21.         option dhcpv6 'server'
  22.         option ra 'server'
  23.         list dhcp_option '224,360MESH'
  24.         option start '2'
  25.         option limit '253'

  26. config dhcp 'wan'
  27.         option interface 'wan'
  28.         option ignore '1'

  29. config odhcpd 'odhcpd'
  30.         option maindhcp '0'
  31.         option leasefile '/tmp/hosts/odhcpd'
  32.         option leasetrigger '/usr/sbin/odhcpd-update'
复制代码


目前是只要贴上

config host
        option mac '00:11:XX:XX:XX:XX'
        option name 'DS218j'
        option ip '192.168.0.2'


再/etc/init.d/dnsmasq reload,路由的DHCP就崩溃了


我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

openwrt firewall3 options 语法规则可以自己查阅官方wiki
Firewall configuration /etc/config/firewall

端口不能并列枚举,只能单个或者端口段,例如18000-18050这种
2409:8a55:30XX:XXXX::2 地址动态掩码类似啊,
  1. ::2/::ffff:ffff:ffff:ffff
复制代码

前提是"::2"部分不变动,这个分配要求不是在server端,是在client端设置的,就是你想NAS固定V6地址后64位,要在NAS的eth0或对应网口设置EUI64选项。同样详见官方wiki,其实很多东西都有的,只是是英文要自己琢磨:
IPv6 configuration-ip6ifaceid

点评

非常感谢你的全程帮助。 IPv4静态分配也搞定了,/etc/ethers不行,/etc/config/dhcp加“host”字段不行,但是/etc/dnsmasq.conf下加dhcp-host可以。 回头我把这个配置过程和要点编辑在第一页,方便其他人  详情 回复 发表于 2022-8-24 21:03
我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

 楼主| | 显示全部楼层
avin4 发表于 2022-8-24 20:30
openwrt firewall3 options 语法规则可以自己查阅官方wiki
Firewall configuration /etc/config/firewall
...

非常感谢你的全程帮助。

IPv4静态分配也搞定了,/etc/ethers不行,/etc/config/dhcp加“host”字段不行,但是/etc/dnsmasq.conf下加dhcp-host可以。
  1. # Always allocate the host with Ethernet address 11:22:33:44:55:66
  2. # The IP address 192.168.0.60
  3. #dhcp-host=11:22:33:44:55:66,192.168.0.60
复制代码



回头我把这个配置过程和要点编辑在第一页,方便其他人。

再次致谢!
我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

国内很多厂商都是拿古老的openwrt魔改做固件,但是自己加了私货,所以配置没法照搬也是正常的
op本身也引入了很多诸如dnsmaq这样的外部程序,/etc/config本身就不支持全部参数,所以保留了/etc/dnsmasq.conf
不过你这个静态分配应该不是op的锅,是360的问题
我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

 楼主| | 显示全部楼层
avin4 发表于 2022-8-24 21:33
国内很多厂商都是拿古老的openwrt魔改做固件,但是自己加了私货,所以配置没法照搬也是正常的
op本身也引 ...

也玩过OP好几年,第一反应就是在/etc/config/dhcp加“host”,结果不行…… 最终在Github的dnsmasq.conf.sample中找到了灵感



config rule
        option name 'Synology Web IPv6'
        option family 'ipv6'
        list proto 'tcp'
        option target 'ACCEPT'
        option src 'wan'
        option dest 'lan'        
        list dest_ip '::211:32ff:fe86:2aa6/::ffff:ffff:ffff:ffff'
        option dest_port '5000 5001 7000 7001 8000 8001 10002 10003'   


摘自官方手册:  
if relevant proto is specified. Multiple ports can be specified like '80 443 465'

所以 list proto 'tcp' 后 option dest_port '5000 5001 7000 7001 8000 8001 10002 10003'    这样行不行?
我的恩山、我的无线 The best wifi forum is right here.
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

关闭

欢迎大家光临恩山无线论坛上一条 /1 下一条

有疑问请添加管理员QQ86788181|手机版|小黑屋|Archiver|恩山无线论坛(常州市恩山计算机开发有限公司版权所有) ( 苏ICP备05084872号 )

GMT+8, 2024-4-29 10:44

Powered by Discuz! X3.5

© 2001-2024 Discuz! Team.

| 江苏省互联网有害信息举报中心 举报信箱:js12377 | @jischina.com.cn 举报电话:025-88802724 本站不良内容举报信箱:68610888@qq.com 举报电话:0519-86695797

快速回复 返回顶部 返回列表