Chinaunix首页 | 论坛 | 博客
  • 博客访问: 167914
  • 博文数量: 36
  • 博客积分: 1466
  • 博客等级: 上尉
  • 技术积分: 380
  • 用 户 组: 普通用户
  • 注册时间: 2007-04-17 17:43
文章分类

全部博文(36)

分类: 网络与安全

2016-11-21 21:42:27

下载并安装rp-pppoe-server包

点击(此处)折叠或打开

  1. opgk update
  2. opkg install rp-pppoe-server
  3. cp /usr/lib/pppd/2.4.7/rp-pppoe.so /etc/ppp/plugins/rp-pppoe.so

修改/etc/init.d/pppoe-server

点击(此处)折叠或打开

  1. #!/bin/sh /etc/rc.common
  2. # Copyright (C) 2006-2011 OpenWrt.org

  3. START=50

  4. DEFAULT=/etc/default/pppoe-server


  5. start() {
  6.         [ -f $DEFAULT ] && . $DEFAULT
  7.         OPTIONS="-k -L 17.16.1.1 -R 172.16.1.100 -I eth0 -S 189"
  8.         service_start /usr/sbin/pppoe-server $OPTIONS
  9. }

  10. stop() {
  11.         service_stop /usr/sbin/pppoe-server
  12. }


修改/etc/ppp/options


  1. debug
  2. dump
  3. unit 100
  4. ms-dns 114.114.114.114
  5. ms-dns 10.168.10.11
  6. defaultroute
  7. logfile /dev/null
  8. noipdefault
  9. noaccomp
  10. nopcomp
  11. nocrtscts
  12. lock
  13. maxfail 0
  14. lcp-echo-failure 5
  15. lcp-echo-interval 1


修改/etc/ppp/pppoe-server-options

点击(此处)折叠或打开

  1. # PPP options for the PPPoE server
  2. # LIC: GPL
  3. require-chap
  4. #login
  5. lcp-echo-interval 10
  6. lcp-echo-failure 2

修改防火墙文件/etc/config/firewall

点击(此处)折叠或打开

  1. config defaults
  2.         option syn_flood 1
  3.         option input ACCEPT
  4.         option output ACCEPT
  5.         option forward REJECT
  6. # Uncomment this line to disable ipv6 rules
  7.         option disable_ipv6 1

  8. config zone
  9.         option name lan
  10.         list network 'lan'
  11.         option input ACCEPT
  12.         option output ACCEPT
  13.         option forward ACCEPT

  14. config zone
  15.         option name wan
  16.         list network 'wan'
  17.         list network 'wan6'
  18.         option input REJECT
  19.         option output ACCEPT
  20.         option forward REJECT
  21.         option masq 1
  22.         option mtu_fix 1

  23. config zone
  24.         option name 'ppp'
  25.         option device 'ppp1+'
  26.         option input 'ACCEPT'
  27.         option output 'ACCEPT'
  28.         option forward 'ACCEPT'

  29. config forwarding
  30.         option src lan
  31.         option dest wan

  32. config forwarding
  33.         option src ppp
  34.         option dest wan

  35. # We need to accept udp packets on port 68,
  36. # see https://dev.openwrt.org/ticket/4108
  37. config rule
  38.         option name Allow-DHCP-Renew
  39.         option src wan
  40.         option proto udp
  41.         option dest_port 68
  42.         option target ACCEPT
  43.         option family ipv4

  44. # Allow IPv4 ping
  45. config rule
  46.         option name Allow-Ping
  47.         option src wan
  48.         option proto icmp
  49.         option icmp_type echo-request
  50.         option family ipv4
  51.         option target ACCEPT

  52. # Allow DHCPv6 replies
  53. # see https://dev.openwrt.org/ticket/10381
  54. config rule
  55.         option name Allow-DHCPv6
  56.         option src wan
  57.         option proto udp
  58.         option src_ip fe80::/10
  59.         option src_port 547
  60.         option dest_ip fe80::/10
  61.         option dest_port 546
  62.         option family ipv6
  63.         option target ACCEPT

  64. # Allow essential incoming IPv6 ICMP traffic
  65. config rule
  66.         option name Allow-ICMPv6-Input
  67.         option src wan
  68.         option proto icmp
  69.         list icmp_type echo-request
  70.         list icmp_type echo-reply
  71.         list icmp_type destination-unreachable
  72.         list icmp_type packet-too-big
  73.         list icmp_type time-exceeded
  74.         list icmp_type bad-header
  75.         list icmp_type unknown-header-type
  76.         list icmp_type router-solicitation
  77.         list icmp_type neighbour-solicitation
  78.         list icmp_type router-advertisement
  79.         list icmp_type neighbour-advertisement
  80.         option limit 1000/sec
  81.         option family ipv6
  82.         option target ACCEPT

  83. # Allow essential forwarded IPv6 ICMP traffic
  84. config rule
  85.         option name Allow-ICMPv6-Forward
  86.         option src wan
  87.         option dest *
  88.         option proto icmp
  89.         list icmp_type echo-request
  90.         list icmp_type echo-reply
  91.         list icmp_type destination-unreachable
  92.         list icmp_type packet-too-big
  93.         list icmp_type time-exceeded
  94.         list icmp_type bad-header
  95.         list icmp_type unknown-header-type
  96.         option limit 1000/sec
  97.         option family ipv6
  98.         option target ACCEPT

  99. # include a file with users custom iptables rules
  100. config include
  101.         option path /etc/firewall.user


  102. ### EXAMPLE CONFIG SECTIONS
  103. # do not allow a specific ip to access wan
  104. #config rule
  105. # option src lan
  106. # option src_ip 192.168.45.2
  107. # option dest wan
  108. # option proto tcp
  109. # option target REJECT

  110. # block a specific mac on wan
  111. #config rule
  112. # option dest wan
  113. # option src_mac 00:11:22:33:44:66
  114. # option target REJECT

  115. # block incoming ICMP traffic on a zone
  116. #config rule
  117. # option src lan
  118. # option proto ICMP
  119. # option target DROP

  120. # port redirect port coming in on wan to lan
  121. #config redirect
  122. # option src wan
  123. # option src_dport 80
  124. # option dest lan
  125. # option dest_ip 192.168.16.235
  126. # option dest_port 80
  127. # option proto tcp

  128. # port redirect of remapped ssh port (22001) on wan
  129. #config redirect
  130. # option src wan
  131. # option src_dport 22001
  132. # option dest lan
  133. # option dest_port 22
  134. # option proto tcp

  135. # allow IPsec/ESP and ISAKMP passthrough
  136. #config rule
  137. # option src wan
  138. # option dest lan
  139. # option protocol esp
  140. # option target ACCEPT

  141. #config rule
  142. # option src wan
  143. # option dest lan
  144. # option src_port 500
  145. # option dest_port 500
  146. # option proto udp
  147. # option target ACCEPT

  148. ### FULL CONFIG SECTIONS
  149. #config rule
  150. # option src lan
  151. # option src_ip 192.168.45.2
  152. # option src_mac 00:11:22:33:44:55
  153. # option src_port 80
  154. # option dest wan
  155. # option dest_ip 194.25.2.129
  156. # option dest_port 120
  157. # option proto tcp
  158. # option target REJECT

  159. #config redirect
  160. # option src lan
  161. # option src_ip 192.168.45.2
  162. # option src_mac 00:11:22:33:44:55
  163. # option src_port 1024
  164. # option src_dport 80
  165. # option dest_ip 194.25.2.129
  166. # option dest_port 120
  167. # option proto tcp

阅读(2768) | 评论(0) | 转发(0) |
0

上一篇:openwrt fw3 命令笔记。

下一篇:scapy笔记

给主人留下些什么吧!~~