2008-12-09 17:50:17 +01:00
|
|
|
#
|
2016-04-05 19:20:55 +02:00
|
|
|
# Shorewall6 -- /usr/share/shorewall6/action.AllowICMPs
|
2008-12-09 17:50:17 +01:00
|
|
|
#
|
2016-04-05 19:20:55 +02:00
|
|
|
# This action ACCEPTs needed ICMP types
|
2008-12-09 17:50:17 +01:00
|
|
|
#
|
|
|
|
###############################################################################
|
2016-04-05 19:20:55 +02:00
|
|
|
#ACTION SOURCE DEST PROTO DPORT
|
2011-07-04 16:13:32 +02:00
|
|
|
|
|
|
|
DEFAULTS ACCEPT
|
|
|
|
|
2012-12-23 19:49:32 +01:00
|
|
|
?COMMENT Needed ICMP types (RFC4890)
|
2008-12-09 17:50:17 +01:00
|
|
|
|
2011-07-04 16:13:32 +02:00
|
|
|
$1 - - ipv6-icmp destination-unreachable
|
|
|
|
$1 - - ipv6-icmp packet-too-big
|
|
|
|
$1 - - ipv6-icmp time-exceeded
|
|
|
|
$1 - - ipv6-icmp parameter-problem
|
2008-12-12 01:05:51 +01:00
|
|
|
|
|
|
|
# The following should have a ttl of 255 and must be allowed to transit a bridge
|
2011-07-04 16:13:32 +02:00
|
|
|
$1 - - ipv6-icmp router-solicitation
|
|
|
|
$1 - - ipv6-icmp router-advertisement
|
|
|
|
$1 - - ipv6-icmp neighbour-solicitation
|
|
|
|
$1 - - ipv6-icmp neighbour-advertisement
|
|
|
|
$1 - - ipv6-icmp 137 # Redirect
|
|
|
|
$1 - - ipv6-icmp 141 # Inverse neighbour discovery solicitation
|
|
|
|
$1 - - ipv6-icmp 142 # Inverse neighbour discovery advertisement
|
2008-12-12 01:05:51 +01:00
|
|
|
|
|
|
|
# The following should have a link local source address and must be allowed to transit a bridge
|
2011-07-04 16:13:32 +02:00
|
|
|
$1 fe80::/10 - ipv6-icmp 130 # Listener query
|
|
|
|
$1 fe80::/10 - ipv6-icmp 131 # Listener report
|
|
|
|
$1 fe80::/10 - ipv6-icmp 132 # Listener done
|
|
|
|
$1 fe80::/10 - ipv6-icmp 143 # Listener report v2
|
2008-12-12 01:05:51 +01:00
|
|
|
|
|
|
|
# The following should be received with a ttl of 255 and must be allowed to transit a bridge
|
2011-07-04 16:13:32 +02:00
|
|
|
$1 - - ipv6-icmp 148 # Certificate path solicitation
|
|
|
|
$1 - - ipv6-icmp 149 # Certificate path advertisement
|
2008-12-12 01:05:51 +01:00
|
|
|
|
|
|
|
# The following should have a link local source address and a ttl of 1 and must be allowed to transit abridge
|
2011-07-04 16:13:32 +02:00
|
|
|
$1 fe80::/10 - ipv6-icmp 151 # Multicast router advertisement
|
|
|
|
$1 fe80::/10 - ipv6-icmp 152 # Multicast router solicitation
|
|
|
|
$1 fe80::/10 - ipv6-icmp 153 # Multicast router termination
|