mirror of
https://github.com/vyos/vyos-documentation.git
synced 2025-12-16 10:32:02 +01:00
quick-start: adding missing rule to allow echo requests
This commit is contained in:
parent
5a57f5968d
commit
7e36b163bd
@ -300,25 +300,29 @@ group to 4 per minute:
|
|||||||
Allow Access to Services
|
Allow Access to Services
|
||||||
------------------------
|
------------------------
|
||||||
|
|
||||||
We can now configure access to the services running on this router, allowing
|
Here we're allowing the router to respond to pings. Then, we can allow access to
|
||||||
all connections coming from localhost:
|
the DNS recursor we configured earlier, accepting traffic bound for port 53 from
|
||||||
|
all hosts on the ``NET-INSIDE-v4`` network:
|
||||||
|
|
||||||
.. code-block:: none
|
.. code-block:: none
|
||||||
|
|
||||||
set firewall ipv4 input filter rule 30 action 'accept'
|
set firewall ipv4 input filter rule 30 action 'accept'
|
||||||
set firewall ipv4 input filter rule 30 source address 127.0.0.0/8
|
set firewall ipv4 input filter rule 30 icmp type-name 'echo-request'
|
||||||
|
set firewall ipv4 input filter rule 30 protocol 'icmp'
|
||||||
Finally, we can allow access to the DNS recursor we configured earlier,
|
set firewall ipv4 input filter rule 30 state new 'enable'
|
||||||
accepting traffic bound for port 53 from all hosts on the ``NET-INSIDE-v4``
|
|
||||||
network:
|
|
||||||
|
|
||||||
.. code-block:: none
|
|
||||||
|
|
||||||
set firewall ipv4 input filter rule 40 action 'accept'
|
set firewall ipv4 input filter rule 40 action 'accept'
|
||||||
set firewall ipv4 input filter rule 40 destination port '53'
|
set firewall ipv4 input filter rule 40 destination port '53'
|
||||||
set firewall ipv4 input filter rule 40 protocol 'tcp_udp'
|
set firewall ipv4 input filter rule 40 protocol 'tcp_udp'
|
||||||
set firewall ipv4 input filter rule 40 source group network-group NET-INSIDE-v4
|
set firewall ipv4 input filter rule 40 source group network-group NET-INSIDE-v4
|
||||||
|
|
||||||
|
Finally, we can now configure access to the services running on this router, allowing
|
||||||
|
all connections coming from localhost:
|
||||||
|
|
||||||
|
.. code-block:: none
|
||||||
|
|
||||||
|
set firewall ipv4 input filter rule 50 action 'accept'
|
||||||
|
set firewall ipv4 input filter rule 50 source address 127.0.0.0/8
|
||||||
|
|
||||||
Commit changes, save the configuration, and exit configuration mode:
|
Commit changes, save the configuration, and exit configuration mode:
|
||||||
|
|
||||||
.. code-block:: none
|
.. code-block:: none
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user