Routing example: PBR with netifd

uci set network.lan.ip4table="1"
uci set network.lan.ip6table="1"
uci set network.wan.ip4table="2"
uci set network.wan6.ip6table="2"
uci -q delete network.lan_wan
uci set network.lan_wan="rule"
uci set network.lan_wan.in="lan"
uci set network.lan_wan.lookup="2"
uci set network.lan_wan.priority="40000"
uci -q delete network.lan_wan6
uci set network.lan_wan6="rule6"
uci set network.lan_wan6.in="lan"
uci set network.lan_wan6.lookup="2"
uci set network.lan_wan6.priority="40000"
uci commit network
/etc/init.d/network restart
uci set network.lan.ip4table="1"
uci set network.lan.ip6table="1"
uci set network.vpn.ip4table="2"
uci set network.vpn.ip6table="2"
uci set network.dmz.ip4table="3"
uci set network.dmz.ip6table="3"
uci -q delete network.dmz_vpn
uci set network.dmz_vpn="rule"
uci set network.dmz_vpn.in="dmz"
uci set network.dmz_vpn.lookup="2"
uci set network.dmz_vpn.priority="30000"
uci -q delete network.dmz_vpn6
uci set network.dmz_vpn6="rule6"
uci set network.dmz_vpn6.in="dmz"
uci set network.dmz_vpn6.lookup="2"
uci set network.dmz_vpn6.priority="30000"
uci commit network
/etc/init.d/network restart
uci -q delete firewall.https_fwd
uci set firewall.https_fwd="rule"
uci set firewall.https_fwd.name="Forward-HTTPS"
uci set firewall.https_fwd.src="wan"
uci set firewall.https_fwd.src_dport="443"
uci set firewall.https_fwd.dest_ip="192.168.1.2"
uci set firewall.https_fwd.proto="tcp"
uci set firewall.https_fwd.target="DNAT"
uci -q delete firewall.https_mark
uci set firewall.https_mark="rule"
uci set firewall.https_mark.name="Mark-HTTPS"
uci set firewall.https_mark.src="lan"
uci set firewall.https_mark.src_ip="192.168.1.2"
uci set firewall.https_mark.src_port="443"
uci set firewall.https_mark.proto="tcp"
uci set firewall.https_mark.set_mark="0x1"
uci set firewall.https_mark.target="MARK"
uci commit firewall
/etc/init.d/firewall restart
uci set network.lan.ip4table="1"
uci set network.wan.ip4table="2"
uci -q delete network.lan_wan
uci set network.lan_wan="rule"
uci set network.lan_wan.in="lan"
uci set network.lan_wan.mark="1"
uci set network.lan_wan.lookup="2"
uci set network.lan_wan.priority="30000"
uci commit network
/etc/init.d/network restart
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.More information about cookies
  • Last modified: 2021/08/17 01:53
  • by vgaetera