#21623: TP-LINK 3020 no internet on wan
------------------------------+-----------------------------
  Reporter:  pavel.masloff@…  |      Owner:  developers
      Type:  defect           |     Status:  closed
  Priority:  normal           |  Milestone:
 Component:  packages         |    Version:  Trunk
Resolution:  not_a_bug        |   Keywords:  wan tplink-3020
------------------------------+-----------------------------

Comment (by pavel.masloff@…):

 Wrire now I ve done the "Unbridge LAN interfaces" part and here is what I
 got:

 /etc/config/network
 {{{
 config interface 'loopback'
         option ifname 'lo'
         option proto 'static'
         option ipaddr '127.0.0.1'
         option netmask '255.0.0.0'

 config interface 'lan'
         option proto 'static'
         option netmask '255.255.255.0'
         option ip6assign '60'
         option ipaddr '10.80.1.1'

 config interface 'WAN'
         option proto 'dhcp'
         option ifname 'eth0'

 }}}


 /etc/config/wireless

 {{{
 config wifi-device 'radio0'
         option type 'mac80211'
         option channel '11'
         option hwmode '11g'
         option path 'platform/ar933x_wmac'
         option htmode 'HT20'
         option txpower '18'
         option country 'US'
         list ht_capab 'SHORT-GI-20'
         list ht_capab 'SHORT-GI-40'
         list ht_capab 'RX-STBC1'
         list ht_capab 'DSSS_CCK-40'

 config wifi-iface
         option device 'radio0'
         option network 'lan'
         option mode 'ap'
         option ssid 'maslick-sr'
         option encryption 'psk2+ccmp'
         option key 'password123'
 }}}

 /etc/config/dhcp

 {{{
 config dnsmasq
         option domainneeded '1'
         option boguspriv '1'
         option filterwin2k '0'
         option localise_queries '1'
         option rebind_protection '1'
         option rebind_localhost '1'
         option local '/lan/'
         option domain 'lan'
         option expandhosts '1'
         option nonegcache '0'
         option authoritative '1'
         option readethers '1'
         option leasefile '/tmp/dhcp.leases'
         option resolvfile '/tmp/resolv.conf.auto'
         option localservice '1'

 config dhcp 'lan'
         option interface 'lan'
         option leasetime '12h'
         option dhcpv6 'server'
         option ra 'server'
         option start '10'
         option limit '20'

 config dhcp 'wan'
         option interface 'wan'
         option ignore '1'

 config odhcpd 'odhcpd'
         option maindhcp '0'
         option leasefile '/tmp/hosts/odhcpd'
         option leasetrigger '/usr/sbin/odhcpd-update'

 }}}



 /etc/config/firewall

 {{{
 config defaults
         option syn_flood '1'
         option input 'ACCEPT'
         option output 'ACCEPT'
         option forward 'REJECT'

 config zone
         option name 'lan'
         list network 'lan'
         option input 'ACCEPT'
         option output 'ACCEPT'
         option forward 'ACCEPT'

 config zone
         option name 'wan'
         option input 'REJECT'
         option output 'ACCEPT'
         option forward 'REJECT'
         option masq '1'
         option mtu_fix '1'
         option network 'wan wan6 WAN'

 config forwarding
         option src 'lan'
         option dest 'wan'

 config rule
         option name 'Allow-DHCP-Renew'
         option src 'wan'
         option proto 'udp'
         option dest_port '68'
         option target 'ACCEPT'
         option family 'ipv4'

 config rule
         option name 'Allow-Ping'
         option src 'wan'
         option proto 'icmp'
         option icmp_type 'echo-request'
         option family 'ipv4'
         option target 'ACCEPT'

 config rule
         option name 'Allow-IGMP'
         option src 'wan'
         option proto 'igmp'
         option family 'ipv4'
         option target 'ACCEPT'

 config rule
         option name 'Allow-DHCPv6'
         option src 'wan'
         option proto 'udp'
         option src_ip 'fc00::/6'
         option dest_ip 'fc00::/6'
         option dest_port '546'
         option family 'ipv6'
         option target 'ACCEPT'

 config rule
         option name 'Allow-MLD'
         option src 'wan'
         option proto 'icmp'
         option src_ip 'fe80::/10'
         list icmp_type '130/0'
         list icmp_type '131/0'
         list icmp_type '132/0'
         list icmp_type '143/0'
         option family 'ipv6'
         option target 'ACCEPT'

 config rule
         option name 'Allow-ICMPv6-Input'
         option src 'wan'
         option proto 'icmp'
         list icmp_type 'echo-request'
         list icmp_type 'echo-reply'
         list icmp_type 'destination-unreachable'
         list icmp_type 'packet-too-big'
         list icmp_type 'time-exceeded'
         list icmp_type 'bad-header'
         list icmp_type 'unknown-header-type'
         list icmp_type 'router-solicitation'
         list icmp_type 'neighbour-solicitation'
         list icmp_type 'router-advertisement'
         list icmp_type 'neighbour-advertisement'
         option limit '1000/sec'
         option family 'ipv6'
         option target 'ACCEPT'

 config rule
         option name 'Allow-ICMPv6-Forward'
         option src 'wan'
         option dest '*'
         option proto 'icmp'
         list icmp_type 'echo-request'
         list icmp_type 'echo-reply'
         list icmp_type 'destination-unreachable'
         list icmp_type 'packet-too-big'
         list icmp_type 'time-exceeded'
         list icmp_type 'bad-header'
         list icmp_type 'unknown-header-type'
         option limit '1000/sec'
         option family 'ipv6'
         option target 'ACCEPT'

 config include
         option path '/etc/firewall.user'

 config rule
         option src 'wan'
         option dest 'lan'
         option proto 'esp'
         option target 'ACCEPT'

 config rule
         option src 'wan'
         option dest 'lan'
         option dest_port '500'
         option proto 'udp'
         option target 'ACCEPT'
 }}}

--
Ticket URL: <https://dev.openwrt.org/ticket/21623#comment:3>
OpenWrt <http://openwrt.org>
Opensource Wireless Router Technology
_______________________________________________
openwrt-tickets mailing list
[email protected]
https://lists.openwrt.org/cgi-bin/mailman/listinfo/openwrt-tickets

Reply via email to