[PATCH] firewall: provide examples of ssh port relocation on firewall and IPsec passt...
authorJo-Philipp Wich <jow@openwrt.org>
Mon, 2 May 2011 12:54:31 +0000 (12:54 +0000)
committerJo-Philipp Wich <jow@openwrt.org>
Mon, 2 May 2011 12:54:31 +0000 (12:54 +0000)
commit244b5fcbdb2795a5cf3a396445551fa3fee8e75d
tree873baee5758beda5d26b4efb77009a9892f8689d
parent5506e60734e447c505763a654fe93703781090cc
[PATCH] firewall: provide examples of ssh port relocation on firewall and IPsec passthrough
Two examples of potentially useful configurations (commented out, of course):

(a) map the ssh service running on the firewall to 22001 externally, without modifying the configuration of the daemon itself. this allows port 22 on the WAN side to then be port-forwarded to a
LAN-based machine if desired, or if not, simply obscures the port from external attack.

(b) allow IPsec/ESP and ISAKMP (UDP-based key exchange) to happen by default. useful for most modern VPN clients you might have on your WAN.

Signed-off-by: Philip Prindeville <philipp@redfish-solutions.com>
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@26805 3c298f89-4303-0410-b956-a3cf2f4a3e73
package/firewall/files/firewall.config
package/firewall/files/lib/core_interface.sh