OpenWrt, limit the access to the internet

September 3rd, 2009

I just tried a Linksys WRT54GL. It’s nice, but what if you have to add hotspot services on it.
I have installed Coova for fun.
A common scenario is to have anonymous clients accessing it with all kind of systems, all kind of software and, of-course, viruses trojans.
So, just to be prepared you want to allow access only to a few ports: 80 (http), 443 (https), 5222 (jabber), 5050 (yahoo messenger), 1863 (MSN), etc.

All you have to do is to add the following two lines in /etc/firewall.user below “Allow SSH on the WAN interface” section:
iptables -A forwarding_rule -i br0 -m multiport --dports 80,443,5222,5050,1863 -j ACCEPT
iptables -A forwarding_rule -i br0 -j DROP

Now restart the firewall:
/etc/init.d/S35firewall restart

That’s all.

Zone-Based Policy Firewall links

October 16th, 2008

I am using this type of cisco firewall on some routers, but I wanted to read more on this topic.
Searching google gave just a few quality links.
Here is what I have found:


The second was found on techrepublic.


If you have more interesting links on this topic please let me know.