Import miniupnpd from routing repo and bump to 20180422. Drop 102-ipv6-ext-port.patch as this looks upstreamed in the pinhole code to me. Consolidate all other patches & update with a view to sending upstream. Add support for runtime IGDv1 mode switch (default to IGDv2) (not extensively) Tested-on: ar71xx Archer C7 v2 in IGDv1 compatibility mode. A variety of devices/applications appear to be able to create mappings. Have an attempt at resolving https://github.com/openwrt-routing/packages/issues/286 TL;DR miniupnpd rules get processed before fw3 rules and thus can override existing/intended redirects. Ideally the miniupnpd rules would be last in the relevant chains, unfortunately fw3 can sometimes use the last rule as a REJECT. Put miniupnpd rules as penultimate. Signed-off-by: Kevin Darbyshire-Bryant <ldir@darbyshire-bryant.me.uk>
28 lines
695 B
Text
28 lines
695 B
Text
config upnpd config
|
|
option enabled 0
|
|
option enable_natpmp 1
|
|
option enable_upnp 1
|
|
option secure_mode 1
|
|
option log_output 0
|
|
option download 1024
|
|
option upload 512
|
|
#by default, looked up dynamically from ubus
|
|
# option external_iface wan
|
|
option internal_iface lan
|
|
option port 5000
|
|
option upnp_lease_file /var/upnp.leases
|
|
option igdv1 0
|
|
|
|
config perm_rule
|
|
option action allow
|
|
option ext_ports 1024-65535
|
|
option int_addr 0.0.0.0/0 # Does not override secure_mode
|
|
option int_ports 1024-65535
|
|
option comment "Allow high ports"
|
|
|
|
config perm_rule
|
|
option action deny
|
|
option ext_ports 0-65535
|
|
option int_addr 0.0.0.0/0
|
|
option int_ports 0-65535
|
|
option comment "Default deny"
|