iptables vs SPI vs GUI firewall rules

Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions
Author Message
TikiHead
DD-WRT Novice


Joined: 20 Jul 2016
Posts: 20

PostPosted: Fri May 26, 2017 12:33    Post subject: iptables vs SPI vs GUI firewall rules Reply with quote
Hi all,

From a lot of Googling (including this thread: http://www.dd-wrt.com/phpBB2/viewtopic.php?p=679345, it sounds to me like the way the firewall works in DD-WRT is this: DD-WRT comes with a simple SPI firewall and then any rules I write in the firewall script section of the GUI are applied as well, and that's it. I can browse the files in my router and see these rules in tmp\.rc_firewall

BUT when I look at the file tmp\.ipt (which I assume is an iptables file), there are a lot of extra rules, including prerouting rules, forwarding, etc.

There's really not one good place that explains how the firewall works, because I thought it was just SPI + my rules, but now I see this third thing as well. Can anyone explain to me, finally, how exactly the firewall works in DD-WRT?

Also, if I install Firewall Builder, does it bypass all the rules configured in DD-WRT?

Thanks!
Sponsor
mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 6268
Location: Texas

PostPosted: Fri May 26, 2017 14:09    Post subject: Reply with quote
http://www.dd-wrt.com/wiki/index.php/Firewall

http://www.dd-wrt.com/wiki/index.php/Firewall_Builder

Old stuff but maybe it will help whatever you are doing.

Any specific question you have about a certain firewall rule or network setup
probably better answered in the advanced networking forum.
http://www.dd-wrt.com/phpBB2/viewforum.php?f=53
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum