_______________________________________________________________________________________________________
_______________________________________________________________________________________________________
© Virtual Access 2018
GW1000 Series User Manual
Issue: 2.3
Page 305 of 463
Web: Output
UCI: firewall.<zone label>.output
Opt: output
Default policy for outgoing zone traffic. Outgoing traffic is traffic
leaving the router through an interface selected in the 'Covered
Networks' option for this zone.
Accept
Accepted packets pass through the
firewall.
Reject
Rejected packets are blocked by the
firewall and ICMP message is returned to
the source host.
Drop
Dropped packets are blocked by the
firewall.
Web: Forward
UCI: firewall.<zone label>.forward
Opt: forward
Default policy for internal zone traffic between interfaces.
Forward rules for a zone describe what happens to traffic passing
between different interfaces within that zone.
Accept
Accepted packets pass through the
firewall.
Reject
Rejected packets are blocked by the
firewall and ICMP message is returned to
the source host.
Drop
Dropped packets are blocked by the
firewall.
Web: Masquerading
UCI: firewall.<zone label>.masq
Opt: masq
Specifies whether outgoing zone traffic should be masqueraded
(NATTED). This is typically enabled on the wan zone.
Web: MSS Clamping
UCI: firewall.<zone label>.mtu_fix
Opt: mtu_fix
Enables MSS clamping for outgoing zone traffic. Subnets are
allowed.
0
Disabled.
1
Enabled.
Web: Covered networks
UCI: firewall.<zone label>.network
Opt: network
Defines a list of interfaces attached to this zone, if omitted, the
value of name is used by default.
Note: use the uci list syntax to edit this setting through UCI.
Table 101: Information table for firewall zone general settings