_______________________________________________________________________________________________________
_______________________________________________________________________________________________________
© Virtual Access 2018
GW2020 Series User Manual
Issue: 2.1
Page 269 of 423
28.2.1.4
Firewall zone: advanced settings
Figure 136: Firewall zone advanced settings
Web Field/UCI/Package Option
Description
Web: Restrict to address family
UCI: firewall.<zone label>.family
Opt: family
Restricts zone to IPv4, IPv6 or both IPv4 and IPv6.
Option
Description
UCI
IPv4 and
IPv6
Any address family
any
IPv4 only
IPv4 only
ipv4
IPv6 only
IPv6 only
Ipv6
Web: Restrict Masquerading to given
source subnets.
UCI: firewall.<zone label>.masq_src
Opt: masq_src
Limits masquerading to the given source subnets. Negation is
possible by prefixing the subnet with ‘!’. Multiple subnets are
allowed.
Web: Restrict Masquerading to given
destination subnets.
UCI: firewall.<zone label>.masq_dest
Opt: masq_dest
Limits masquerading to the given destination subnets. Negation
is possible by prefixing the subnet with ‘!’. Multiple subnets are
allowed. Multiple IP addresses/subnets should be separated by a
space, for example: option masq_dest ‘1.1.1.1 2.2.2.0/24’.
Web: Force connection tracking
UCI: firewall.<zone label>.conntrack
Opt: conntrack
Forces connection tracking for this zone.
0
Disabled.
1
If masquerading is used. Otherwise,
default is 0.
Web: Enable logging on this zone
UCI: firewall.<zone label>.log
Opt: log
Creates log rules for rejected and dropped traffic in this zone.
Web: Allow NAT reflections
UCI: firewall.<zone label>.reflection
Opt: reflection
Enable/disable all NAT reflections for this zone.
Note: For configs with a large number of firewall rules, disabling
NAT reflection will speed up load of firewall rules on interface
start.
0
Disable reflection.
1
Enable reflection.