Protocol Source Port Destination Port Gateway Schedule Description Automatically generated rules IN IPv6 UDP fe80::/10 * fe80::/10,ff02::/16 546 * * allow access to DHCPv6 server on LAN IN IPv6 UDP fe80::/10 * ff02::/16 547 * * allow access to DHCPv6 server on LAN IN IPv6 UDP ff02::/16 * fe80::/10 547 * * allow access to DHCPv6 server on LAN IN IPv6 UDP fe80::/10 * (self) 546 * * allow access to DHCPv6 server on LAN OUT IPv6 UDP (self) 547 fe80::/10 * * * allow access to DHCPv6 server on LAN IN IPv4 UDP * 68 255.255.255.255 67 * * allow access to DHCP server IN IPv4+6 UDP * 68 (self) 67 * * allow access to DHCP server OUT IPv4+6 UDP (self) 67 * 68 * * allow access to DHCP server IN IPv4+6 TCP * * (self) 22 80 443 * * anti-lockout rule IN IPv4 * LAN net * * * * * Default allow LAN to any rule IN IPv6 * LAN net * * * * * Default allow LAN IPv6 to any rule OUT IPv4+6 * * * * * * *
Protocol Source Port Destination Port Gateway Schedule Description IN IPv4+6 * * * * * * * OUT IPv4+6 * * * * * * *
dev ovpns1verb 3dev-type tuntun-ipv6dev-node /dev/tun1writepid /var/run/openvpn_server1.pidscript-security 3daemonkeepalive 10 60ping-timer-rempersist-tunpersist-keyproto tcp6-servercipher AES-256-CBCauth SHA256up /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkupdown /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkdownlocal 2a00:6020:XXXX:YYYY:ZZZZ:AAAA:BBBB:c0bdclient-connect "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_setup_cso.php server1"tls-serverserver 10.8.87.0 255.255.255.0client-config-dir /var/etc/openvpn-csc/1tls-verify "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_auth_verify tls 'OpenVPN-Server' 1"lport 1194management /var/etc/openvpn/server1.sock unixmax-clients 4push "route 192.168.187.0 255.255.255.0"push "redirect-gateway def1"client-to-clientca /var/etc/openvpn/server1.cacert /var/etc/openvpn/server1.certkey /var/etc/openvpn/server1.keydh /usr/local/etc/dh-parameters.2048.sampletls-auth /var/etc/openvpn/server1.tls-auth 0comp-lzo adaptivepersist-remote-ipfloattopology subnet
dev tunpersist-tunpersist-keyproto tcpcipher AES-256-CBCauth SHA512clientresolv-retry infiniteremote ABC.deport 18652lport 0remote-cert-tls servercomp-lzo adaptiveauth-nocache<ca>...</ca>key-direction 1