[luci] Question on luci-fw

Jo-Philipp Wich xm at subsignal.org
Tue Dec 15 11:13:37 CET 2009


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi Saverio.

> I see the following dir is empty:
> http://luci.subsignal.org/trac/browser/luci/trunk/applications/luci-fw/root/etc/init.d
> I guess because the /etc/init.d/firewall is shipped with OpenWRT correct ?

Yes, at this point LuCI is just a frontend for OpenWrt's firewall
implementation.

>  [...], but
> also I have to modify uci_firewall.sh so that it is able to insert the
> custom rules.

You're correct. For Freifunk I utilized hotplug handlers to support some
nonstandard extensions to /etc/config/firewall to avoid having to patch
the OpenWrt firewall, see this link for information:

http://wiki.openwrt.org/doc/uci/firewall#hotplug.hooks.8.09.2

> Think as an example of iptables rules having as a target NFQUEUE and
> you have to specify --queue number

Nice, is this intended for QoS?

> am I correct ? thanks :)

Absolutely.


Regards,
JoW
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAksnYU0ACgkQdputYINPTPORTgCdEF2GQbwzPkIDdS3ZL79cIUMm
Rf4AnAj3nEfEIIMVUJg8+vupHItfi5V3
=NUWy
-----END PGP SIGNATURE-----


More information about the luci mailing list