# Chang firewall to statue firewallset firewall state-policy established action 'accept'set firewall state-policy related action 'accept'set firewall state-policy invalid action 'drop'# Set Zone for interfacesset zone-policy zone dmz interface 'eth1'set zone-policy zone private interface 'eth2'set zone-policy zone local local-zone
set zone-policy zone public interface 'pppoe0'# define firewall policyset firewall name dmz-local default-action 'drop'set firewall name dmz-local rule 10 action 'accept'set firewall name dmz-local rule 10 destination address '192.168.68.1'set firewall name dmz-local rule 10 destination port '53'set firewall name dmz-local rule 10 protocol 'udp'set firewall name dmz-local rule 11 action 'accept'set firewall name dmz-local rule 11 icmp type-name 'echo-request'set firewall name dmz-local rule 11 protocol 'icmp'set firewall name dmz-private default-action 'drop'set firewall name dmz-private rule 10 action 'accept'set firewall name dmz-private rule 10 destination address '192.168.68.1'set firewall name dmz-private rule 10 destination port '53'set firewall name dmz-private rule 10 protocol 'udp'set firewall name dmz-public default-action 'accept'set firewall name local-dmz default-action 'accept'set firewall name local-private default-action 'accept'set firewall name local-public default-action 'accept'set firewall name private-dmz default-action 'accept'set firewall name private-local default-action 'accept'# Allow pingset firewall name private-local rule 1 action 'accept'set firewall name private-local rule 1 icmp type-name 'echo-request'set firewall name private-local rule 1 protocol 'icmp'set firewall name private-public default-action 'accept'set firewall name public-dmz default-action 'drop'set firewall name public-local default-action 'drop'set firewall name public-private default-action 'drop'set zone-policy zone dmz default-action 'drop'set zone-policy zone private default-action 'drop'set zone-policy zone public default-action 'drop'set zone-policy zone dmz from local firewall name 'local-dmz'set zone-policy zone dmz from private firewall name 'private-dmz'set zone-policy zone dmz from public firewall name 'public-dmz'set zone-policy zone local from dmz firewall name 'dmz-local'set zone-policy zone local from private firewall name 'private-local'set zone-policy zone local from public firewall name 'public-local'set zone-policy zone private from dmz firewall name 'dmz-private'set zone-policy zone private from local firewall name 'local-private'set zone-policy zone private from public firewall name 'public-private'set zone-policy zone public from dmz firewall name 'dmz-public'set zone-policy zone public from local firewall name 'local-public'set zone-policy zone public from private firewall name 'private-public'set firewall all-ping 'enable'set firewall broadcast-ping 'disable'set firewall config-trap 'disable'set firewall receive-redirects 'disable'set firewall send-redirects 'enable'set firewall source-validation 'disable'set firewall syn-cookies 'enable'set firewall twa-hazards-protection 'disable'set firewall ip-src-route 'disable'set firewall ipv6-receive-redirects 'disable'set firewall ipv6-src-route 'disable'set firewall log-martians 'enable'commit
save