firewall
rule 10 permit dhcpv4 from ipv4-internal.dhcp to ipv4-internal.dhcp
rule 20 permit any from ipv4-internal.lan to ipv4-internal.lan
rule 30 permit any from ipv4-internal.lan to ipv4-internet
rule 40 permit any from ipv4-internet.wan.tunnel0 to ipv4-internet
rule 100 permit any from ipv6-internal to ipv6-internal
rule 110 permit any from ipv6-internal to ipv6-internet
rule 120 permit any from ipv6-internal.lan.vlan1 to ipv6-internet
rule 130 permit any from ipv6-internet.wan.eth1 to ipv6-internet
rule 140 permit icmpv6 from ipv6-internet to ipv6-internal.lan.vlan1
rule 150 permit dhcpv6 from ipv6-internet to ipv6-internet.wan.eth1
protect
!
interface eth1
ipv6 enable
no ipv6 nd accept-ra-pinfo
ipv6 nd proxy interface vlan1
!
interface vlan1
ip address 192.168.10.1/24
ipv6 address autoconfig eth1
no ipv6 nd suppress-ra
ipv6 nd dns-server vlan1
!
ipv6 forwarding
!
ip dhcp pool pool10
network 192.168.10.0 255.255.255.0
range 192.168.10.100 192.168.10.131
dns-server 192.168.10.1
default-router 192.168.10.1
lease 0 2 0
!
service dhcp-server
!
interface tunnel0
tunnel source vlan1
tunnel destination gw.transix.jp
tunnel mode ds-lite
ip address 192.0.0.2/29
ip tcp adjust-mss pmtu
!
ip route 0.0.0.0/0 tunnel0
!
zone ipv4-internal
network dhcp
ip subnet 0.0.0.0/0 interface vlan1
network lan
ip subnet 192.168.10.0/24 interface vlan1
!
zone ipv4-internet
network wan
ip subnet 0.0.0.0/0 interface tunnel0
host tunnel0
ip address 192.0.0.2
!
zone ipv6-internal
network lan
ipv6 subnet ::/0 interface vlan1
host vlan1
ipv6 address dynamic interface vlan1
!
zone ipv6-internet
network wan
ipv6 subnet ::/0 interface eth1
host eth1
ipv6 address dynamic interface eth1
!
application dhcpv4
protocol udp
dport 67 to 68
!
application dhcpv6
protocol udp
dport 546 to 547
!
application icmpv6
protocol ipv6-icmp
!
firewall
rule 10 permit dhcpv4 from ipv4-internal.dhcp to ipv4-internal.dhcp
rule 20 permit any from ipv4-internal.lan to ipv4-internal.lan
rule 30 permit any from ipv4-internal.lan to ipv4-internet
rule 40 permit any from ipv4-internet.wan.tunnel0 to ipv4-internet
rule 100 permit any from ipv6-internal to ipv6-internal
rule 110 permit any from ipv6-internal to ipv6-internet
rule 120 permit any from ipv6-internal.lan.vlan1 to ipv6-internet
rule 130 permit any from ipv6-internet.wan.eth1 to ipv6-internet
rule 140 permit icmpv6 from ipv6-internet to ipv6-internal.lan.vlan1
rule 150 permit dhcpv6 from ipv6-internet to ipv6-internet.wan.eth1
protect
!
ip dns forwarding
!
end