firewall
rule 10 permit any from gui to gui
rule 20 permit dhcpv6 from all to all
rule 30 permit icmpv6 from all to all
rule 40 permit any from private_ipv6 to private_ipv6
rule 50 permit any from private_ipv6 to private_ipv6.lan.eth0
rule 60 permit any from private_ipv6 to public_ipv6
rule 70 permit any from private_ipv6.lan.eth0 to private_ipv6
rule 80 permit any from private_ipv6.lan.eth0 to public_ipv6
rule 90 permit any from public_ipv6.wan.eth1 to public_ipv6
protect
!
interface eth1
ipv6 enable
no ipv6 nd accept-ra-pinfo
ipv6 nd proxy interface eth0
!
interface eth0
ip address 192.168.1.2/24
ipv6 address autoconfig eth1
no ipv6 nd suppress-ra
ipv6 nd dns-server eth0
!
ipv6 forwarding
!
zone all
network ipv6
ipv6 subnet ::/0
!
zone gui
network ipv4
ip subnet 192.168.1.0/24
!
zone private_ipv6
network lan
ipv6 subnet ::/0 interface eth0
host eth0
ipv6 address dynamic interface eth0
!
zone public_ipv6
network wan
ipv6 subnet ::/0 interface eth1
host eth1
ipv6 address dynamic interface eth1
!
application dhcpv6
protocol udp
dport 546 to 547
!
application icmpv6
protocol ipv6-icmp
!
firewall
rule 10 permit any from gui to gui
rule 20 permit dhcpv6 from all to all
rule 30 permit icmpv6 from all to all
rule 40 permit any from private_ipv6 to private_ipv6
rule 50 permit any from private_ipv6 to private_ipv6.lan.eth0
rule 60 permit any from private_ipv6 to public_ipv6
rule 70 permit any from private_ipv6.lan.eth0 to private_ipv6
rule 80 permit any from private_ipv6.lan.eth0 to public_ipv6
rule 90 permit any from public_ipv6.wan.eth1 to public_ipv6
protect
!
ip dns forwarding
!
end