Skip to content

Instantly share code, notes, and snippets.

@111a5ab1
Last active July 3, 2018 15:11
Show Gist options
  • Star 1 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save 111a5ab1/b3eb2e87b32129ddf84bf1c41914cf43 to your computer and use it in GitHub Desktop.
Save 111a5ab1/b3eb2e87b32129ddf84bf1c41914cf43 to your computer and use it in GitHub Desktop.
EdgeOS CLI: "Martian" packet firewall groups
delete firewall group address-group martians-v4-adr
delete firewall group network-group martians-v4-net
delete firewall group ipv6-address-group martians-v6-adr
delete firewall group ipv6-network-group martians-v6-net
delete firewall group ipv6-network-group martians6to4-v6-net
delete firewall group ipv6-network-group martiansTeredo-v6-net
set firewall group address-group martians-v4-adr description "IPv4 addresses reserved for special-use by IANA that should never appear on the public Internet"
set firewall group address-group martians-v4-adr address 255.255.255.255
set firewall group network-group martians-v4-net description "IPv4 networks reserved for special-use by IANA that should never appear on the public Internet"
set firewall group network-group martians-v4-net network 0.0.0.0/8
set firewall group network-group martians-v4-net network 10.0.0.0/8
set firewall group network-group martians-v4-net network 100.64.0.0/10
set firewall group network-group martians-v4-net network 127.0.0.0/8
set firewall group network-group martians-v4-net network 169.254.0.0/16
set firewall group network-group martians-v4-net network 172.16.0.0/12
set firewall group network-group martians-v4-net network 192.0.0.0/24
set firewall group network-group martians-v4-net network 192.0.2.0/24
set firewall group network-group martians-v4-net network 192.168.0.0/16
set firewall group network-group martians-v4-net network 198.18.0.0/15
set firewall group network-group martians-v4-net network 198.51.100.0/24
set firewall group network-group martians-v4-net network 203.0.113.0/24
set firewall group network-group martians-v4-net network 224.0.0.0/4
set firewall group network-group martians-v4-net network 240.0.0.0/4
set firewall group ipv6-address-group martians-v6-adr description "IPv6 addresses reserved for special-use by IANA that should never appear on the public Internet"
set firewall group ipv6-address-group martians-v6-adr ipv6-address ::
set firewall group ipv6-address-group martians-v6-adr ipv6-address ::1
set firewall group ipv6-network-group martians-v6-net description "IPv6 networks reserved for special-use by IANA that should never appear on the public Internet"
set firewall group ipv6-network-group martians-v6-net ipv6-network ::ffff:0:0/96
set firewall group ipv6-network-group martians-v6-net ipv6-network ::/96
set firewall group ipv6-network-group martians-v6-net ipv6-network 100::/64
set firewall group ipv6-network-group martians-v6-net ipv6-network 2001:10::/28
set firewall group ipv6-network-group martians-v6-net ipv6-network 2001:db8::/32
set firewall group ipv6-network-group martians-v6-net ipv6-network fc00::/7
set firewall group ipv6-network-group martians-v6-net ipv6-network fe80::/10
set firewall group ipv6-network-group martians-v6-net ipv6-network fec0::/10
set firewall group ipv6-network-group martians-v6-net ipv6-network ff00::/8
set firewall group ipv6-network-group martians6to4-v6-net description "6to4 IPv6 transition addresses corresponding to IPv4 martians that should never appear on the public Internet"
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002::/24
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002:a00::/24
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002:7f00::/24
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002:a9fe::/32
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002:ac10::/28
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002:c000::/40
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002:c000:200::/40
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002:c0a8::/32
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002:c612::/31
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002:c633:6400::/40
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002:cb00:7100::/40
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002:e000::/20
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002:f000::/20
set firewall group ipv6-network-group martians6to4-v6-net ipv6-network 2002:ffff:ffff::/48
set firewall group ipv6-network-group martiansTeredo-v6-net description "Teredo IPv6 transition addresses corresponding to IPv4 martians that should never appear on the public Internet"
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001::/40
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001:0:a00::/40
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001:0:7f00::/40
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001:0:a9fe::/48
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001:0:ac10::/44
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001:0:c000::/56
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001:0:c000:200::/56
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001:0:c0a8::/48
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001:0:c612::/47
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001:0:c633:6400::/56
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001:0:cb00:7100::/56
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001:0:e000::/36
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001:0:f000::/36
set firewall group ipv6-network-group martiansTeredo-v6-net ipv6-network 2001:0:ffff:ffff::/64
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment