Technical data
4. Packages
• All IPv6 address strings (including IP_NET_x etc.) must be enclosed in square brack-
ets if followed by a port or a port range.
Examples:
PF6_OUTPUT_1='tmpl:ftp IPV6_NET_1 ACCEPT HELPER:ftp'
PF6_OUTPUT_x_COMMENT This variable contains a description or comment to the as-
sociated OUTPUT rule.
Example: PF6_OUTPUT_3_COMMENT='no␣samba␣traffic␣allowed'
PF6_USR_CHAIN_N This variable holds the number of IPv6-firewall tables defined by the
user. For a detailed description see the documentation of PF_USR_CHAIN_N.
Default setting: PF6_USR_CHAIN_N='0'
PF6_USR_CHAIN_x_NAME This variable contains the name of the according user defined
IPv6-Firewall table. For a detailed description see the documentation of PF_USR_CHAIN_x_NAME.
Example: PF6_USR_CHAIN_1_NAME='usr-myvpn'
PF6_USR_CHAIN_x_RULE_N This variable contains the number of IPv6-firewall rules
in the according user defined IPv6-firewall table. For a detailed description see the
documentation of PF_USR_CHAIN_x_RULE_N.
Example: PF6_USR_CHAIN_1_RULE_N='0'
PF6_USR_CHAIN_x_RULE_x This variable specifies a rule for the user defined IPv6-
firewall table. For a detailed description see the documentation of PF_USR_CHAIN_x_RULE_x.
Differences regarding the IPv4-firewall:
• IPV6_NET_x has to be used instead of IP_NET_x.
• IPV6_ROUTE_x has to be used instead of IP_ROUTE_x.
• IPv6-addresses must be enclosed in square brackets (including the network mask, if
present).
• All IPv6 address strings (including IP_NET_x etc.) must be enclosed in square brack-
ets if a port or a port range follows.
PF6_USR_CHAIN_x_RULE_x_COMMENT This variable holds a description or a com-
ment for the rule it belongs to.
Example: PF6_USR_CHAIN_1_RULE_1_COMMENT='some␣user-defined␣rule'
PF6_POSTROUTING_N This variable contains the number of IPv6 firewall rules for mask-
ing (POSTROUTING chain). For a more detailed description, see the documentation of
variable PF_POSTROUTING_N.
Example: PF6_POSTROUTING_N='2'
PF6_POSTROUTING_x PF6_POSTROUTING_x_COMMENT
A list of rules that describe which IPv6 packets are masked by the router (or will be
forwarded unmasked). For a more detailed description see the documentation of variable
PF_POSTROUTING_x.
144










