diff --git a/package/network/config/firewall/Makefile b/package/network/config/firewall/Makefile
index 6fb82c49dab3ce1edcfc3df7b28d59d70b24aa28..0f52ab98dae041aa572774a5eeeb7522bfef96c2 100644
--- a/package/network/config/firewall/Makefile
+++ b/package/network/config/firewall/Makefile
@@ -9,7 +9,7 @@
 include $(TOPDIR)/rules.mk
 
 PKG_NAME:=firewall
-PKG_RELEASE:=1
+PKG_RELEASE:=2
 
 PKG_SOURCE_PROTO:=git
 PKG_SOURCE_URL=$(LEDE_GIT)/project/firewall3.git
diff --git a/package/network/config/firewall/files/firewall.config b/package/network/config/firewall/files/firewall.config
index 749dbecb974d9f8055d900f4790da72a96cb7f1e..8874e9882c3083932fc90e061739dc265992eb61 100644
--- a/package/network/config/firewall/files/firewall.config
+++ b/package/network/config/firewall/files/firewall.config
@@ -114,6 +114,21 @@ config rule
 	option family		ipv6
 	option target		ACCEPT
 
+config rule
+	option name		Allow-IPSec-ESP
+	option src		wan
+	option dest		lan
+	option proto		esp
+	option target		ACCEPT
+
+config rule
+	option name		Allow-ISAKMP
+	option src		wan
+	option dest		lan
+	option dest_port	500
+	option proto		udp
+	option target		ACCEPT
+
 # include a file with users custom iptables rules
 config include
 	option path /etc/firewall.user
@@ -157,20 +172,6 @@ config include
 #	option dest_port	22
 #	option proto		tcp
 
-# allow IPsec/ESP and ISAKMP passthrough
-config rule
-	option src		wan
-	option dest		lan
-	option proto		esp
-	option target		ACCEPT
-
-config rule
-	option src		wan
-	option dest		lan
-	option dest_port	500
-	option proto		udp
-	option target		ACCEPT
-
 ### FULL CONFIG SECTIONS
 #config rule
 #	option src		lan