|
|
发表于 2011-2-11 22:27:09
|
显示全部楼层
参考RG200E-AB里的ebtables,初步作了一个:
' b: `7 s& i! b3 E5 Nebtables -L --Lc7 a- z( }: e0 ]
Bridge table: filter
% R+ @7 I3 g0 }
6 C9 R$ W9 n8 \0 W' s3 T: T: QBridge chain: INPUT, entries: 9, policy: ACCEPT
* N% q" }9 ?" l1 M. g5 H" Q-p PPP_DISC -i eth1 -j DROP , pcnt = 0 -- bcnt = 0
, h, a5 u: t' {( q4 s* l$ @* w( ~-p PPP_DISC -i eth2 -j DROP , pcnt = 0 -- bcnt = 0& V& A) @6 v8 e( ?( ?. r
-p PPP_DISC -i vlan85 -j DROP , pcnt = 3 -- bcnt = 1383 e: F. t1 n- \( n) }
-i vlan51 -j DROP , pcnt = 55741 -- bcnt = 75494176
( e% [5 d0 \$ K0 C8 t! }1 O8 F6 H) n `-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 2 -- bcnt = 1152
8 t0 p6 a% x, ~2 O3 \! M& [-p IPv6 -i vlan85 -j DROP , pcnt = 0 -- bcnt = 0
. U" z& I, x9 C! [" l: P-d Broadcast -i vlan85 -j ACCEPT , pcnt = 61 -- bcnt = 2806
5 y% v. q, S* F5 P-p IPv4 -i vlan85 --ip-dst ! 192.168.1.1 -j DROP , pcnt = 486 -- bcnt = 193328 ^* j( O' G) Z1 E( T
-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0' z- F* z2 E1 ?8 ~" I2 t' j
, y! T2 ]1 }- v, m x
Bridge chain: FORWARD, entries: 9, policy: ACCEPT
: D! j l+ R- e0 z( N& q) E-o vlan51 -j DROP , pcnt = 611 -- bcnt = 28742$ H8 \/ w" V! M) |& Y Q
-i vlan51 -o eth1 -j DROP , pcnt = 55685 -- bcnt = 75491600
& T) d. e) `4 j-i vlan51 -o eth2 -j DROP , pcnt = 55685 -- bcnt = 75491600) P7 z( B+ r* h, o" f3 D
-i vlan85 -o vlan51 -j ACCEPT , pcnt = 0 -- bcnt = 0
: Y2 j; \: e' e$ U-i vlan51 -o vlan85 -j ACCEPT , pcnt = 55685 -- bcnt = 75491600
! B) Z8 }% v& n8 h-o vlan85 -j DROP , pcnt = 76 -- bcnt = 6079
0 s. i8 \( d1 e# a+ w-i vlan85 -j DROP , pcnt = 2132 -- bcnt = 90284
! {- N9 W. E7 m, N-p IPv4 -i eth1 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
1 \4 F! F$ {, |& f-p IPv4 -i eth2 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
( h, l, H! V5 a
4 V/ _' H) m7 J5 UBridge chain: OUTPUT, entries: 2, policy: ACCEPT" |, l- L6 k* j m' R9 z; Z
-o vlan51 -j DROP , pcnt = 0 -- bcnt = 0
: S/ ` A4 D9 L. F( x-p IPv6 -o vlan85 -j DROP , pcnt = 0 -- bcnt = 0 |
|