|
|
发表于 2011-2-11 22:27:09
|
显示全部楼层
参考RG200E-AB里的ebtables,初步作了一个:8 Q+ B; l' M: {4 k* @
ebtables -L --Lc
! M" s0 o( U8 s0 hBridge table: filter
3 H6 k1 {# N5 i# A* w- |
+ B8 E% z" g( [# y$ D8 @Bridge chain: INPUT, entries: 9, policy: ACCEPT+ y/ o8 y' [' R3 l8 i3 H# v
-p PPP_DISC -i eth1 -j DROP , pcnt = 0 -- bcnt = 0+ n( L3 F. Q- j9 ?; b
-p PPP_DISC -i eth2 -j DROP , pcnt = 0 -- bcnt = 0
+ F' w' ]4 B5 r4 n+ `) f-p PPP_DISC -i vlan85 -j DROP , pcnt = 3 -- bcnt = 138( \/ s* e! @/ N, L) y9 ~7 u
-i vlan51 -j DROP , pcnt = 55741 -- bcnt = 75494176) c: B4 M& i1 x
-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 2 -- bcnt = 1152
* ~# I) e/ t$ P1 V6 `: ^% L* |-p IPv6 -i vlan85 -j DROP , pcnt = 0 -- bcnt = 0
: x) w- ^, i1 o-d Broadcast -i vlan85 -j ACCEPT , pcnt = 61 -- bcnt = 2806
# e$ a" B) p+ `. ^-p IPv4 -i vlan85 --ip-dst ! 192.168.1.1 -j DROP , pcnt = 486 -- bcnt = 19332# x- K# i" ] N; D; O
-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0" ]4 ^1 z# A, T6 D
5 [; x: ]3 Y ^$ YBridge chain: FORWARD, entries: 9, policy: ACCEPT
( g& \6 G5 U' Q L-o vlan51 -j DROP , pcnt = 611 -- bcnt = 28742: c; k+ r% E4 u' L8 t& G
-i vlan51 -o eth1 -j DROP , pcnt = 55685 -- bcnt = 75491600
/ z- B* U7 Z" }" l- S-i vlan51 -o eth2 -j DROP , pcnt = 55685 -- bcnt = 75491600& A: t9 G( W; j8 K9 b% w, U
-i vlan85 -o vlan51 -j ACCEPT , pcnt = 0 -- bcnt = 05 ?- v; b' J" X2 z1 a' L* L
-i vlan51 -o vlan85 -j ACCEPT , pcnt = 55685 -- bcnt = 75491600
/ {, B" {8 w3 V0 I/ x( K-o vlan85 -j DROP , pcnt = 76 -- bcnt = 6079# A+ _9 k8 a( b+ j9 k d% j
-i vlan85 -j DROP , pcnt = 2132 -- bcnt = 902840 u5 B) t# |3 K6 k
-p IPv4 -i eth1 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
: A& e- u7 B' O) p h) Z. {-p IPv4 -i eth2 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
. i+ T" _, U9 a+ u9 A3 c/ O% {" b0 v+ O% D' V* D/ d |! K& p% `& [ k
Bridge chain: OUTPUT, entries: 2, policy: ACCEPT! A9 p' \6 }, }- w" U$ `
-o vlan51 -j DROP , pcnt = 0 -- bcnt = 0 _5 f* o1 d# {" [$ ~* B, [
-p IPv6 -o vlan85 -j DROP , pcnt = 0 -- bcnt = 0 |
|