|
发表于 2011-2-11 22:27:09
|
显示全部楼层
参考RG200E-AB里的ebtables,初步作了一个:6 b; `* m; O- y( _
ebtables -L --Lc6 ^; I( P5 f$ i1 [4 a8 P" p7 K
Bridge table: filter0 Q7 D( ^. a* T" }5 i ]( W g# @
5 W7 e) S! [) ~2 ^2 K9 b9 `. |Bridge chain: INPUT, entries: 9, policy: ACCEPT0 X+ `! P v) J- J
-p PPP_DISC -i eth1 -j DROP , pcnt = 0 -- bcnt = 03 y% S* o% N# C5 t8 B7 G' w, ~
-p PPP_DISC -i eth2 -j DROP , pcnt = 0 -- bcnt = 0# I0 K5 S1 u7 U* p9 {9 k
-p PPP_DISC -i vlan85 -j DROP , pcnt = 3 -- bcnt = 138# p& ]& o( K) k4 f
-i vlan51 -j DROP , pcnt = 55741 -- bcnt = 754941765 Z1 N) b2 Z& q4 q5 D. N
-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 2 -- bcnt = 11526 z1 J: N' j, F7 d2 ^+ t
-p IPv6 -i vlan85 -j DROP , pcnt = 0 -- bcnt = 0
: @/ @1 _5 Z7 e3 y% O-d Broadcast -i vlan85 -j ACCEPT , pcnt = 61 -- bcnt = 28060 U3 A0 E3 P ^9 }
-p IPv4 -i vlan85 --ip-dst ! 192.168.1.1 -j DROP , pcnt = 486 -- bcnt = 19332
l+ _$ k% f7 \4 N9 g$ n-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 06 `" k {. k' {/ ]/ `1 f
# h1 h- U1 d% g
Bridge chain: FORWARD, entries: 9, policy: ACCEPT
; K; I) L- E1 h' L) U! f2 q$ Q-o vlan51 -j DROP , pcnt = 611 -- bcnt = 28742
3 J ^4 H* k) W-i vlan51 -o eth1 -j DROP , pcnt = 55685 -- bcnt = 75491600
7 Q. E3 r( X7 o! v' q-i vlan51 -o eth2 -j DROP , pcnt = 55685 -- bcnt = 75491600* N. Z) F' d' f, Y# e
-i vlan85 -o vlan51 -j ACCEPT , pcnt = 0 -- bcnt = 09 L5 @; w$ H. Q3 g
-i vlan51 -o vlan85 -j ACCEPT , pcnt = 55685 -- bcnt = 75491600
" ^7 r: I0 K4 A4 n-o vlan85 -j DROP , pcnt = 76 -- bcnt = 6079
) e+ ~# O' A- [-i vlan85 -j DROP , pcnt = 2132 -- bcnt = 90284; F( s7 Q% g5 c* o
-p IPv4 -i eth1 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 00 l5 w8 q- q1 p& r- v
-p IPv4 -i eth2 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 06 y4 }4 Y0 A# V# |- F! m
8 _0 f) Q: D2 e: t7 a; J7 _4 p
Bridge chain: OUTPUT, entries: 2, policy: ACCEPT- Q' B! c7 A$ ~. O% Q. Z
-o vlan51 -j DROP , pcnt = 0 -- bcnt = 0: T: u( e3 V2 a* x
-p IPv6 -o vlan85 -j DROP , pcnt = 0 -- bcnt = 0 |
|