|
|
发表于 2011-2-11 22:27:09
|
显示全部楼层
参考RG200E-AB里的ebtables,初步作了一个:
3 Z6 j2 F2 g$ X4 i( R/ f+ \& pebtables -L --Lc, n- f5 \4 `* v, w
Bridge table: filter" B3 I6 ^# c5 |2 t: ]$ i6 r
* ] |+ i: r0 m5 hBridge chain: INPUT, entries: 9, policy: ACCEPT3 Y1 w/ S) {* v; K+ E
-p PPP_DISC -i eth1 -j DROP , pcnt = 0 -- bcnt = 05 e5 P/ d+ B# n+ e% e
-p PPP_DISC -i eth2 -j DROP , pcnt = 0 -- bcnt = 00 q2 a, c/ [# Y4 {. w; |( N
-p PPP_DISC -i vlan85 -j DROP , pcnt = 3 -- bcnt = 138
+ T" `3 ?9 q4 k-i vlan51 -j DROP , pcnt = 55741 -- bcnt = 75494176
$ N4 B4 q% w8 W# x4 u2 H. z-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 2 -- bcnt = 1152
" I! z& X# l+ \; C7 N s( A-p IPv6 -i vlan85 -j DROP , pcnt = 0 -- bcnt = 0
0 U( O F9 e9 [# q7 M$ b-d Broadcast -i vlan85 -j ACCEPT , pcnt = 61 -- bcnt = 28061 T: m( P+ A R: {* K
-p IPv4 -i vlan85 --ip-dst ! 192.168.1.1 -j DROP , pcnt = 486 -- bcnt = 193321 H- S! t6 O" G$ i' V
-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
' }7 I" E0 ^' c' a( p/ x, p
7 B3 J- k5 f" n" KBridge chain: FORWARD, entries: 9, policy: ACCEPT; l" `! N: t" y* B
-o vlan51 -j DROP , pcnt = 611 -- bcnt = 28742
# F) W; a, x# `# r" ~3 N-i vlan51 -o eth1 -j DROP , pcnt = 55685 -- bcnt = 754916002 G' h3 [3 o# x& S, t) I* E# s
-i vlan51 -o eth2 -j DROP , pcnt = 55685 -- bcnt = 754916001 X+ D- c, w% e# M% O: y
-i vlan85 -o vlan51 -j ACCEPT , pcnt = 0 -- bcnt = 0) f7 d; j f9 e' \6 r
-i vlan51 -o vlan85 -j ACCEPT , pcnt = 55685 -- bcnt = 75491600
; L: ]; B2 B$ {-o vlan85 -j DROP , pcnt = 76 -- bcnt = 6079
0 ?5 J- x$ W4 u-i vlan85 -j DROP , pcnt = 2132 -- bcnt = 90284* D- c3 I$ L( w4 G& S9 {! }/ C' l
-p IPv4 -i eth1 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
/ |( O+ K. l5 v+ M( v' W1 I4 {-p IPv4 -i eth2 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
# l" |% Z5 y9 L9 `( B8 T
9 B$ A& x4 q- Y& H2 i XBridge chain: OUTPUT, entries: 2, policy: ACCEPT
* @: d2 D9 X& @% O4 w' l+ B3 B0 E/ ^-o vlan51 -j DROP , pcnt = 0 -- bcnt = 0
$ H9 O; b! r4 C* `- _' m+ A-p IPv6 -o vlan85 -j DROP , pcnt = 0 -- bcnt = 0 |
|