|
|
发表于 2011-2-11 22:27:09
|
显示全部楼层
参考RG200E-AB里的ebtables,初步作了一个:7 u( g4 q1 z+ l6 E; M
ebtables -L --Lc
& j; i" S; K# |- G6 k) e5 \Bridge table: filter
* @) z6 d6 L% |, M! \& x) L m9 v% J) B. I/ e/ }/ H
Bridge chain: INPUT, entries: 9, policy: ACCEPT
$ x- m; h" b' O0 ]: c5 Q-p PPP_DISC -i eth1 -j DROP , pcnt = 0 -- bcnt = 0) C9 G; ?1 B+ W1 J. b2 n
-p PPP_DISC -i eth2 -j DROP , pcnt = 0 -- bcnt = 0
- N; m8 d. V2 O& v-p PPP_DISC -i vlan85 -j DROP , pcnt = 3 -- bcnt = 138
; x4 Y* R a2 W+ B- z-i vlan51 -j DROP , pcnt = 55741 -- bcnt = 75494176
5 M- f. p7 c2 x) C, J-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 2 -- bcnt = 1152
6 P0 f; H: \0 i! [3 I" h1 D-p IPv6 -i vlan85 -j DROP , pcnt = 0 -- bcnt = 0. T8 ?/ ?1 ^# b# Q
-d Broadcast -i vlan85 -j ACCEPT , pcnt = 61 -- bcnt = 2806
6 A( ]2 f& M% t- K _, F-p IPv4 -i vlan85 --ip-dst ! 192.168.1.1 -j DROP , pcnt = 486 -- bcnt = 19332
' x& E; e$ H8 P" e-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
, Q# i# t( w8 M6 K5 d9 o" q) w
. ?! c) g, `# d- I4 c) E/ b8 XBridge chain: FORWARD, entries: 9, policy: ACCEPT1 x8 Q6 D# V) U7 P" A
-o vlan51 -j DROP , pcnt = 611 -- bcnt = 28742
. }: a% X$ S! v-i vlan51 -o eth1 -j DROP , pcnt = 55685 -- bcnt = 75491600
6 G' R4 F7 ?1 P2 c-i vlan51 -o eth2 -j DROP , pcnt = 55685 -- bcnt = 75491600
/ {% r8 M' J* R1 [& P6 U/ F-i vlan85 -o vlan51 -j ACCEPT , pcnt = 0 -- bcnt = 07 _& }4 C) `+ [7 h
-i vlan51 -o vlan85 -j ACCEPT , pcnt = 55685 -- bcnt = 75491600
# ?! p O5 _) Y3 F5 L, s" k-o vlan85 -j DROP , pcnt = 76 -- bcnt = 6079
# u# Z' K5 a4 @-i vlan85 -j DROP , pcnt = 2132 -- bcnt = 90284( \) m% R) b; _1 }
-p IPv4 -i eth1 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 08 } R' y; p. ^3 g
-p IPv4 -i eth2 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
1 V w: \3 L" R4 c3 e* u7 @5 a' Y# ~9 v: Y: u" G3 d) H' F
Bridge chain: OUTPUT, entries: 2, policy: ACCEPT* _! }( o4 h3 x& [+ K/ U1 S6 L6 Y) L. F
-o vlan51 -j DROP , pcnt = 0 -- bcnt = 0
) U7 x: J- x4 f) y) L/ W- k' {-p IPv6 -o vlan85 -j DROP , pcnt = 0 -- bcnt = 0 |
|