|
发表于 2011-2-11 22:27:09
|
显示全部楼层
参考RG200E-AB里的ebtables,初步作了一个:
ebtables -L --Lc
Bridge table: filter
Bridge chain: INPUT, entries: 9, policy: ACCEPT
-p PPP_DISC -i eth1 -j DROP , pcnt = 0 -- bcnt = 0
-p PPP_DISC -i eth2 -j DROP , pcnt = 0 -- bcnt = 0
-p PPP_DISC -i vlan85 -j DROP , pcnt = 3 -- bcnt = 138
-i vlan51 -j DROP , pcnt = 55741 -- bcnt = 75494176
-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 2 -- bcnt = 1152
-p IPv6 -i vlan85 -j DROP , pcnt = 0 -- bcnt = 0
-d Broadcast -i vlan85 -j ACCEPT , pcnt = 61 -- bcnt = 2806
-p IPv4 -i vlan85 --ip-dst ! 192.168.1.1 -j DROP , pcnt = 486 -- bcnt = 19332
-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
Bridge chain: FORWARD, entries: 9, policy: ACCEPT
-o vlan51 -j DROP , pcnt = 611 -- bcnt = 28742
-i vlan51 -o eth1 -j DROP , pcnt = 55685 -- bcnt = 75491600
-i vlan51 -o eth2 -j DROP , pcnt = 55685 -- bcnt = 75491600
-i vlan85 -o vlan51 -j ACCEPT , pcnt = 0 -- bcnt = 0
-i vlan51 -o vlan85 -j ACCEPT , pcnt = 55685 -- bcnt = 75491600
-o vlan85 -j DROP , pcnt = 76 -- bcnt = 6079
-i vlan85 -j DROP , pcnt = 2132 -- bcnt = 90284
-p IPv4 -i eth1 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
-p IPv4 -i eth2 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
Bridge chain: OUTPUT, entries: 2, policy: ACCEPT
-o vlan51 -j DROP , pcnt = 0 -- bcnt = 0
-p IPv6 -o vlan85 -j DROP , pcnt = 0 -- bcnt = 0 |
|