|
发表于 2011-2-11 22:27:09
|
显示全部楼层
参考RG200E-AB里的ebtables,初步作了一个:7 @; O* C' B1 P2 }: F k
ebtables -L --Lc
, h; c7 E1 ?/ f' ~0 D$ m, M9 JBridge table: filter
' J$ \4 N& G1 q" ~' B
$ _/ j1 u, Z# g$ y# q( u! pBridge chain: INPUT, entries: 9, policy: ACCEPT
2 J/ F& b; o; F' l-p PPP_DISC -i eth1 -j DROP , pcnt = 0 -- bcnt = 09 _. O# e$ @# E3 H( V" f
-p PPP_DISC -i eth2 -j DROP , pcnt = 0 -- bcnt = 00 }" H3 i& s) E6 w7 f6 a+ u
-p PPP_DISC -i vlan85 -j DROP , pcnt = 3 -- bcnt = 138" b' [: g3 G5 j( g/ T m
-i vlan51 -j DROP , pcnt = 55741 -- bcnt = 75494176
( |& @) A* |. u5 n-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 2 -- bcnt = 1152" o6 p3 B* O1 r; D' v8 W8 k
-p IPv6 -i vlan85 -j DROP , pcnt = 0 -- bcnt = 0
: {" l# W, P; Y n-d Broadcast -i vlan85 -j ACCEPT , pcnt = 61 -- bcnt = 28064 F. v j3 ~7 ?) ]" ^ `, U
-p IPv4 -i vlan85 --ip-dst ! 192.168.1.1 -j DROP , pcnt = 486 -- bcnt = 19332% C2 ]2 o8 S+ |; u% I; y; d# w
-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
( s7 i" l2 y% O3 i' W& l& V2 T
! L* r/ m% s: ~- b5 bBridge chain: FORWARD, entries: 9, policy: ACCEPT8 j$ B& N4 _7 G- m1 y
-o vlan51 -j DROP , pcnt = 611 -- bcnt = 28742, C z5 l- f; [. X( p' e% H
-i vlan51 -o eth1 -j DROP , pcnt = 55685 -- bcnt = 75491600; R4 _& u" e" x: Q3 ^: j, i; J
-i vlan51 -o eth2 -j DROP , pcnt = 55685 -- bcnt = 75491600* H8 ^$ d( F+ G$ B3 S2 G3 N
-i vlan85 -o vlan51 -j ACCEPT , pcnt = 0 -- bcnt = 0' g. [$ z" z% p2 d$ Q# v
-i vlan51 -o vlan85 -j ACCEPT , pcnt = 55685 -- bcnt = 754916006 I: ?7 H9 E# D, Z5 @$ z* a- `
-o vlan85 -j DROP , pcnt = 76 -- bcnt = 6079
4 w( @) a' U, \5 {- A3 w( R* ~-i vlan85 -j DROP , pcnt = 2132 -- bcnt = 90284' S2 l) P1 { J% C' y
-p IPv4 -i eth1 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 00 H4 P9 E O8 J4 j
-p IPv4 -i eth2 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 04 V( [0 n7 D0 h" _& h- y/ [
' `1 Q/ d% f! u" z
Bridge chain: OUTPUT, entries: 2, policy: ACCEPT" |' B; C* G1 P, i3 L
-o vlan51 -j DROP , pcnt = 0 -- bcnt = 0+ U, p! |$ z5 N+ d: z8 w2 C
-p IPv6 -o vlan85 -j DROP , pcnt = 0 -- bcnt = 0 |
|