|
|
发表于 2011-2-11 22:27:09
|
显示全部楼层
参考RG200E-AB里的ebtables,初步作了一个:
+ ]8 ~: ?9 Y7 c( Mebtables -L --Lc4 C+ p" @+ b" D1 y4 @
Bridge table: filter
1 _' ~* g3 g/ W1 o9 L: L" Z
/ e9 c, j5 B o; m6 J. r1 o1 QBridge chain: INPUT, entries: 9, policy: ACCEPT
5 q9 q3 t+ B" q# d, R1 x-p PPP_DISC -i eth1 -j DROP , pcnt = 0 -- bcnt = 0% @# ?3 L) e5 t) V& T
-p PPP_DISC -i eth2 -j DROP , pcnt = 0 -- bcnt = 0
* r' n# t5 x' j8 C4 |; _-p PPP_DISC -i vlan85 -j DROP , pcnt = 3 -- bcnt = 1382 d& y" F5 f% D9 c2 c( I% x
-i vlan51 -j DROP , pcnt = 55741 -- bcnt = 75494176" k& S8 K) d7 @) p# E& U& D/ _) c
-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 2 -- bcnt = 1152
; a6 D' F3 B, R/ o5 X2 E6 B2 V-p IPv6 -i vlan85 -j DROP , pcnt = 0 -- bcnt = 05 |0 x- t9 ?/ Z" B( D9 j
-d Broadcast -i vlan85 -j ACCEPT , pcnt = 61 -- bcnt = 2806
& i1 V1 I5 _/ C8 i2 J2 n0 f l9 q-p IPv4 -i vlan85 --ip-dst ! 192.168.1.1 -j DROP , pcnt = 486 -- bcnt = 19332. z6 w3 d! d4 {6 w# s
-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0; `" P; X& M U: {
. J. I8 }! t5 G' i$ I
Bridge chain: FORWARD, entries: 9, policy: ACCEPT
) G8 f% q1 `1 ]( [+ {-o vlan51 -j DROP , pcnt = 611 -- bcnt = 28742, N) C2 ~6 Z$ M$ W2 l
-i vlan51 -o eth1 -j DROP , pcnt = 55685 -- bcnt = 75491600
( M: { t9 X. T8 b$ Z-i vlan51 -o eth2 -j DROP , pcnt = 55685 -- bcnt = 754916005 h" K1 x# q# b7 Y
-i vlan85 -o vlan51 -j ACCEPT , pcnt = 0 -- bcnt = 0
$ u5 q2 I$ K$ C0 ?( O2 b q-i vlan51 -o vlan85 -j ACCEPT , pcnt = 55685 -- bcnt = 754916000 _% g2 A) {- q& }, `% d
-o vlan85 -j DROP , pcnt = 76 -- bcnt = 6079
1 x6 s8 N+ }1 t& H5 p-i vlan85 -j DROP , pcnt = 2132 -- bcnt = 90284" L- ^, I5 ?6 ?0 R; x( P T
-p IPv4 -i eth1 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
) Z* d# ?3 S! Z* L-p IPv4 -i eth2 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0" H/ ^8 L* U5 I8 r8 G7 x
; L U( m, |7 M7 ^, EBridge chain: OUTPUT, entries: 2, policy: ACCEPT
) n7 k! s- Z G) o-o vlan51 -j DROP , pcnt = 0 -- bcnt = 0) n; H' l3 X) A; t. K
-p IPv6 -o vlan85 -j DROP , pcnt = 0 -- bcnt = 0 |
|