|
发表于 2011-2-11 22:27:09
|
显示全部楼层
参考RG200E-AB里的ebtables,初步作了一个:
, ?# i: l, G7 K6 J: webtables -L --Lc
; b0 I" {2 p4 [: t6 R9 eBridge table: filter
8 c2 ^/ B4 g2 R, ~& W0 S
& J# W Z, K' m' }3 o7 e0 jBridge chain: INPUT, entries: 9, policy: ACCEPT$ y5 s; F8 w) Q& j! o0 y, V7 ]7 ^* y% x
-p PPP_DISC -i eth1 -j DROP , pcnt = 0 -- bcnt = 0
: ]! C$ y$ P5 `- n w5 R-p PPP_DISC -i eth2 -j DROP , pcnt = 0 -- bcnt = 0* m" b* z [: F9 U( g% ^
-p PPP_DISC -i vlan85 -j DROP , pcnt = 3 -- bcnt = 138
6 t1 e2 K1 i" Y- a4 ]-i vlan51 -j DROP , pcnt = 55741 -- bcnt = 75494176
& X: G6 f: n% l+ W# n-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 2 -- bcnt = 1152
7 [* u [7 m2 _# p3 |/ x, _-p IPv6 -i vlan85 -j DROP , pcnt = 0 -- bcnt = 0& J: U+ y- F8 r7 e' X
-d Broadcast -i vlan85 -j ACCEPT , pcnt = 61 -- bcnt = 2806" s! J0 t* }% ^$ D
-p IPv4 -i vlan85 --ip-dst ! 192.168.1.1 -j DROP , pcnt = 486 -- bcnt = 19332
' \/ D0 y% U1 F$ o, m- `# W-p IPv4 -i vlan85 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
1 x& U# E, V/ e2 w- P Q4 I- a
3 p- ?+ H- c% ~- K" dBridge chain: FORWARD, entries: 9, policy: ACCEPT) P9 X+ C; i( H( ~
-o vlan51 -j DROP , pcnt = 611 -- bcnt = 28742& Y6 z0 y( B& E% O, @! ?
-i vlan51 -o eth1 -j DROP , pcnt = 55685 -- bcnt = 75491600
& N" ]* R7 x0 r& K9 l-i vlan51 -o eth2 -j DROP , pcnt = 55685 -- bcnt = 75491600
4 }# v( j: g! q% J u0 T-i vlan85 -o vlan51 -j ACCEPT , pcnt = 0 -- bcnt = 0
+ F) o9 S; L& v2 }( \+ @/ R7 N6 {-i vlan51 -o vlan85 -j ACCEPT , pcnt = 55685 -- bcnt = 75491600
1 k& P' {$ B5 o# s2 M" ?8 o6 A* s2 l-o vlan85 -j DROP , pcnt = 76 -- bcnt = 6079
) u2 L" p- Q9 q. A0 y-i vlan85 -j DROP , pcnt = 2132 -- bcnt = 90284
3 ~ C: g c' H3 } g-p IPv4 -i eth1 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 0
! V7 E* t9 J( K( z. e-p IPv4 -i eth2 --ip-proto udp --ip-sport 68 -j DROP , pcnt = 0 -- bcnt = 02 j" q. ^% `7 E$ f ?% G& | Z
3 S9 ?4 L( r$ }, B( [( qBridge chain: OUTPUT, entries: 2, policy: ACCEPT! G* L5 c: q9 \" {4 `" [
-o vlan51 -j DROP , pcnt = 0 -- bcnt = 05 }9 u+ m5 I5 b* K8 s* e8 Q- d
-p IPv6 -o vlan85 -j DROP , pcnt = 0 -- bcnt = 0 |
|