Цитата:
а трафик через устройство ходит?
да конечно - это без вариантов, если бы не проходило то это было бы просто физически не возможно.
а трафик через устройство ходит?
/ ip firewall address-list
add list="allowed-internet" address=172.17.2.0/24 comment="" disabled=no
/ ip firewall nat
add chain=srcnat action=masquerade out-interface="pppoe-ogo" src-address-list="allowed-internet" comment="Gateway ogo pppoe" disabled=no
add chain=srcnat action=masquerade out-interface="net" src-address-list="allowed-internet" comment="Gateway ark 10.222.0.1" disabled=no
/ ip firewall mangle
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="dns_tcp_traffic" passthrough=no dst-port=53 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="dns_udp_traffic" passthrough=no dst-port=53 protocol=udp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="http_traffic" passthrough=no dst-port=80 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="ssl_traffic" passthrough=no dst-port=443 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="ftp_traffic" passthrough=no dst-port=21 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="ssh_traffic" passthrough=no dst-port=22 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="icq_traffic" passthrough=no dst-port=5190 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="pop3_traffic" passthrough=no dst-port=110 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="smtp_traffic" passthrough=no dst-port=25 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="yahoo_msg_voice_tcp_traffic" passthrough=no dst-port=5000-5001 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="yahoo_msg_voice_udp_traffic" passthrough=no dst-port=5000-5010 protocol=udp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="yahoo_msg_traffic" passthrough=no dst-port=5050 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="yahoo_msg_video_traffic" passthrough=no dst-port=5100 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="cws_traffic" passthrough=no dst-port=10000 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="cws_in_traffic" passthrough=no dst-port=12000 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="cstrike_tcp_traffic" passthrough=no dst-port=27020-27041 protocol=tcp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="cstrike_udp_traffic" passthrough=no dst-port=1200,27000-27015 protocol=udp comment="" disabled=no
add chain=prerouting src-address-list="allowed-internet" action=mark-routing new-routing-mark="other_traffic" passthrough=no comment="" disabled=no
/ ip route
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="dns_tcp_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="dns_udp_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="http_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="ssl_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="ftp_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="ssh_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="icq_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="pop3_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="smtp_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="yahoo_msg_voice_tcp_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="yahoo_msg_voice_udp_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="yahoo_msg_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="yahoo_msg_video_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="cws_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="cws_in_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="cstrike_tcp_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 routing-mark="cstrike_udp_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=10.222.0.1 scope=255 target-scope=10 routing-mark="other_traffic" comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=pppoe-ogo scope=255 target-scope=10 comment="default route for router" disabled=no
как мне сделать фильтрацию по списки IP адресов
как промаркировать пакеты в бридже
получилось?.. ppp работает с dhcp?..
к примеру если видно что с одного IP адреса идет не характерная активность
Страницы: 1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768
Предыдущая тема: Шары открываются только по IP (не по имени)