Ребята помогите с правилами
не работает
hotmail.com
если drop input
[more=правила]#
Flags: X - disabled, I - invalid, D - dynamic
0 X ;;; Drop invalid connection packets
chain=input action=drop connection-state=invalid
1 ;;; Allow established connections
chain=input action=accept connection-state=established
2 ;;; Allow UDP
chain=input action=accept protocol=udp
3 ;;; Allow ICMP Ping
chain=input action=accept protocol=icmp
4 ;;; Web proxy
chain=input action=accept protocol=tcp src-address=192.168.0.0/24
in-interface=LAN dst-port=8080
5 chain=input action=accept protocol=tcp src-address=192.168.3.0/24
in-interface=LAN dst-port=8080
6 ;;; Access to router only for admin
chain=input action=accept src-address=192.168.0.6
7 X ;;; VPN
chain=input action=accept protocol=tcp dst-port=1194
8 chain=input action=drop protocol=tcp in-interface=WAN dst-port=8080
9 X ;;; All other inputs drop
chain=input action=drop
10 X ;;; Drop invalid connection packets
chain=forward action=drop connection-state=invalid
11 ;;; Allow established connections
chain=forward action=accept connection-state=established
12 ;;; Allow related connections
chain=forward action=accept connection-state=related
13 ;;; Allow UDP
chain=forward action=accept protocol=udp
14 ;;; RDP
chain=forward action=accept protocol=tcp dst-port=3389
15 ;;; Voyadger
chain=forward action=accept protocol=tcp dst-port=3055
16 chain=forward action=accept protocol=tcp dst-port=3053
17 ;;; Allow ICMP Ping
chain=forward action=accept protocol=icmp
18 ;;; Access to internet from admin
chain=forward action=accept src-address=192.168.0.6
19 ;;; Access to internet from all
chain=forward action=accept src-address=192.168.0.0/24
20 chain=forward action=accept src-address=192.168.3.0/24
21 ;;; µTorrent
chain=forward action=accept protocol=tcp dst-address=192.168.0.6
in-interface=!LAN dst-port=36445
22 ;;; L2TP
chain=forward action=accept src-address=192.0.0.0/24 out-interface=LAN
23 ;;; All other forwards drop
chain=forward action=drop [/more]
не работает
hotmail.com
если drop input
[more=правила]#
Flags: X - disabled, I - invalid, D - dynamic
0 X ;;; Drop invalid connection packets
chain=input action=drop connection-state=invalid
1 ;;; Allow established connections
chain=input action=accept connection-state=established
2 ;;; Allow UDP
chain=input action=accept protocol=udp
3 ;;; Allow ICMP Ping
chain=input action=accept protocol=icmp
4 ;;; Web proxy
chain=input action=accept protocol=tcp src-address=192.168.0.0/24
in-interface=LAN dst-port=8080
5 chain=input action=accept protocol=tcp src-address=192.168.3.0/24
in-interface=LAN dst-port=8080
6 ;;; Access to router only for admin
chain=input action=accept src-address=192.168.0.6
7 X ;;; VPN
chain=input action=accept protocol=tcp dst-port=1194
8 chain=input action=drop protocol=tcp in-interface=WAN dst-port=8080
9 X ;;; All other inputs drop
chain=input action=drop
10 X ;;; Drop invalid connection packets
chain=forward action=drop connection-state=invalid
11 ;;; Allow established connections
chain=forward action=accept connection-state=established
12 ;;; Allow related connections
chain=forward action=accept connection-state=related
13 ;;; Allow UDP
chain=forward action=accept protocol=udp
14 ;;; RDP
chain=forward action=accept protocol=tcp dst-port=3389
15 ;;; Voyadger
chain=forward action=accept protocol=tcp dst-port=3055
16 chain=forward action=accept protocol=tcp dst-port=3053
17 ;;; Allow ICMP Ping
chain=forward action=accept protocol=icmp
18 ;;; Access to internet from admin
chain=forward action=accept src-address=192.168.0.6
19 ;;; Access to internet from all
chain=forward action=accept src-address=192.168.0.0/24
20 chain=forward action=accept src-address=192.168.3.0/24
21 ;;; µTorrent
chain=forward action=accept protocol=tcp dst-address=192.168.0.6
in-interface=!LAN dst-port=36445
22 ;;; L2TP
chain=forward action=accept src-address=192.0.0.0/24 out-interface=LAN
23 ;;; All other forwards drop
chain=forward action=drop [/more]