Код: Выделить всё
[root@server /boot]# ifconfig
myk0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=2b<RXCSUM,TXCSUM,VLAN_MTU,JUMBO_MTU>
inet 10.0.1.1 netmask 0xffffff00 broadcast 10.0.1.255
inet 10.0.2.1 netmask 0xffffff00 broadcast 10.0.2.255
inet 10.0.3.1 netmask 0xffffff00 broadcast 10.0.3.255
ether 00:15:f2:d7:67:58
media: Ethernet autoselect
status: no carrier
myk1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=2b<RXCSUM,TXCSUM,VLAN_MTU,JUMBO_MTU>
inet 195.250.79.10 netmask 0xffffffc0 broadcast 195.250.79.63
ether 00:15:f2:d7:64:38
media: Ethernet autoselect (10baseT/UTP <half-duplex>)
status: active
re0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=1b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING>
inet 10.0.0.1 netmask 0xffffff00 broadcast 10.0.0.255
inet 192.168.100.254 netmask 0xffffff00 broadcast 192.168.100.255
ether 00:17:9a:38:a8:3a
media: Ethernet autoselect (100baseTX <full-duplex>)
status: active
re1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=1b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING>
inet 80.81.223.117 netmask 0xffffff00 broadcast 80.81.223.255
inet 192.168.168.254 netmask 0xffffff00 broadcast 192.168.168.255
ether 00:17:9a:38:a9:b3
media: Ethernet autoselect (100baseTX <full-duplex>)
status: active
plip0: flags=108810<POINTOPOINT,SIMPLEX,MULTICAST,NEEDSGIANT> mtu 1500
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x6
inet6 ::1 prefixlen 128
inet 127.0.0.1 netmask 0xff000000
Код: Выделить всё
[root@server /boot]# netstat -nr
Routing tables
Internet:
Destination Gateway Flags Refs Use Netif Expire
default 195.250.79.1 UGS 0 12583 myk1
10/24 link#3 UC 0 0 re0
10.0.0.9 00:50:da:6d:b3:b5 UHLW 1 8047 re0 946
10.0.0.13 00:14:d1:35:2a:0d UHLW 1 44 re0 1161
10.0.0.15 00:14:d1:35:2a:0d UHLW 1 4889 re0 805
10.0.0.18 00:14:d1:35:2a:0d UHLW 1 2113 re0 724
10.0.0.27 00:14:d1:39:e2:cc UHLW 1 2116 re0 823
10.0.0.28 00:14:d1:39:e2:89 UHLW 1 37 re0 1018
10.0.0.34 00:14:d1:35:2a:0d UHLW 1 127 re0 1139
10.0.1/24 link#1 UC 0 0 myk0
10.0.2/24 link#1 UC 0 0 myk0
10.0.3/24 link#1 UC 0 0 myk0
80.81.223/24 link#4 UC 0 0 re1
80.81.223.2 link#4 UHLW 1 42 re1
127.0.0.1 127.0.0.1 UH 0 3440 lo0
192.168.100 link#3 UC 0 0 re0
192.168.168 link#4 UC 0 0 re1
195.250.79/26 link#2 UC 0 0 myk1
195.250.79.1 00:50:50:0d:fa:13 UHLW 2 58 myk1 1197
195.250.79.10 00:15:f2:d7:64:38 UHLW 1 151 lo0
Internet6:
Destination Gateway Flags Netif Expire
::1 ::1 UHL lo0
fe80::%lo0/64 fe80::1%lo0 U lo0
fe80::1%lo0 link#6 UHL lo0
ff01:6::/32 fe80::1%lo0 UC lo0
ff02::%lo0/32 fe80::1%lo0 UC lo0
Код: Выделить всё
[root@server /boot]# ipfw -ad list
00100 0 0 check-state
00150 6900 997806 allow ip from any to any via lo0
00200 34741 12371148 allow ip from me to any keep-state
00250 2028 174584 deny ip from not 10.0.0.0/24 to any via re0 in
00300 3935 336543 deny ip from any to not me via myk1 in
00450 12745 2329261 fwd 127.0.0.1,3128 tcp from 10.0.0.0/24 to any dst-port 80 in
00500 2156 199196 divert 8668 ip from any to any via myk1
00550 0 0 allow ip from any to any via myk1 out
00600 910 76576 allow tcp from any to me dst-port 22 via re0
00650 29 1376 allow tcp from any to me dst-port 80,443 via re0
00700 5 300 allow icmp from any to me
00750 299 19865 allow udp from any to me dst-port 53 via re0
00800 716 31719 allow udp from any to me dst-port 7723 via re0
00850 3 234 deny ip from any to me
00950 0 0 allow ip from any to any via myk1
41000 0 0 allow ip from 10.0.0.12 to any
41000 0 0 allow ip from any to 10.0.0.12
42000 36 3940 allow ip from 10.0.0.13 to any
42000 106 72113 allow ip from any to 10.0.0.13
43000 0 0 allow ip from 10.0.0.14 to any
43000 0 0 allow ip from any to 10.0.0.14
44000 106 5988 allow ip from 10.0.0.15 to any
44000 4633 2387636 allow ip from any to 10.0.0.15
55000 0 0 allow ip from 10.0.0.16 to any
55000 0 0 allow ip from any to 10.0.0.16
52000 259 17009 allow ip from 10.0.0.9 to any
52000 2519 1439373 allow ip from any to 10.0.0.9
60000 18626 2136808 deny ip from any to any
65535 0 0 deny ip from any to any
## Dynamic rules (54):
00200 10 1941 (1s) STATE udp 10.0.0.1 53 <-> 10.0.0.15 49162
00200 0 0 (1s) STATE tcp 10.0.0.1 22 <-> 10.0.0.9 1206