1. Настроить файрвол то я настроил, и теперь хочу с помощью divert завернуть трафик на биллинг, чтобы он в свою очередь начал щитать. Но не тут то было:
Код: Выделить всё
Super-foX# ipfw show
00100 0 0 check-state
00200 295916 12289078 divert 8668 ip from 192.168.1.0/24 to any out via rl0
00300 585070 869429562 divert 8668 ip from any to 192.168.0.4 in via rl0
00400 0 0 divert 199 ip from 192.168.1.0/24 to any out via rl0
00500 73 6530 divert 199 ip from any to 192.168.0.4 in via rl0
00600 100 10472 allow ip from any to any via lo0
00700 0 0 allow ip from 192.168.0.13 to any via rl0
00800 0 0 deny ip from any to 127.0.0.0/8
00900 0 0 deny ip from 127.0.0.0/8 to any
01000 0 0 deny log icmp from any to 255.255.255.255 in via rl0
01100 0 0 deny log icmp from any to 255.255.255.255 out via rl0
01200 1759695 1763351065 allow tcp from any to any established
01300 0 0 allow ip from 192.168.1.1 to any out xmit rl0
01400 70 11823 allow udp from any 53 to any via rl0
01500 103 6515 allow udp from any to any dst-port 53 via rl0
01600 0 0 allow udp from any to any dst-port 123 via rl0
01700 0 0 allow tcp from any to 192.168.1.1 dst-port 21 via rl0
01800 8 464 allow icmp from any to any icmptypes 0,8,11
01900 0 0 allow tcp from any to 192.168.0.4 dst-port 22 via rl0
02000 279 13392 allow tcp from any to any via fxp0
02100 1902 191520 allow udp from any to any via fxp0
02200 0 0 allow icmp from any to any via fxp0
02300 259 12432 allow tcp from any to any via rl0
02400 1779 176458 allow udp from any to any via rl0
02500 7 392 allow icmp from any to any via rl0
65535 0 0 allow ip from any to any
Код: Выделить всё
${FwCMD} add divert 8668 ip from ${NetIn}/${NetMask} to any out via ${LanOut}
${FwCMD} add divert 8668 ip from any to ${IpOut} in via ${LanOut}
${FwCMD} add divert 199 ip from ${NetIn}/${NetMask} to any out via ${LanOut}
${FwCMD} add divert 199 ip from any to ${IpOut} in via ${LanOut}