
Все пришел спрашивать потому что уже клин!
есть сети
192.168.91.0
192.168.92.0
сервак
192.168.1.2 255.255.255.252 (воткнут в каталист 3560)
инет
82.ч.ч.ч
Код: Выделить всё
/home/banec/>ipfw show
00100 763 47369 pipe 1 ip from any to any tcpflags ack iplen 0-128
00200 4 580 allow ip from any to any via lo0
00300 0 0 deny ip from any to 127.0.0.0/8
00400 0 0 deny ip from 127.0.0.0/8 to any
00500 0 0 deny log logamount 50 ip from 192.168.1.0/30 to any in via bge0
00600 0 0 deny log logamount 50 ip from 82.ч.ч.0/30 to any in via bge1
00700 0 0 deny ip from any to 10.0.0.0/8 in via bge0
00800 0 0 deny ip from any to 172.16.0.0/12 in via bge0
00900 0 0 deny ip from any to 192.168.0.0/16 in via bge0
01000 0 0 deny ip from any to 0.0.0.0/8 in via bge0
01100 0 0 deny ip from any to 169.254.0.0/16 in via bge0
01200 0 0 deny ip from any to 192.0.2.0/24 in via bge0
01300 0 0 deny ip from any to 224.0.0.0/4 in via bge0
01400 0 0 deny ip from any to 240.0.0.0/4 in via bge0
01500 0 0 deny icmp from any to any frag
01600 0 0 deny icmp from any to 255.255.255.255 out via bge0
01700 0 0 deny icmp from any to 255.255.255.255 in via bge0
01800 792 45926 pipe 2 ip from any to any in via ng0
01900 741 73759 pipe 3 ip from any to any out via ng0
02000 838 47917 divert 8668 ip from any to any out xmit bge0
02100 859 80683 divert 8668 ip from any to 82.ч.ч.ч
02200 0 0 deny ip from 10.0.0.0/8 to any out via bge0
02300 0 0 deny ip from 172.16.0.0/12 to any out via bge0
02400 0 0 deny ip from 192.168.0.0/16 to any out via bge0
02500 0 0 deny ip from 0.0.0.0/8 to any out via bge0
02600 0 0 deny ip from 169.254.0.0/16 to any out via bge0
02700 0 0 deny ip from 192.0.2.0/24 to any out via bge0
02800 0 0 deny ip from 224.0.0.0/4 to any out via bge0
02900 0 0 deny ip from 240.0.0.0/4 to any out via bge0
03000 1080 104867 allow ip from any to any in via bge1
03100 1165 111513 allow ip from any to any out via bge1
03200 792 45926 allow ip from any to any in via ng0
03300 741 73759 allow ip from any to any out via ng0
03400 233 40708 allow tcp from any to any established
03500 690 41385 allow ip from 82.ч.ч.ч to any xmit bge0
03600 0 0 allow tcp from any to ч.ч.ч.ч dst-port 49152-65535 via bge0
03700 0 0 allow tcp from any to 82.ч.ч.ч dst-port 53 setup
03800 13 1973 allow udp from any 53 to any
03900 0 0 allow udp from any to any dst-port 53
04000 661 39628 allow icmp from any to any in via bge0 icmptypes 0,3,4,8,11
04100 0 0 allow tcp from any 80,443,20-21,989-990 to any
04200 0 0 allow tcp from any to any dst-port 80,443,20-21,989-990
04300 0 0 allow tcp from any 40000 to any via bge0
04400 62 3040 allow tcp from any to any dst-port 40000 via bge0
04500 0 0 allow tcp from any 30000 to any via bge0
04600 29 1392 allow tcp from any to any dst-port 30000 via bge0
04700 0 0 allow tcp from any to 82.ч.ч.ч dst-port 22 via bge0
04800 0 0 allow udp from 82.ч.ч.ч to any dst-port 53 keep-state
04900 0 0 allow udp from 82.ч.ч.ч to any dst-port 123 keep-state
05000 8 384 deny log logamount 50 tcp from any to any in via bge0 setup
05100 0 0 allow tcp from 82.ч.ч.ч to any out via bge0 setup
05200 0 0 allow tcp from any to 82.ч.ч.ч in via bge1 setup
05300 0 0 allow tcp from any to me dst-port 1723
05400 0 0 allow gre from any to any
05500 0 0 allow tcp from any to 192.168.1.2 dst-port 80 setup
05600 0 0 allow tcp from any to 192.168.1.2 dst-port 22 setup
05700 0 0 allow icmp from any to any icmptypes 0,8
05800 0 0 allow ip from any to any in via ng0 setup
05900 0 0 skipto 39999 ip from any to any tcpflags ack iplen 0-128
40000 0 0 check-state
40100 1 90 deny ip from any to any
65535 30 5951 deny ip from any to any
/home/banec/>
/home/banec/>netstat -rn
Routing tables
Internet:
Destination Gateway Flags Refs Use Netif Expire
default 82.ч.ч.1 UGS 0 39142 bge0
82.ч.ч/30 link#1 UC 0 0 bge0
82.ч.ч.1 00:15:e9:ad:3a:ac UHLW 2 7644 bge0 1152
127.0.0.1 127.0.0.1 UH 0 54 lo0
172.16.0.1 lo0 UHS 0 0 lo0
172.16.6.3 172.16.0.1 UH 0 1919 ng0
192.168.1/30 link#2 UC 0 0 bge1
192.168.1.1 00:18:19:57:a3:c4 UHLW 3 0 bge1 945
192.168.91 192.168.1.1 UGS 0 4265 bge1
192.168.92 192.168.1.1 UGS 0 27526 bge1
/home/banec/>ifconfig
bge0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=1b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING>
inet 82.ч.ч.ч netmask 0xfffffffc broadcast 82.ч.ч.3
ether 00:17:08:5c:1b:8b
media: Ethernet autoselect (1000baseTX <full-duplex>)
status: active
bge1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=1b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING>
inet 192.168.1.2 netmask 0xfffffffc broadcast 192.168.1.3
ether 00:17:08:5c:1b:8a
media: Ethernet autoselect (1000baseTX <full-duplex>)
status: active
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
inet 127.0.0.1 netmask 0xff000000
ng0: flags=88d1<UP,POINTOPOINT,RUNNING,NOARP,SIMPLEX,MULTICAST> mtu 1398
inet 172.16.0.1 --> 172.16.6.3 netmask 0xffffffff
ng1: flags=8890<POINTOPOINT,NOARP,SIMPLEX,MULTICAST> mtu 1500
ng2: flags=8890<POINTOPOINT,NOARP,SIMPLEX,MULTICAST> mtu 1500
/home/banec/>
куда их пихать и какие вставлять у меня крыша едет?
нужно резать на ngX канал 64/32
