Któryś z kolegów kiedyś coś takiego zapodał (to było a propos dopuszczenia ruchu tylko do windows update i wybranych portów na jednym IP):
iptables -I FORWARD -s 192.168.0.5 -j DROP
iptables -I FORWARD -p tcp -m multiport -s 192.168.0.5 --dports xxx,yyy -j ACCEPT
iptables -I FORWARD -p tcp -s 192.168.0.5 -d windowsupdate.microsoft.com -j ACCEPT
iptables -I FORWARD -p tcp -s 192.168.0.5 -d update.microsoft.com -j ACCEPT
iptables -I FORWARD -p tcp -s 192.168.0.5 -d download.windowsupdate.com -j ACCEPT
iptables -I FORWARD -p tcp -s 192.168.0.5 -d redir.metaservices.microsoft.com -j ACCEPT
iptables -I FORWARD -p tcp -s 192.168.0.5 -d images.metaservices.microsoft.com -j ACCEPT
iptables -I FORWARD -p tcp -s 192.168.0.5 -d c.microsoft.com -j ACCEPT
iptables -I FORWARD -p tcp -s 192.168.0.5 -d www.download.windowsupdate.com -j ACCEPT
iptables -I FORWARD -p tcp -s 192.168.0.5 -d wustat.windows.com -j ACCEPT
iptables -I FORWARD -p tcp -s 192.168.0.5 -d crl.microsoft.com -j ACCEPT
iptables -I FORWARD -p tcp -s 192.168.0.5 -d sls.microsoft.com -j ACCEPT
iptables -I FORWARD -p tcp -s 192.168.0.5 -d productactivation.one.microsoft.com -j ACCEPT
iptables -I FORWARD -p tcp -s 192.168.0.5 -d ntservicepack.microsoft.com -j ACCEPT
iptables -I FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
Netowski 1Gb/1Gb
Huawei E3372s-153 non-hilink + 2x15dBi MIMO
FreshTomato: Asus RT-AC3200 + RT-N18U + RT-N66U + RT-N12
|