Jump to content
Калькуляторы

Разделение внешней и глобальной сетей

Есть шлюз ASP Linux 7.3 с двумя сетевухами и IPTABLES. Есть список городских сетей с дешевым трафиком(городской интернет), и глобальная сеть 0.0.0.0/0 подороже. Надо, чтобы пользователи могли иметь городской трафик всегда, а внешний с моего разрешения. Как эти сети можно реализовать такое разделение через IPTABLES?

Share this post


Link to post
Share on other sites

fw -t nat -I PREROUTING -s lan_subnet -j DROP

fw -t nat -I PREROUTING -s lan_subnet -d deshovyj_subent -j ACCEPT

fw -t nat -I PREROUTING -s lan_subnet -d deshovyj_subent2 -j ACCEPT

fw -t nat -I PREROUTING -s lan_subnet -d deshovyj_subent3 -j ACCEPT

 

i potom dkit' nekotorym useram vsio:

fw -t nat -I PREROUTIN|G -s ip_horoshego_usera -d 0/0 -j ACCEPT

Share this post


Link to post
Share on other sites

fw -t nat -I PREROUTING -s lan_subnet -j DROP

fw -t nat -I PREROUTING -s lan_subnet -d deshovyj_subent -j ACCEPT

fw -t nat -I PREROUTING -s lan_subnet -d deshovyj_subent2 -j ACCEPT

fw -t nat -I PREROUTING -s lan_subnet -d deshovyj_subent3 -j ACCEPT

 

i potom dkit' nekotorym useram vsio:

fw -t nat -I PREROUTIN|G -s ip_horoshego_usera -d 0/0 -j ACCEPT

Спасибо, попробую!

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.