![]() |
![]() |
#11 |
Junior Member
Регистрация: 03.11.2016
Сообщений: 21
Вес репутации: 0 ![]() |
![]()
есть коммутатор. на один из портов приходит тегированый (vlan100) трафик. нужно его, как-то скушать.
пробую такой конфиг на роутере(tp-link841). network Код:
config interface 'loopback' option ifname 'lo' option proto 'static' option ipaddr '127.0.0.1' option netmask '255.0.0.0' config globals 'globals' option ula_prefix 'fd40:e014:5811::/48' config interface 'mgm' option ifname 'eth1.100' option proto 'static' option ipaddr '172.16.1.19' option netmask '255.255.255.0' option gateway '172.16.1.1' option dns '172.16.1.3 8.8.8.8' option macaddr '84:74:2A:54:34:35' config interface 'lan' option ifname 'eth1.1' option type 'bridge' option proto 'static' option ipaddr '192.168.1.1' option netmask '255.255.255.0' option dns '192.168.1.1' option ip6assign '60' config interface 'wan' option ifname 'eth0' option proto 'dhcp' config switch option name 'eth1' option reset '1' option enable_vlan '1' config switch_vlan option device 'eth1' option vlan '1' option vid '1' option ports '0t 2 4' config switch_vlan option device 'eth1' option vlan '100' option vid '100' option ports '0t 1 3' firewall Код:
# blank # delete ipv6 rules config defaults option syn_flood 1 option input ACCEPT option output ACCEPT option forward REJECT config zone option name lan list network 'lan' option input ACCEPT option output ACCEPT option forward ACCEPT config zone option name mgm list network 'mgm' option input REJECT option output ACCEPT option forward REJECT # option masq 1 # option mtu_fix 1 #config forwarding # option src lan # option dest wan # We need to accept udp packets on port 68, # see https://dev.openwrt.org/ticket/4108 config rule option name Allow-DHCP-Renew option src wan option proto udp option dest_port 68 option target ACCEPT option family ipv4 # Allow IPv4 ping config rule option name Allow-Ping option src wan option proto icmp option icmp_type echo-request option family ipv4 option target ACCEPT config rule option name Allow-IGMP option src wan option proto igmp option family ipv4 option target ACCEPT # include a file with users custom iptables rules config include option path /etc/firewall.user # allow IPsec/ESP and ISAKMP passthrough config rule option src wan option dest lan option proto esp option target ACCEPT config rule option src wan option dest lan option dest_port 500 option proto udp option target ACCEPT |
![]() |
![]() |
Метки |
network openwrt, wi-fi openwrt, настройка сети openwrt |
Здесь присутствуют: 5 (пользователей: 0 , гостей: 5) | |
|
|