query píše:testuju na stole za natem, přístup z venku tady nemám. Konfigurace je popsaná nahoře.
pepulis » nemohl by sis sem hodit export pravidla, abych to porovnal...
Nejak takhle:
add action=jump chain=forward comment=priority disabled=no jump-target=\
priority
add action=mark-packet chain=priority disabled=no dst-address-list=local \
new-packet-mark=net-all/icmp passthrough=no protocol=icmp
add action=mark-packet chain=priority comment=dns connection-type=!ftp \
disabled=no dst-port=53 new-packet-mark=all/DNS-net p2p=!all-p2p \
passthrough=no protocol=udp src-address-list=local
add action=mark-packet chain=priority connection-type=!ftp disabled=no \
new-packet-mark=all/DNS-net p2p=!all-p2p passthrough=no protocol=udp \
src-address-list=local src-port=53
add action=mark-packet chain=priority connection-type=!ftp disabled=no \
dst-address-list=local new-packet-mark=net-all/DNS p2p=!all-p2p \
passthrough=no protocol=udp src-port=53
add action=mark-packet chain=priority connection-type=!ftp disabled=no \
dst-address-list=local dst-port=53 new-packet-mark=net-all/DNS p2p=\
!all-p2p passthrough=no protocol=udp
add action=mark-packet chain=priority comment=voip connection-type=!ftp \
disabled=no dst-port=5060-5065,8060 new-packet-mark=all/VOIP-net p2p=\
!all-p2p passthrough=no protocol=udp src-address-list=local
add action=mark-packet chain=priority connection-type=!ftp disabled=no \
new-packet-mark=all/VOIP-net p2p=!all-p2p passthrough=no protocol=udp \
src-address-list=local src-port=5060-5065,8060
add action=mark-packet chain=priority connection-type=!ftp disabled=no \
dst-address-list=local new-packet-mark=net-all/VOIP p2p=!all-p2p \
passthrough=no protocol=udp src-port=5060-5065,8060
add action=mark-packet chain=priority connection-type=!ftp disabled=no \
dst-address-list=local dst-port=5060-5065,8060 new-packet-mark=\
net-all/VOIP p2p=!all-p2p passthrough=no protocol=udp
add action=mark-packet chain=priority comment=cod connection-type=!ftp \
disabled=no dst-port=28960 new-packet-mark=all/COD-net p2p=!all-p2p \
passthrough=no protocol=udp src-address-list=local
add action=mark-packet chain=priority connection-type=!ftp disabled=no \
new-packet-mark=all/COD-net p2p=!all-p2p passthrough=no protocol=udp \
src-address-list=local src-port=28960
add action=mark-packet chain=priority connection-type=!ftp disabled=no \
dst-address-list=local new-packet-mark=net-all/COD p2p=!all-p2p \
passthrough=no protocol=udp src-port=28960
add action=mark-packet chain=priority connection-type=!ftp disabled=no \
dst-address-list=local dst-port=28960 new-packet-mark=net-all/COD p2p=\
!all-p2p passthrough=no protocol=udp
add action=jump chain=segments comment=\
"Manglovani paketu pro uzivatele s rozsahem 192.168.105.0/24" disabled=no \
in-interface=!wan jump-target=segment_105 out-interface=wan src-address=\
192.168.105.0/24
add action=jump chain=segments disabled=no dst-address=192.168.105.0/24 \
in-interface=wan jump-target=segment_105 out-interface=!wan
Pod chain segment_105 si pak dat uz uzivatele a vytvorit si QT strom. Rozsah atd. zvolit dle vlastniho pouziti.
V QT pak udelat hlavni parent DOWNLOAD, pod nim podparent DOWNLOAD-priority, kde budou mangle s prioritama napr. 1 a podparent DOWNLOAD-uzivatele, kde uz budou mangle uzivatelu. To stejne udelat i pro UPLOAD.