Kód: Vybrat vše
1 ;;; allow already established connections
chain=forward action=accept connection-state=established
2 ;;; allow related connections
chain=forward action=accept connection-state=related
3 ;;; drop invalid connections
chain=forward action=drop connection-state=invalid
4 ;;; p2p_den
chain=forward action=drop p2p=all-p2p src-address-list=downloaders_p2p
5 ;;; ICQ
chain=forward action=accept dst-port=5190 protocol=tcp
src-address-list=downloaders_p2p
6 ;;; Jabber
chain=forward action=accept dst-port=5222 protocol=tcp
src-address-list=downloaders_p2p
7 chain=forward action=accept dst-port=8291 protocol=tcp
src-address-list=downloaders_p2p
8 ;;; Call of Duty
chain=forward action=accept dst-port=28959-28961 protocol=udp
src-address-list=downloaders_p2p
9 ;;; downloaders_p2p_block_tcp
chain=forward action=drop dst-port=1000-65535 protocol=tcp
src-address-list=downloaders_p2p
10 ;;; downloaders_p2p_block_udp
chain=forward action=drop dst-port=2000-65535 protocol=udp
src-address-list=downloaders_p2p
najprv mi to oznaci ludi co stahuju cez p2p hodi ich do adress listu, dalsie pravidla obmedzia ludi z adress listu(downloaders_p2p) tak ze im dovolia len porty 0-1000 pre tcp a 0-2000 pre UDP + porty pre niektore sluzby ostatne by malo blokovat - aspon doteraz to blokovalo ale teraz na niektorych pozorujem ze to pusta aj tie porty ktore su blokovane pri danych ludoch v address liste(downloaders_p2p). Vedeli by ste prosim vas poradit kde moze byt problem a ako by sa to dalo riesit? Za kazdu pomoc vopred dakujem.