|
发表于 2004-5-27 11:40:24
|
显示全部楼层
MAC绑定建议用arp,用ipfw处理mac比较麻烦,例如:
- arp -s 192.168.0.11 01:02:03:04:05:06
复制代码
你要的规则大概是这样的:
- #允许已建立的连接
- check-state
- #允许DNS
- netuser="192.168.0.0/24{11-18,25}"
- allow udp from any domain to ${netuser}
- allow udp from ${netuser} to any domain
- allow tcp from ${netuser} to any domain keep-state
- #允许11-18使用http
- allow tcp from 192.168.0.0/24{11-18} to any http keep-state
- #允许25使用smtp和pop3
- allow tcp from 192.168.0.25 to any smtp keep-state
- allow tcp from 192.168.0.25 to any pop3 keep-state
- #默认禁止其他连接
- deny ip from any to any
复制代码 |
|