mirror of https://gitee.com/openkylin/libvirt.git
110 lines
1.6 KiB
Plaintext
110 lines
1.6 KiB
Plaintext
iptables \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
-m mac \
|
|
--mac-source 01:02:03:04:05:06 \
|
|
--destination 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
-m state \
|
|
--state NEW,ESTABLISHED \
|
|
-j RETURN
|
|
iptables \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--source 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
-m state \
|
|
--state ESTABLISHED \
|
|
-j ACCEPT
|
|
iptables \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
-m mac \
|
|
--mac-source 01:02:03:04:05:06 \
|
|
--destination 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
-m state \
|
|
--state NEW,ESTABLISHED \
|
|
-j RETURN
|
|
iptables \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--destination 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 33 \
|
|
--dport 20:21 \
|
|
--sport 100:1111 \
|
|
-j RETURN
|
|
iptables \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
-m mac \
|
|
--mac-source 01:02:03:04:05:06 \
|
|
--source 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 33 \
|
|
--sport 20:21 \
|
|
--dport 100:1111 \
|
|
-j ACCEPT
|
|
iptables \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--destination 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 33 \
|
|
--dport 20:21 \
|
|
--sport 100:1111 \
|
|
-j RETURN
|
|
iptables \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--destination 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 63 \
|
|
--dport 255:256 \
|
|
--sport 65535:65535 \
|
|
-j RETURN
|
|
iptables \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
-m mac \
|
|
--mac-source 01:02:03:04:05:06 \
|
|
--source 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 63 \
|
|
--sport 255:256 \
|
|
--dport 65535:65535 \
|
|
-j ACCEPT
|
|
iptables \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--destination 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 63 \
|
|
--dport 255:256 \
|
|
--sport 65535:65535 \
|
|
-j RETURN
|
|
iptables \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--tcp-flags SYN ALL \
|
|
-j ACCEPT
|
|
iptables \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--tcp-flags SYN SYN,ACK \
|
|
-j ACCEPT
|
|
iptables \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--tcp-flags RST NONE \
|
|
-j ACCEPT
|
|
iptables \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--tcp-flags PSH NONE \
|
|
-j ACCEPT
|