mirror of https://gitee.com/openkylin/libvirt.git
129 lines
1.9 KiB
Plaintext
129 lines
1.9 KiB
Plaintext
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
-m mac \
|
|
--mac-source 01:02:03:04:05:06 \
|
|
--destination 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--source 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
-m mac \
|
|
--mac-source 01:02:03:04:05:06 \
|
|
--destination 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--destination 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 33 \
|
|
--dport 20:21 \
|
|
--sport 100:1111 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
-m mac \
|
|
--mac-source 01:02:03:04:05:06 \
|
|
--source 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 33 \
|
|
--sport 20:21 \
|
|
--dport 100:1111 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--destination 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 33 \
|
|
--dport 20:21 \
|
|
--sport 100:1111 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--destination 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 63 \
|
|
--dport 255:256 \
|
|
--sport 65535:65535 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
-m mac \
|
|
--mac-source 01:02:03:04:05:06 \
|
|
--source 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 63 \
|
|
--sport 255:256 \
|
|
--dport 65535:65535 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--destination 10.1.2.3/32 \
|
|
-m dscp \
|
|
--dscp 63 \
|
|
--dport 255:256 \
|
|
--sport 65535:65535 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j RETURN
|