原理:通过控制arp表的总数,和允许上网的ip地址,来执行ip和物力网卡地址帮定
for b in `awk '{print $1 \",\" $2}' /home/etracer/addr_fw`
do
a=`echo \"$b\" |awk -F\",\" '{print $1}'`
c=`echo \"$b\" |awk -F\",\" '{print $1 \" \" $2}'`
arp -s $c
iptables -A FORWARD -s $a -j ACCEPT
done
----------------------
[root@firewall etracer]# cat addr_fw
192.168.0.40 00:15:f2:ef:f4:36 wanglaowu
192.168.0.42 00:15:f2:ef:f5:01 pangang
[root@firewall etracer]#
复制代码
[ 本帖最后由 x-phenix 于 2006-7-6 15:31 编辑 ]