/sbin/tc filter add dev eth0 parent 1:0 protocol ip prio 1 handle 1 fw classid 1:10
sbin/iptables -t mangle -A PREROUTING -s 172.26.48.67 -j MARK --set-mark 0x1
sbin/iptables -t mangle -A PREROUTING -s 172.26.48.67 -j MARK --set-mark 0x1
用这中方式可以,但是必须用snat上网,用squid做代理就不行了.