wt020 发表于 2008-8-5 12:05:41

ROS2.9.27 控制所有类型的P2P服务--要求加分!!!!

方法很简单,效果不一般! i 不对之处欢迎拍砖!!!


/ ip firewall mangle
add chain=prerouting src-address=10.200.0.0/15 protocol=udp \
    src-port=1000-65535 packet-size=800-1500 src-address-list=p2p-udp \
    action=mark-packet new-packet-mark=P2PUP passthrough=yes comment="P2P-UDP" \
    disabled=no
add chain=prerouting src-address=10.200.0.0/16 protocol=!tcp \
    connection-limit=15,32 action=add-src-to-address-list address-list=p2p-udp \
    address-list-timeout=30s comment="" disabled=no
add chain=prerouting src-address=10.200.0.0/15 protocol=tcp dst-port=!80 \
    packet-size=800-1500 src-address-list=p2p-20 action=mark-packet \
    new-packet-mark=P2PUP passthrough=yes comment="P2P-TCP" disabled=no
add chain=prerouting src-address=10.200.0.0/15 protocol=tcp dst-port=!80 \
    connection-limit=20,32 packet-size=800-1500 action=add-src-to-address-list \
    address-list=p2p-20 address-list-timeout=30s comment="" disabled=no
#注意10.200.0.0/15是我内网源地址,你使用前改成你的源.

/ queue simple
add name="P2P-all" dst-address=0.0.0.0/0 interface=ydwan parent=none \
    packet-marks=P2PUP direction=download priority=8 queue=Pcq_UP_C/Pcq_UP_C \
    limit-at=64000/64000 max-limit=200000/128000 total-queue=default-small \
    disabled=no

#queue=Pcq_UP_C自己建一个PCQ
#interface=ydwan 是ROS出口,我内网全是PPPOE上网,所以只好用出口限制.
#以是只是限制了P2P上传流量,别的限制应该很简单了.

/ ip firewall filter
add chain=forward protocol=udp src-port=10000-65535 \
    time=20h-23h,sat,fri,thu,wed,tue,mon,sun src-address-list=p2p-udp \
    action=drop comment="P2P-UDP" disabled=no
#再加个drop也很不错

hcb 发表于 2008-8-5 12:07:37

留个脚印

wt020 发表于 2008-8-5 19:06:12

没人在意?:L

suchengyu 发表于 2008-9-6 08:37:12

有问题

add chain=prerouting src-address=10.200.0.0/16 protocol=!tcp \
    connection-limit=15,32 action=add-src-to-address-list address-list=p2p-udp \
    address-list-timeout=30s comment="" disabled=no
这句是加不上去的!系统提示只有tcp 才可以设置connection-limit

onothing 发表于 2008-9-6 13:52:44

只能远观

286220302 发表于 2009-12-14 13:05:02

下载的怎么写啊,帖出来好不好。
页: [1]
查看完整版本: ROS2.9.27 控制所有类型的P2P服务--要求加分!!!!