|
马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。
您需要 登录 才可以下载或查看,没有账号?注册
×
本帖最后由 lzw83 于 2011-11-13 09:25 编辑
- # ros3.30-HTB
- #
- # 说明: 内网网卡名称改为lan 默认带宽100M, 200台客户机 请根据实际情况修改
- #
- /ip firewall mangle
- add action=mark-connection chain=prerouting comment=" *\B7\F0\B9\E2\B2\CB\B8\
- \F9\CC\B7* QQ:304120225 HTB + PCQ \B6\AF\CC\AC\C1\F7\BF\D8 \$\$\$\
- \$\$\$\$\$ \$\$\$\$\$\$\$\$ \CA\A5\CD\A2\B3\F6\C6\B7 \B1\D8\CA\F4\
- \BE\AB\C6\B7 " disabled=no limit=10,10 new-connection-mark=icmp \
- passthrough=yes protocol=icmp
- add action=mark-packet chain=forward comment="" connection-mark=icmp \
- disabled=no in-interface=lan new-packet-mark=icmps passthrough=no
- add action=mark-packet chain=prerouting comment="" connection-mark=icmp \
- disabled=no new-packet-mark=icmp passthrough=no
- add action=mark-packet chain=forward comment=ALL_UP disabled=no in-interface=\
- lan new-packet-mark=lanup passthrough=no
- add action=mark-connection chain=prerouting comment=\
- "HTTP\CF\C2\D4\D8_\C1\B4\BD\D3" connection-bytes=700000-0 disabled=no \
- new-connection-mark=http passthrough=yes protocol=tcp src-port=80
- add action=mark-packet chain=prerouting comment="" connection-mark=http \
- disabled=no new-packet-mark=http passthrough=no
- add action=mark-connection chain=prerouting comment=\
- "WEB\CD\F8\D2\B3_\C1\B4\BD\D3" connection-bytes=0-700000 disabled=no \
- new-connection-mark=web passthrough=yes protocol=tcp src-port=80
- add action=mark-connection chain=prerouting comment="" connection-rate=0-80k \
- disabled=no new-connection-mark=web passthrough=yes protocol=udp \
- src-port=53
- add action=mark-packet chain=prerouting comment="" connection-mark=web \
- disabled=no new-packet-mark=web passthrough=no
- add action=mark-connection chain=prerouting comment="Games_\C1\B4\BD\D3" \
- disabled=no new-connection-mark=game passthrough=yes protocol=tcp \
- src-port=3724,6112,6114,1119,7777,10241,2099,5223
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=tcp src-port=\
- 5692,7101-7103,28012,2349,8586,10001-10070,28008,31414,6299,5130
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=tcp src-port=\
- 3110-3120,6217,2181,28880,8001,21800,8030,6020,6030,6877,4680,13000-13002
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=tcp src-port=\
- 3110-3120,28993,29000,5816,6868,33567,39311,9600,1119,3025,31414,3470
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=tcp src-port=\
- 6004,7004,5562,9010-9014,17703-17706,8801,1253,1346,1272,1203,3468
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=tcp src-port=\
- 25520-25521,25511,10906,30000-30010,8445-8451,3731-3735,7449,7237
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=tcp src-port=\
- 7100-7200,7440,7491,7204,7400-7401,7500,7300,6040,6050,6661-6663
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=tcp src-port=\
- 27931,47611,1607,2175,6000,20002-20007,22001,13317
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=tcp src-port=\
- 7100,7203-7204,7400,7417,6831-6832,6840-6847,8888
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=tcp src-port=\
- 14500,8000,15000
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=udp src-port=\
- 12000-13000,2349,5063,39311,1764,12721,3133,4550,3620
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=udp src-port="8861,1932,\
- 2287,14531,1897,2428,13735,1039,1100,1210,1381,1473,1509,1785,18979"
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=udp src-port="1140,1371,\
- 1510,16434,9865,2105,1497,31519,9000,1151,4311,1506,1559,55952,59823"
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=udp src-port="32404,3240\
- 5,32406,1176,1076,1169,13791,1139,11337,9000,1511,20096,20059,27005-27030"
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=udp src-port="7263,2408,\
- 2468,2117,1871,1429,2294,1520,57236,1429,2494,7625,1552,1842,12411"
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=udp src-port="1273,1061,\
- 65473,1940,2882,1501,4078,8369,4861,4964,8445-8452,7081,30700-30711"
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=udp src-port="32824,9646\
- ,8024,15966,18997,49386,15086,22634,35339,1610,1308,6660,6600,1991,30195"
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=udp src-port="12345,6660\
- ,1610,6600,7002,15002-15004,3100,1059,4111,32424,32299,15101-15104,14401"
- add action=mark-connection chain=prerouting comment="" disabled=no \
- new-connection-mark=game passthrough=yes protocol=udp src-port=\
- 8000-8005,32407
- add action=mark-packet chain=prerouting comment="" connection-mark=game \
- disabled=no new-packet-mark=game passthrough=no
- add action=mark-connection chain=prerouting comment="Heavy_\C1\B4\BD\D3" \
- connection-bytes=500000-0 connection-rate=80k-200M disabled=no \
- new-connection-mark=heavy passthrough=yes protocol=tcp src-port=\
- 21,80,443,1024-65535
- add action=mark-connection chain=prerouting comment="" connection-bytes=\
- 500000-0 connection-rate=80k-200M disabled=no new-connection-mark=heavy \
- passthrough=yes protocol=udp src-port=21,80,443,1024-65535
- add action=mark-packet chain=prerouting comment="" connection-mark=heavy \
- disabled=no new-packet-mark=heavy passthrough=no
- add action=mark-connection chain=prerouting comment="Small_\C1\B4\BD\D3" \
- disabled=no new-connection-mark=small passthrough=yes
- add action=mark-packet chain=prerouting comment="" connection-mark=small \
- disabled=no new-packet-mark=small passthrough=no
- /queue type
- set default kind=pfifo name=default pfifo-limit=50
- set ethernet-default kind=pfifo name=ethernet-default pfifo-limit=50
- set wireless-default kind=sfq name=wireless-default sfq-allot=1514 \
- sfq-perturb=5
- set synchronous-default kind=red name=synchronous-default red-avg-packet=1000 \
- red-burst=20 red-limit=60 red-max-threshold=50 red-min-threshold=10
- set hotspot-default kind=sfq name=hotspot-default sfq-allot=1514 sfq-perturb=\
- 5
- add kind=pcq name=small pcq-classifier=dst-address pcq-limit=50 pcq-rate=\
- 512000 pcq-total-limit=10000
- add kind=pcq name=0m pcq-classifier=dst-address pcq-limit=50 pcq-rate=0 \
- pcq-total-limit=10000
- add kind=pcq name=lanup pcq-classifier=src-address pcq-limit=50 pcq-rate=\
- 1000000 pcq-total-limit=10000
- add kind=pcq name=game pcq-classifier=dst-address pcq-limit=60 pcq-rate=\
- 512000 pcq-total-limit=12000
- set default-small kind=pfifo name=default-small pfifo-limit=10
- /queue tree
- add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=0 \
- max-limit=80M name=HTB_DOWN parent=global-in priority=6
- add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=5M \
- max-limit=70M name="1_\CD\F8\C2\E7\D3\CE\CF\B7" packet-mark=game parent=\
- HTB_DOWN priority=2 queue=game
- add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=20M \
- max-limit=70M name="2_\CD\F8\D2\B3\E4\AF\C0\C0" packet-mark=web parent=\
- HTB_DOWN priority=3 queue=0m
- add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=20M \
- max-limit=70M name="3_\D0\A1\B0\FC\CA\FD\BE\DD" packet-mark=small parent=\
- HTB_DOWN priority=5 queue=small
- add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=0 \
- max-limit=40M name=HTB_UP packet-mark=lanup parent=global-out priority=7 \
- queue=lanup
- add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=10M \
- max-limit=70M name="5_\CE\C4\BC\FE\CF\C2\D4\D8" packet-mark=heavy parent=\
- HTB_DOWN priority=8 queue=0m
- add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=10M \
- max-limit=70M name="4_\D4\DA\CF\DF\CA\D3\C6\B5" packet-mark=http parent=\
- HTB_DOWN priority=6 queue=0m
- add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=1M \
- max-limit=1M name=ICMP_DOWN packet-mark=icmp parent=global-in priority=1 \
- queue=default
- add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=1M \
- max-limit=1M name=ICMP_UP packet-mark=icmps parent=global-out priority=1 \
- queue=default
复制代码 |
|