, fw-policy
all - ( ip- src/dst)
local - , ,
drop -
pass -
restrict all drop local pass , , src/dst IP- //, . , / "" . restrict local drop fw-policy. acct-policy fw-policy, no-local-pass, .. restrict all restrict local.
. , .
, . - mac ( , , . )
unit group oid 08EA6D name LAN
unit host oid 0AD6A9 name server ip 192.168.9.1 parent LAN acct-policy ip
unit user oid 04D535 name HOST1 ip 192.168.9.2 parent LAN acct-policy ip
unit user oid 0E8592 name HOST2 ip 192.168.9.5 parent LAN acct-policy ip
unit user oid 0C14C4 name HOST3 ip 192.168.9.7 parent LAN acct-policy ip
unit user oid 06941D name HOST4 ip 192.168.9.8 parent LAN acct-policy ip
unit user oid 0E9C62 name HOST5 ip 192.168.9.10 parent LAN acct-policy ip
unit user oid 0B915E name HOST6 ip 192.168.9.11 parent LAN acct-policy ip
unit user oid 0023E6 name HOST7 ip 192.168.9.12 parent LAN acct-policy ip
unit user oid 073899 name HOST8 ip 192.168.9.20 parent LAN acct-policy ip
unit user oid 083230 name HOST9 ip 192.168.9.32 parent LAN acct-policy ip
service storage 1
type mysql
user netams
password ***
dbname netams
accept all
. , , . accept all . .
service data-source 1
type libpcap
source fxp0
.FXP0 - . libpcap . libcpap - . , , .
service data-source 1
type ip-traffic
source divert 199
rule 9000 "ip from 192.168.0.0/24 to any out xmit fxp0"
rule 11000 "ip from any to 192.168.0.0/24 in via fxp0"
divert natd from any to any via interface 9000 11000
199 , . FXP0 .
- monitor.
, . , 3.4.x 3.3.5
3.4.
enable
configure terminal
service monitor
monitor unit oid/name
service html
path /usr/local/www/stat
run 10sec
url http://192.168.9.1/stat
client-pages all
account-pages none
service scheduler
oid 08FFFF time 10sec action "html"
. . - quota. _ _ .
policy oid 013ECF name msgs target proto tcp port 25 110 5190
Service quota 0
storage 1
policy ip
block-policy msgs^M
notify soft owner
notify hard owner
notify return owner
, , Service Storage
. OID', .
Admintool, . :
telnet localhost 21000 ( )
enable
configure terminal
service quota
set OID/NAME active
set OID/NAME block-policy [ fw-policy, ] day [ ] in/out/both week [ ] in/out/both month [ ] in/out/both
- HOST/OID, , - ip, fw-policy, msgs. ip - 300 . K M G.
: , fw-policy msgs, .. 110 25 5190.
01300 divert 199 ip from not 192.168.0.0/24 to any via em0
09000 divert 199 ip from 192.168.0.0/24 to any out xmit fxp0
09100 divert 199 ip from 192.168.254.0/24 to any out xmit fxp0
09500 fwd 127.0.0.1,3128 tcp from 192.168.0.0/24 to not 192.168.0.254 dst-port 80,3128,8080,8101,8108 via fxp0
09600 fwd 127.0.0.1,3128 tcp from 192.168.0.0/21 to not 192.168.0.254 dst-port 80,3128,8080,8101,8108 via fxp0
10000 divert 8668 ip from any to any via fxp0
11000 divert 199 ip from any to 192.168.0.0/24 in via fxp0