本帖最後由 167pk 於 2014-11-1 07:53 編輯
- add action=mark-connection chain=prerouting comment="xbox live mark" \
- new-connection-mark=cm-games-in port=3074 protocol=tcp
- add action=mark-connection chain=prerouting in-interface=$WANInter \
- new-connection-mark=cm-games-in port=88,3074,3544,4500 protocol=udp
- add action=mark-connection chain=prerouting comment="steam mark-in" \
- new-connection-mark=cm-games-in port=27014-27050 protocol=tcp
- add action=mark-connection chain=prerouting dst-address-list=Internal-Nets \
- in-interface=$WANInter new-connection-mark=cm-games-in port=\
- 4380,28960,27000-27030 protocol=udp
- add action=mark-connection chain=prerouting comment="ps3 online mark" \
- new-connection-mark=cm-games-in port=5223 protocol=tcp
- add action=mark-connection chain=prerouting in-interface=$WANInter \
- new-connection-mark=cm-games-in port=3478,3479,3658 protocol=udp
- add action=mark-connection chain=prerouting comment="wii online mark" \
- new-connection-mark=cm-games-in port=28910,29900-29901,29920 protocol=tcp
- add action=mark-packet chain=prerouting comment="games packet mark-in" \
- connection-mark=cm-games-in new-packet-mark=games-in passthrough=no
- add action=mark-connection chain=postrouting comment="steam mark-out" \
- new-connection-mark=cm-games-out out-interface=$WANInter port=\
- 53,1500,3005,3101,3478,4379-4380,27000-27030,28960 protocol=udp \
- src-address-list=Internal-Nets
- add action=mark-packet chain=postrouting comment="games packet mark-out" \
- connection-mark=cm-games-out new-packet-mark=games-out passthrough=no
- add action=mark-connection chain=forward comment="VOIP mark-in" \
- dst-address-list=VOIP in-interface=$WANInter new-connection-mark=\
- cm-voip-in
- add action=mark-connection chain=prerouting in-interface=$WANInter \
- new-connection-mark=cm-voip-in port=3478,3784,4080,5060-5061,5223 \
- protocol=tcp
- add action=mark-connection chain=prerouting in-interface=$WANInter \
- new-connection-mark=cm-voip-in port=3784,5004,5060-5061,9987,16348-16798 \
- protocol=udp
- add action=mark-packet chain=prerouting connection-mark=cm-voip-in \
- new-packet-mark=voip-in passthrough=no
- add action=mark-connection chain=postrouting comment="VOIP mark-out" \
- new-connection-mark=cm-voip-out out-interface=$WANInter \
- src-address-list=VOIP
- add action=mark-connection chain=postrouting new-connection-mark=cm-voip-out \
- out-interface=$WANInter port=3478,3784,4080,5060-5061,5223 protocol=tcp
- add action=mark-connection chain=postrouting new-connection-mark=cm-voip-out \
- out-interface=$WANInter port=3784,5004,5060-5061,9987,16348-16798 \
- protocol=udp
- add action=mark-packet chain=postrouting connection-mark=cm-voip-out \
- new-packet-mark=voip-out passthrough=no
- add action=mark-connection chain=prerouting comment="VPN mark-in" \
- in-interface=$WANInter new-connection-mark=cm-vpn-in protocol=gre
- add action=mark-connection chain=prerouting in-interface=$WANInter \
- new-connection-mark=cm-vpn-in protocol=ipsec-esp
- add action=mark-connection chain=prerouting in-interface=$WANInter \
- new-connection-mark=cm-vpn-in protocol=ipsec-ah
- add action=mark-connection chain=prerouting in-interface=$WANInter \
- new-connection-mark=cm-vpn-in port=500,1701,4500 protocol=udp
- add action=mark-connection chain=prerouting in-interface=$WANInter \
- new-connection-mark=cm-vpn-in port=1723 protocol=tcp
- add action=mark-packet chain=prerouting connection-mark=cm-vpn-in \
- new-packet-mark=vpn-in passthrough=no
- add action=mark-connection chain=postrouting comment="VPN mark-out" \
- new-connection-mark=cm-vpn-out out-interface=$WANInter protocol=gre
- add action=mark-connection chain=postrouting new-connection-mark=cm-vpn-out \
- out-interface=$WANInter protocol=ipsec-esp
- add action=mark-connection chain=postrouting new-connection-mark=cm-vpn-out \
- out-interface=$WANInter protocol=ipsec-ah
- add action=mark-connection chain=postrouting new-connection-mark=cm-vpn-out \
- out-interface=$WANInter port=500,1701,4500 protocol=udp
- add action=mark-connection chain=postrouting new-connection-mark=cm-vpn-out \
- out-interface=$WANInter port=1723 protocol=tcp
- add action=mark-packet chain=postrouting connection-mark=cm-vpn-out \
- new-packet-mark=vpn-out passthrough=no
- add action=mark-connection chain=prerouting comment="ALL in" in-interface=\
- $WANInter new-connection-mark=cm-in
- add action=mark-packet chain=prerouting connection-mark=cm-in \
- new-packet-mark=in passthrough=no
- add action=mark-connection chain=postrouting comment="ALL out" \
- new-connection-mark=cm-out out-interface=$WANInter
- add action=mark-packet chain=postrouting connection-mark=cm-out \
- new-packet-mark=out passthrough=no
複製代碼 |