| 本帖最後由 167pk 於 2014-11-1 07:53 編輯 
 複製代碼add action=mark-connection chain=prerouting comment="xbox live mark" \
    new-connection-mark=cm-games-in port=3074 protocol=tcp
add action=mark-connection chain=prerouting in-interface=$WANInter \
    new-connection-mark=cm-games-in port=88,3074,3544,4500 protocol=udp
add action=mark-connection chain=prerouting comment="steam mark-in" \
    new-connection-mark=cm-games-in port=27014-27050 protocol=tcp
add action=mark-connection chain=prerouting dst-address-list=Internal-Nets \
    in-interface=$WANInter new-connection-mark=cm-games-in port=\
    4380,28960,27000-27030 protocol=udp
add action=mark-connection chain=prerouting comment="ps3 online mark" \
    new-connection-mark=cm-games-in port=5223 protocol=tcp
add action=mark-connection chain=prerouting in-interface=$WANInter \
    new-connection-mark=cm-games-in port=3478,3479,3658 protocol=udp
add action=mark-connection chain=prerouting comment="wii online mark" \
    new-connection-mark=cm-games-in port=28910,29900-29901,29920 protocol=tcp
add action=mark-packet chain=prerouting comment="games packet mark-in" \
    connection-mark=cm-games-in new-packet-mark=games-in passthrough=no
add action=mark-connection chain=postrouting comment="steam mark-out" \
    new-connection-mark=cm-games-out out-interface=$WANInter port=\
    53,1500,3005,3101,3478,4379-4380,27000-27030,28960 protocol=udp \
    src-address-list=Internal-Nets
add action=mark-packet chain=postrouting comment="games packet mark-out" \
    connection-mark=cm-games-out new-packet-mark=games-out passthrough=no
add action=mark-connection chain=forward comment="VOIP mark-in" \
    dst-address-list=VOIP in-interface=$WANInter new-connection-mark=\
    cm-voip-in
add action=mark-connection chain=prerouting in-interface=$WANInter \
    new-connection-mark=cm-voip-in port=3478,3784,4080,5060-5061,5223 \
    protocol=tcp
add action=mark-connection chain=prerouting in-interface=$WANInter \
    new-connection-mark=cm-voip-in port=3784,5004,5060-5061,9987,16348-16798 \
    protocol=udp
add action=mark-packet chain=prerouting connection-mark=cm-voip-in \
    new-packet-mark=voip-in passthrough=no
add action=mark-connection chain=postrouting comment="VOIP mark-out" \
    new-connection-mark=cm-voip-out out-interface=$WANInter \
    src-address-list=VOIP
add action=mark-connection chain=postrouting new-connection-mark=cm-voip-out \
    out-interface=$WANInter port=3478,3784,4080,5060-5061,5223 protocol=tcp
add action=mark-connection chain=postrouting new-connection-mark=cm-voip-out \
    out-interface=$WANInter port=3784,5004,5060-5061,9987,16348-16798 \
    protocol=udp
add action=mark-packet chain=postrouting connection-mark=cm-voip-out \
    new-packet-mark=voip-out passthrough=no
add action=mark-connection chain=prerouting comment="VPN mark-in" \
    in-interface=$WANInter new-connection-mark=cm-vpn-in protocol=gre
add action=mark-connection chain=prerouting in-interface=$WANInter \
    new-connection-mark=cm-vpn-in protocol=ipsec-esp
add action=mark-connection chain=prerouting in-interface=$WANInter \
    new-connection-mark=cm-vpn-in protocol=ipsec-ah
add action=mark-connection chain=prerouting in-interface=$WANInter \
    new-connection-mark=cm-vpn-in port=500,1701,4500 protocol=udp
add action=mark-connection chain=prerouting in-interface=$WANInter \
    new-connection-mark=cm-vpn-in port=1723 protocol=tcp
add action=mark-packet chain=prerouting connection-mark=cm-vpn-in \
    new-packet-mark=vpn-in passthrough=no
add action=mark-connection chain=postrouting comment="VPN mark-out" \
    new-connection-mark=cm-vpn-out out-interface=$WANInter protocol=gre
add action=mark-connection chain=postrouting new-connection-mark=cm-vpn-out \
    out-interface=$WANInter protocol=ipsec-esp
add action=mark-connection chain=postrouting new-connection-mark=cm-vpn-out \
    out-interface=$WANInter protocol=ipsec-ah
add action=mark-connection chain=postrouting new-connection-mark=cm-vpn-out \
    out-interface=$WANInter port=500,1701,4500 protocol=udp
add action=mark-connection chain=postrouting new-connection-mark=cm-vpn-out \
    out-interface=$WANInter port=1723 protocol=tcp
add action=mark-packet chain=postrouting connection-mark=cm-vpn-out \
    new-packet-mark=vpn-out passthrough=no
add action=mark-connection chain=prerouting comment="ALL in" in-interface=\
    $WANInter new-connection-mark=cm-in
add action=mark-packet chain=prerouting connection-mark=cm-in \
    new-packet-mark=in passthrough=no
add action=mark-connection chain=postrouting comment="ALL out" \
    new-connection-mark=cm-out out-interface=$WANInter
add action=mark-packet chain=postrouting connection-mark=cm-out \
    new-packet-mark=out passthrough=no
 |