From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Message-ID: <40FF8709.9000801@zaz.zp.ua> Date: Thu, 22 Jul 2004 12:21:13 +0300 From: Gennadiy Redko Organization: =?windows-1251?Q?=C7=C0=CE_=22=C7=C0=C7=22_=E3=2E_=C7?= =?windows-1251?Q?=E0=EF=EE=F0=EE=E6=FC=E5?= User-Agent: Mozilla/5.0 (X11; U; Linux i686; ru-RU; rv:1.4) Gecko/20030710 X-Accept-Language: ru-ru, en, uk, en-us MIME-Version: 1.0 To: community@altlinux.ru Subject: Re: [Comm] ipchains + =?windows-1251?Q?=F4=E8=EB=FC=F2=F0=E0=F6=E8?= =?windows-1251?Q?=FF_=EF=EE_=EC=E0=EA=E0=EC?= References: <1777940942.20040722111903@vostok.net.ua> <200407221325.44534.combr@vesna.ru> <782338533.20040722114217@vostok.net.ua> In-Reply-To: <782338533.20040722114217@vostok.net.ua> X-Enigmail-Version: 0.76.1.0 X-Enigmail-Supports: pgp-inline, pgp-mime Content-Type: text/plain; charset=windows-1251; format=flowed Content-Transfer-Encoding: 8bit X-BeenThere: community@altlinux.ru X-Mailman-Version: 2.1.5 Precedence: list Reply-To: community@altlinux.ru List-Id: Mailing list for ALT Linux users List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 22 Jul 2004 09:21:25 -0000 Archived-At: List-Archive: List-Post: Alexey S. Kuznetsov пишет: > > ну я понимаю...она отслеживает.....есть ли аналог, если нет iptables > такой кооманде: > iptables -I input -s 192.168.5.117 -d 192.168.5.1 -m mac --mac-source 00:0a:00:00:00:01 -j ACCEPT > > Можно вручную задать соответствие MAC и IP: man arp /skip -s hostname hw_addr, --set hostname Manually create an ARP address mapping entry for host hostname with hardware address set to hw_addr class, but for most classes one can assume that the usual presentation can be used. For the Ethernet class, this is 6 bytes in hexadecimal, separated by colons. When adding proxy arp entries (that is those with the publish flag set a netmask may be specified to proxy arp for entire subnets. This is not good practice, but is supported by older kernels because it can be useful. If the temp flag is not supplied entries will be permanent stored into the ARP cache. NOTE: As of kernel 2.2.0 it is no longer possible to set an ARP entry for an entire subnet. Linux instead does automagic proxy arp when a route exists and it is forwarding. See arp(7) for details.