Установлена Ubuntu
217.55.66.252 адрес машины с Нодени
217.55.66.250 адрес микротика
В фаерволе:
y# iptables -n -L -v --line-numbers
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
num pkts bytes target prot opt in out source destination
1 1638 110K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8080
2 186 9412 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
3 314 226K ACCEPT all -- enp2s0 * 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
num pkts bytes target prot opt in out source destination
1 0 0 ACCEPT tcp -- * * 217.55.66.250 0.0.0.0/0 tcp dpt:8080
2 0 0 ACCEPT tcp -- * * 0.0.0.0/0 217.66.99.250 tcp dpt:8080
3 0 0 ACCEPT tcp -- * * 0.0.0.0/0 217.66.99.250 tcp spt:8080
4 0 0 ACCEPT tcp -- * * 217.55.66.250 0.0.0.0/0 tcp dpt:8080
Chain OUTPUT (policy ACCEPT 309 packets, 37457 bytes)
num pkts bytes target prot opt in out source destination
1 3414 211K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:8080
2 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1812
3 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:1812
4 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1813
5 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:1813
Клиент заблокирован в билинге: Интернета нет
Tcpdump на сервере, выдает:
root@my:/usr/local/nodeny# tcpdump -i enp2s0 -n port 8080
tcpdump: listening on enp2s0, link-type EN10MB (Ethernet), capture size 262144 bytes
07:04:10.943602 IP 217.55.66.252.8080 > 10.0.1.2.56014: Flags [S.], seq 1418934811, ack 2950311529, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:04:10.943610 IP 10.0.1.2.56015 > 217.55.66.252.8080: Flags [S.], seq 35142073, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
07:04:10.943619 IP 217.55.66.252.8080 > 10.0.1.2.56015: Flags [S.], seq 184472726, ack 35142074, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:04:11.205887 IP 217.55.66.252.8080 > 10.0.1.2.56010: Flags [S.], seq 1652429136, ack 1915600124, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:04:11.717886 IP 217.55.66.252.8080 > 10.0.1.2.56013: Flags [S.], seq 470908392, ack 2625623687, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:04:11.717901 IP 217.55.66.252.8080 > 10.0.1.2.56012: Flags [S.], seq 3322572897, ack 3205600477, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:04:11.973888 IP 217.55.66.252.8080 > 10.0.1.2.56015: Flags [S.], seq 184472726, ack 35142074, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:04:11.973903 IP 217.55.66.252.8080 > 10.0.1.2.56014: Flags [S.], seq 1418934811, ack 2950311529, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:04:12.549889 IP 217.55.66.252.8080 > 10.0.1.2.56011: Flags [S.], seq 3484709457, ack 816735160, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
^C
34 packets captured
34 packets received by filter
0 packets dropped by kernel
Клиент в билинге не заблокирован. Все работает, заглушка в том числе:
root@my:/usr/local/nodeny# tcpdump -i enp2s0 -n port 8080
07:01:38.702975 IP 217.66.99.250.55970 > 217.55.66.252.8080: Flags [S.], seq 2832799464, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
07:01:38.703003 IP 217.55.66.252.8080 > 217.66.99.250.55970: Flags [S.], seq 40183081, ack 2832799465, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:01:38.703759 IP 217.66.99.250.55970 > 217.55.66.252.8080: Flags [.], ack 1, win 256, length 0
07:01:38.710228 IP 217.66.99.250.55970 > 217.55.66.252.8080: Flags [P.], seq 1:421, ack 1, win 256, length 420: HTTP: GET / HTTP/1.1
07:01:38.710241 IP 217.55.66.252.8080 > 217.66.99.250.55970: Flags [.], ack 421, win 237, length 0
07:01:38.710581 IP 217.55.66.252.8080 > 217.66.99.250.55970: Flags [P.], seq 1:488, ack 421, win 237, length 487: HTTP: HTTP/1.1 200 OK
07:01:38.710648 IP 217.55.66.252.8080 > 217.66.99.250.55970: Flags [F.], seq 488, ack 421, win 237, length 0
07:01:38.710980 IP 217.66.99.250.55970 > 217.55.66.252.8080: Flags [.], ack 488, win 254, length 0
07:01:38.712289 IP 217.66.99.250.55970 > 217.55.66.252.8080: Flags [.], ack 489, win 254, length 0
07:01:38.712869 IP 217.66.99.250.55970 > 217.55.66.252.8080: Flags [R.], seq 421, ack 489, win 0, length 0