Не надо ничего бояться, надо просто думать головой!
А что бы голова не болела, ко всему прочему надо ее чаще тренировать, а не только в нее есть ;)
iptables -t filter -D OUTPUT -o br-wan -j u-l-out
iptables -t filter -F u-l-out
iptables -t filter -X u-l-out
iptables -t filter -N u-l-out
iptables -t filter -I OUTPUT -o br-wan -j u-l-out
iptables -t filter -A u-l-out -p icmp -j RETURN
for I in `uci show network.wan.dns | cut -d'=' -f2`
do
iptables -t filter -A u-l-out -p udp -d "${I}" --dport 53 -j RETURN
iptables -t filter -A u-l-out -p tcp -d "${I}" --dport 53 -j RETURN
done
# uci show system.ntp.server | cut -d '=' -f 2
for I in `uci show system.ntp.server | cut -d '=' -f 2`
do
#iptables -t filter -A u-l-out -p udp --dport 123 -j RETURN
iptables -t filter -A u-l-out -p udp -d "${I}" --dport 123 -j RETURN
done
iptables -t filter -A u-l-out -p udp --dport 123 -j DROP
iptables -t filter -A u-l-out -p tcp -d freedns.afraid.org --dport 80 -j RETURN
iptables -t filter -A u-l-out -p tcp -d openwrt.org --dport 80 -j RETURN
iptables -t filter -A u-l-out -j LOG
iptables -t filter -A u-l-out -j DROP
#iptables -t filter -A u-l-out -p udp -m multiport ! --sports 53,67,68,80,123 -j LOG
iptables -t filter -A u-l-out -p udp -m multiport ! --dports 53,67,68,80,123 -j LOG
#iptables -t filter -A u-l-out -p tcp -m multiport ! --sports 53,80 -j LOG
#iptables -t filter -A u-l-out -p tcp -m multiport ! --dports 53,80 -j LOG
iptables -t filter -A u-l-out -p tcp --syn -m multiport ! --dports 53,80 -j LOG
#iptables -t filter -I OUTPUT -o br-wan -j u-l-out
iptables -t filter -D INPUT -i br-wan -j u-l-in
iptables -t filter -F u-l-in
iptables -t filter -X u-l-in
iptables -t filter -N u-l-in
iptables -t filter -I INPUT -i br-wan -j u-l-in
iptables -t filter -A u-l-in -p icmp -j RETURN
for I in `uci show network.wan.dns | cut -d'=' -f2`
do
iptables -t filter -A u-l-in -p udp -s "${I}" --sport 53 -j RETURN
iptables -t filter -A u-l-in -p tcp -s "${I}" --sport 53 -j RETURN
done
for I in `uci show system.ntp.server | cut -d '=' -f 2`
do
iptables -t filter -A u-l-in -p udp -s "${I}" --sport 123 -j RETURN
done
iptables -t filter -A u-l-in -p tcp -s freedns.afraid.org --sport 80 -j RETURN
iptables -t filter -A u-l-in -p tcp -s openwrt.org --sport 80 -j RETURN
#iptables -t filter -A u-l-in -j LOG
iptables -t filter -A u-l-in -j DROP
iptables -t filter -F u-l-in-u53
iptables -t filter -X u-l-in-u53
iptables -t filter -N u-l-in-u53
iptables -t filter -A u-l-in-u53 -p udp -m multiport --dports 53,67,68,80 -j LOG
#iptables -t filter -A u-l-in -p udp -m multiport ! --sports 53,67,68,80,123 -j LOG
iptables -t filter -A u-l-in -p udp -m multiport ! --sports 53,67,68,80,123 -j LOG
#iptables -t filter -A u-l-in -p udp -m multiport --dports 53,67,68,80 -j LOG
#iptables -t filter -A u-l-in -p tcp -m multiport ! --sports 53,80 -j LOG
#iptables -t filter -A u-l-in -p tcp ! --syn -m multiport --dports 53,80,22 -j LOG
iptables -t filter -A u-l-in -p tcp ! --syn -m multiport ! --sports 53,80,22 -j LOG
#iptables -t filter -I INPUT -i br-wan -j u-l-in