Не работает
Ответы уходят на первый маршрутизатор.
# tcpdump -pi eth0 -s 6553 -e -- host 86.62.108.132 and \(\(tcp port 80\) or \(tcp port 81\)\)
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 6553 bytes
15:01:15.836100 00:d0:d0:61:30:2c (oui Unknown) > 00:60:97:93:62:fe (oui Unknown), ethertype IPv4 (0x0800), length 62: h86-62-108-132.ln.rinet.ru.1141 > daemon1.darkdragon.lan.81: S 1557011461:1557011461(0) win 65535 <mss 1460,nop,nop,sackOK>
15:01:15.836294 00:60:97:93:62:fe (oui Unknown) > 00:1b:11:84:e3:90 (oui Unknown), ethertype IPv4 (0x0800), length 62: daemon1.darkdragon.lan.81 > h86-62-108-132.ln.rinet.ru.1141: S 592007803:592007803(0) ack 1557011462 win 5840 <mss 1460,nop,nop,sackOK>
15:01:15.839728 00:1b:11:84:e3:90 (oui Unknown) > 00:60:97:93:62:fe (oui Unknown), ethertype IPv4 (0x0800), length 60: h86-62-108-132.ln.rinet.ru.1141 > daemon1.darkdragon.lan.81: R 1557011462:1557011462(0) win 0
15:01:18.795675 00:d0:d0:61:30:2c (oui Unknown) > 00:60:97:93:62:fe (oui Unknown), ethertype IPv4 (0x0800), length 62: h86-62-108-132.ln.rinet.ru.1141 > daemon1.darkdragon.lan.81: S 1557011461:1557011461(0) win 65535 <mss 1460,nop,nop,sackOK>
15:01:18.795834 00:60:97:93:62:fe (oui Unknown) > 00:1b:11:84:e3:90 (oui Unknown), ethertype IPv4 (0x0800), length 62: daemon1.darkdragon.lan.81 > h86-62-108-132.ln.rinet.ru.1141: S 638250873:638250873(0) ack 1557011462 win 5840 <mss 1460,nop,nop,sackOK>
15:01:18.799341 00:1b:11:84:e3:90 (oui Unknown) > 00:60:97:93:62:fe (oui Unknown), ethertype IPv4 (0x0800), length 60: h86-62-108-132.ln.rinet.ru.1141 > daemon1.darkdragon.lan.81: R 1557011462:1557011462(0) win 0
15:01:24.786658 00:d0:d0:61:30:2c (oui Unknown) > 00:60:97:93:62:fe (oui Unknown), ethertype IPv4 (0x0800), length 62: h86-62-108-132.ln.rinet.ru.1141 > daemon1.darkdragon.lan.81: S 1557011461:1557011461(0) win 65535 <mss 1460,nop,nop,sackOK>
15:01:24.786807 00:60:97:93:62:fe (oui Unknown) > 00:1b:11:84:e3:90 (oui Unknown), ethertype IPv4 (0x0800), length 62: daemon1.darkdragon.lan.81 > h86-62-108-132.ln.rinet.ru.1141: S 731859860:731859860(0) ack 1557011462 win 5840 <mss 1460,nop,nop,sackOK>
15:01:24.790013 00:1b:11:84:e3:90 (oui Unknown) > 00:60:97:93:62:fe (oui Unknown), ethertype IPv4 (0x0800), length 60: h86-62-108-132.ln.rinet.ru.1141 > daemon1.darkdragon.lan.81: R 1557011462:1557011462(0) win 0
9 packets captured
9 packets received by filter
0 packets dropped by kernel
# ip rule list
0: from all lookup local
32765: from all fwmark 0x2 lookup adsl.mtu
32766: from all lookup main
32767: from all lookup default
# ip route list table adsl.mtu
default via 192.168.1.2 dev eth0
# iptables-save -t mangle
*mangle
:PREROUTING ACCEPT [2387:338395]
:INPUT ACCEPT [2046:209696]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [2042:939437]
:POSTROUTING ACCEPT [2048:940922]
-A PREROUTING -m conntrack --ctstate NEW,RELATED -m mac --mac-source 00:D0:D0:61:30:2C -j CONNMARK --set-mark 0x2
-A PREROUTING -j CONNMARK --restore-mark
COMMIT