да.. роутер пора выбросить. но на новый нет лишнего рубля(
В общем дело такое, имеем роутер DIR-100 к нему подключены телевизор на android и комп, также интернет веревка по динамическому IP с нужным mac.
в компе торчит usb свисток Dlink DWA125. представляет точку доступа для ноута и мобильников (hostapd dnsmasq)
через вафлю сервер minidlna виден прекрасно, также доступны общие папки через smb://
через роутер, телеку недоступно вышеуказанное счастье. пингуется. куда копать?
$ sudo iptables-save
# Generated by iptables-save v1.4.21 on Wed Dec 3 00:08:01 2014
*nat
:PREROUTING ACCEPT [635:145929]
:INPUT ACCEPT [131:9312]
:OUTPUT ACCEPT [3666:281274]
:POSTROUTING ACCEPT [491:33769]
-A POSTROUTING -o eth0 -j MASQUERADE
COMMIT
# Completed on Wed Dec 3 00:08:01 2014
# Generated by iptables-save v1.4.21 on Wed Dec 3 00:08:01 2014
*mangle
:PREROUTING ACCEPT [38815:27835428]
:INPUT ACCEPT [12066:5192266]
:FORWARD ACCEPT [26672:22631278]
:OUTPUT ACCEPT [16100:2839374]
:POSTROUTING ACCEPT [42994:25490414]
COMMIT
# Completed on Wed Dec 3 00:08:01 2014
# Generated by iptables-save v1.4.21 on Wed Dec 3 00:08:01 2014
*filter
:INPUT DROP [2:72]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]
:bad_packets - [0:0]
:icmp_p - [0:0]
:tcp_p - [0:0]
:udp_p - [0:0]
-A INPUT -p tcp -j bad_packets
-A INPUT -i br0 -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i eth0 -p tcp -j tcp_p
-A INPUT -i eth0 -p udp -j udp_p
-A INPUT -i eth0 -p icmp -j icmp_p
-A FORWARD -p tcp -j bad_packets
-A FORWARD -i br0 -j ACCEPT
-A FORWARD -i lo -j ACCEPT
-A FORWARD -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -p tcp -j bad_packets
-A OUTPUT -o eth0 -j ACCEPT
-A OUTPUT -o br0 -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A bad_packets -p tcp -m tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j REJECT --reject-with tcp-reset
-A bad_packets -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j LOG --log-prefix "New not syn:"
-A bad_packets -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
-A icmp_p -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A icmp_p -p icmp -m icmp --icmp-type 11 -j ACCEPT
-A icmp_p -p icmp -j DROP
-A tcp_p -p tcp -j DROP
-A udp_p -p udp -j DROP
COMMIT
# Completed on Wed Dec 3 00:08:01 2014
pkts bytes target prot opt in out source destination
10041 7405K bad_packets tcp -- * * 0.0.0.0/0 0.0.0.0/0
671 72030 ACCEPT all -- br0 * 0.0.0.0/0 0.0.0.0/0
2105 253K ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
34262 9458K ACCEPT all -- eth0 * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
4 196 tcp_p tcp -- eth0 * 0.0.0.0/0 0.0.0.0/0
615 162K udp_p udp -- eth0 * 0.0.0.0/0 0.0.0.0/0
0 0 icmp_p icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
141K 126M bad_packets tcp -- * * 0.0.0.0/0 0.0.0.0/0
55524 3661K ACCEPT all -- br0 * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
85921 123M ACCEPT all -- eth0 * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
Chain OUTPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
14844 1544K bad_packets tcp -- * * 0.0.0.0/0 0.0.0.0/0
41042 23M ACCEPT all -- * eth0 0.0.0.0/0 0.0.0.0/0
709 128K ACCEPT all -- * br0 0.0.0.0/0 0.0.0.0/0
2251 276K ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
Chain bad_packets (3 references)
pkts bytes target prot opt in out source destination
0 0 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x12/0x12 state NEW reject-with tcp-reset
15 15133 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:!0x17/0x02 state NEW LOG flags 0 level 4 prefix "New not syn:"
15 15133 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:!0x17/0x02 state NEW
Chain icmp_p (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 8
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 11
0 0 DROP icmp -- * * 0.0.0.0/0 0.0.0.0/0
Chain tcp_p (1 references)
pkts bytes target prot opt in out source destination
4 196 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0
Chain udp_p (1 references)
pkts bytes target prot opt in out source destination
615 162K DROP udp -- * * 0.0.0.0/0 0.0.0.0/0
$ ifconfig
br0 Link encap:Ethernet HWaddr 84:c9:b2:7f:e2:83
inet addr:192.168.1.1 Bcast:192.168.1.255 Mask:255.255.255.0
inet6 addr: fe80::f054:99ff:fe36:62b0/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:66666 errors:0 dropped:0 overruns:0 frame:0
TX packets:102946 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:4374559 (4.3 MB) TX bytes:147745184 (147.7 MB)
eth0 Link encap:Ethernet HWaddr 00:25:22:bd:4b:f8
inet addr:192.168.0.100 Bcast:192.168.0.255 Mask:255.255.255.0
inet6 addr: fe80::225:22ff:febd:4bf8/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:138817 errors:0 dropped:0 overruns:0 frame:0
TX packets:109946 errors:0 dropped:0 overruns:0 carrier:1
collisions:0 txqueuelen:1000
RX bytes:157981588 (157.9 MB) TX bytes:28805452 (28.8 MB)
lo Link encap:Локальная петля (Loopback)
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:65536 Metric:1
RX packets:2493 errors:0 dropped:0 overruns:0 frame:0
TX packets:2493 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:300622 (300.6 KB) TX bytes:300622 (300.6 KB)
wlan0 Link encap:Ethernet HWaddr 84:c9:b2:7f:e2:83
inet6 addr: fe80::86c9:b2ff:fe7f:e283/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:66663 errors:0 dropped:0 overruns:0 frame:0
TX packets:103437 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:5307823 (5.3 MB) TX bytes:149674263 (149.6 MB)