cortar o acesso da wlan à lan e à wan

iptables -I FORWARD -i br1 -o br0 -m state --state NEW -j DROP
iptables -I FORWARD -i br0 -o br1 -m state --state NEW -j DROP
iptables -I FORWARD -i br1 -o `get_wanface` -j DROP

iptables -t nat -I POSTROUTING -o `get_wanface` -j SNAT --to `nvram get wan_ipaddr`

ip route add 192.168.70.0/24 dev br1 table 200
ip route add default via 10.0.11.5 dev tun1 table 200
ip rule add from 192.168.70.140 table 200
ip route flush cache

definitivas
rotas
ip route add default dev tun1 table 200
ip route add 192.168.70.0/24 dev br1 table 200
ip rule add from 192.168.70.0/24 table 200
ip route flush cache

firewall
iptables -I FORWARD -i br1 -o br0 -m state --state NEW -j DROP
iptables -I FORWARD -i br0 -o br1 -m state --state NEW -j DROP
iptables -I FORWARD -i br1 -o `get_wanface` -j DROP
iptables -t nat -I POSTROUTING -o tun1 -j MASQUERADE

http://www.dd-wrt.com/wiki/index.php/Separate_LAN_and_WLAN

http://www.dd-wrt.com/phpBB2/viewtopic.php?p=448143 - masquerade

http://www.dd-wrt.com/wiki/index.php/One-to-one_NAT

http://www.dd-wrt.com/wiki/index.php/Iptables_command

http://www.dd-wrt.com/wiki/index.php/Firewall

http://www.dd-wrt.com/phpBB2/viewtopic.php?t=78690 - quando se pretende encaminhar toda a rede para uma nova tabela de roteamento

http://www.dd-wrt.com/phpBB2/viewtopic.php?t=155043 - scripts de arranque (ver)

http://www.dd-wrt.com/wiki/index.php/Script_Execution

http://www.dd-wrt.com/wiki/index.php/Startup_Scripts

http://www.dd-wrt.com/wiki/index.php/OpenVPN

http://www.dd-wrt.com/wiki/index.php/Policy_Based_Routing

http://www.dd-wrt.com/wiki/index.php/Development

Tags