Всем доброго времени!
Есть бридж с vlan:
auto br1
iface br1 inet static
address 172.XX.XX.XX
netmask 255.255.255.0
broadcast 172.XX.XX.XX
gateway XXX.XX.XX.X
bridge-ports eth0.7 eth1.7
dns-nameservers XXX.XX.XX.X
dns-search domain.local
bridge_stp off
Используются следующие правила:
ebtables -t broute -A BROUTING -p IPv4 --ip-protocol 6 \
--ip-destination-port 80 -j redirect --redirect-target ACCEPT
[br]
# Generated by iptables-save v1.4.12 on Sat Jan 25 21:54:01 2014
*mangle
:PREROUTING ACCEPT [69298:44844614]
:INPUT ACCEPT [1815:365801]
:FORWARD ACCEPT [68120:44553171]
:OUTPUT ACCEPT [1234:376955]
:POSTROUTING ACCEPT [69353:44930050]
COMMIT
# Completed on Sat Jan 25 21:54:01 2014
# Generated by iptables-save v1.4.12 on Sat Jan 25 21:54:01 2014
*filter
:INPUT ACCEPT [1815:365801]
:FORWARD ACCEPT [68120:44553171]
:OUTPUT ACCEPT [1235:377287]
COMMIT
# Completed on Sat Jan 25 21:54:01 2014
# Generated by iptables-save v1.4.12 on Sat Jan 25 21:54:01 2014
*nat
:PREROUTING ACCEPT [1662:185707]
:INPUT ACCEPT [26:1252]
:OUTPUT ACCEPT [72:4320]
:POSTROUTING ACCEPT [1728:187899]
-A PREROUTING -s 172.16.23.0/24 ! -d 172.16.20.0/16 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
COMMIT
# Completed on Sat Jan 25 21:54:01 2014
iptables -A FORWARD -p tcp -s 172.16.23.241 -d 77.222.42.167 -j ACCEPT
iptables -A FORWARD -p tcp -s 172.16.23.0/24 -d 77.222.42.167 -j DROP
подскажите, в чем может быть дело? на что обратить внимание?