accel-ppp-1
10.1.0.0/20accel-ppp-2
10.2.0.0/20ipset for accel = allowed
iptables
:FORWARD DROP
-A FORWARD -m set --match-set allowed src -m set --match-set allowed dst -j ACCEPT
-A FORWARD -m set --match-set allowed src ! -m set --match-set internal_networks dst -j ACCEPT
-A FORWARD -m set --match-set allowed dst ! -m set --match-set internal_networks src -j ACCEPT
ipset list
Name: internal_networks
Type: hash:net
Revision: 6
Header: family inet hashsize 1024 maxelem 65536
Size in memory: 600
References: 1
Number of entries: 4
Members:
172.19.0.0/24
172.19.3.0/24
192.168.1.0/24172.19.2.0/24
10.1.0.0/2010.2.0.0/20"ходят ли пакеты, если клиенты на одном сервере"
Да