#/bin/sh
file="/usr/local/script/student_ip.txt"
iptables -t filter -N STUDENT

reg="[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}"

mac="88:88:88:88:87:88"
#mac="D0:17:C2:88:6D:31"
iptables -I STUDENT -m mac --mac-source ${mac} -p tcp --dport 80  -j DROP
iptables -I STUDENT -m mac --mac-source ${mac} -p tcp --dport 443 -j DROP

for k in $(cat $file)
do
        if [[ "$k" =~ $reg ]]
        then

                iptables -I STUDENT -d ${k} -j ACCEPT
        fi
done

iptables -I FORWARD -j STUDENT
~
