Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /*
- *
- *
- * @Author: Glaubert Suyan Dacio
- * @Data: 14/10/2018 -
- * @Description:
- * Sistema de segurança que bloqueia o ip do usuario caso ele erre a senha mais de 3x a senha da VPN
- *
- *
- */
- /ip firewall filter
- add action=drop chain=input dst-port=1723,1701 protocol=tcp src-address-list=\
- BLACKLIST
- add action=add-src-to-address-list address-list=LVL01_BRUTEFORCE \
- address-list-timeout=2m10s chain=input packet-mark=ANTIBRUTE01 \
- src-address-list=!LVL01_BRUTEFORCE
- add action=add-src-to-address-list address-list=LVL02_BRUTEFORCE \
- address-list-timeout=2m10s chain=input packet-mark=ANTIBRUTE02 \
- src-address-list=!LVL02_BRUTEFORCE
- add action=add-src-to-address-list address-list=LVL03_BRUTEFORCE \
- address-list-timeout=2m10s chain=input packet-mark=ANTIBRUTE03 \
- src-address-list=!LVL03_BRUTEFORCE
- add action=add-src-to-address-list address-list=BLACKLIST address-list-timeout=\
- none-dynamic chain=input packet-mark=BLACK-LIST
- /ip firewall mangle
- add action=jump chain=input connection-state=new dst-port=1723,1701 \
- jump-target=ANTI-BRUTEFORCE protocol=tcp
- add action=jump chain=input connection-state=new dst-port=1723,1701 \
- jump-target=ANTI-BRUTEFORCE protocol=udp
- add action=mark-packet chain=ANTI-BRUTEFORCE new-packet-mark=ANTIBRUTE01 \
- packet-mark=no-mark passthrough=yes src-address-list=!LVL01_BRUTEFORCE
- add action=mark-packet chain=ANTI-BRUTEFORCE new-packet-mark=ANTIBRUTE02 \
- packet-mark=no-mark passthrough=yes src-address-list=!LVL02_BRUTEFORCE
- add action=mark-packet chain=ANTI-BRUTEFORCE new-packet-mark=ANTIBRUTE03 \
- packet-mark=no-mark passthrough=yes src-address-list=!LVL03_BRUTEFORCE
- add action=mark-packet chain=ANTI-BRUTEFORCE new-packet-mark=BLACK-LIST \
- packet-mark=no-mark passthrough=yes src-address-list=LVL03_BRUTEFORCE
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement