Guest User

Untitled

a guest
Feb 19th, 2017
49
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.50 KB | None | 0 0
  1. ip firewall export
  2. # feb/19/2017 22:23:24 by RouterOS 6.38.1
  3. # software id = 4YN5-2WQK
  4. #
  5. /ip firewall filter
  6. add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
  7. add action=accept chain=input comment="defconf: accept established,related" connection-state=established,related
  8. add action=drop chain=input comment="defconf: drop all from WAN" in-interface=ether1
  9. add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
  10. add action=accept chain=forward comment="defconf: accept established,related" connection-state=established,related
  11. add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
  12. add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface=ether1
  13. /ip firewall nat
  14. add action=masquerade chain=srcnat comment="defconf: masquerade" out-interface=ether1
  15. add action=masquerade chain=srcnat comment="defconf: masquerade" out-interface=bridge
  16. add action=dst-nat chain=dstnat disabled=yes dst-port=9090 protocol=tcp to-addresses=1.1.1.1 to-ports=9090
  17. add action=dst-nat chain=dstnat comment="Endurance WEB" dst-address=тут_был_адрес dst-port=80 in-interface=ether1 protocol=tcp to-addresses=192.168.0.113 \
  18. to-ports=80
  19. add action=dst-nat chain=dstnat comment="Endurance WEB-SSL" dst-address=тут_был_адрес dst-port=443 in-interface=ether1 protocol=tcp to-addresses=\
  20. 192.168.0.113 to-ports=443
  21. add action=dst-nat chain=dstnat comment=Factorio dst-address=тут_был_адрес dst-port=34197 in-interface=ether1 protocol=udp to-addresses=192.168.0.113 \
  22. to-ports=34197
  23. add action=netmap chain=dstnat comment="University Debian" disabled=yes dst-address=тут_был_адрес dst-port=22101 in-interface=ether1 protocol=tcp \
  24. to-addresses=192.168.0.17 to-ports=22
  25. add action=dst-nat chain=dstnat dst-address=тут_был_адрес dst-port=80 protocol=tcp src-address=192.168.0.0/24 to-addresses=192.168.0.113
  26. add action=dst-nat chain=dstnat dst-address=тут_был_адрес dst-port=22101 protocol=tcp to-addresses=192.168.0.17 to-ports=22
  27. add action=dst-nat chain=dstnat dst-address=тут_был_адрес dst-port=443 protocol=tcp src-address=192.168.0.0/24 to-addresses=192.168.0.113
  28. add action=masquerade chain=srcnat dst-address=192.168.0.113 dst-port=80 protocol=tcp src-address=192.168.0.0/24 to-addresses=192.168.0.113
  29. add action=accept chain=srcnat src-address=192.168.1.0/24
Advertisement
Add Comment
Please, Sign In to add comment