Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [admin@RB3011UiAS] > ip firewall filter print
- Flags: X - disabled, I - invalid, D - dynamic
- 0 ;;; SSH to router
- chain=input action=accept protocol=tcp dst-port=52222 log=no log-prefix=""
- 1 ;;; OpenVPN
- chain=input action=accept protocol=tcp dst-port=51194 log=no log-prefix=""
- 2 ;;; Drop all invalid connections
- chain=input action=drop connection-state=invalid log=no log-prefix=""
- 3 ;;; Drop all other SSH & FTP connections
- chain=input action=drop protocol=tcp in-interface=ether1 dst-port=21,22 log=no log-prefix=""
- 4 ;;; Allow access to the router from the LAN using an address list
- chain=input action=accept src-address-list=LAN log=no log-prefix=""
- 5 ;;; Allow established connections to the router
- chain=input action=accept connection-state=established log=no log-prefix=""
- 6 ;;; Allow related connections to the router
- chain=input action=accept connection-state=related log=no log-prefix=""
- 7 ;;; Allow icmp requests
- chain=input action=accept protocol=icmp log=no log-prefix=""
- 8 ;;; Drop all other traffic to the router
- chain=input action=drop log=no log-prefix=""
- 9 ;;; Drop all invalid connections
- chain=forward action=drop connection-state=invalid log=no log-prefix=""
- 10 ;;; Block IPMI from WAN
- chain=forward action=drop out-interface=ether1 src-mac-address=BC:5F:F4:FE:7C:AA log=no log-prefix=""
- 11 ;;; Block Facebook on girls' laptop
- chain=forward action=drop protocol=tcp dst-port=80,443 src-mac-address=00:24:D7:7E:66:90 content=facebook log=no log-prefix=""
- 12 ;;; Block YouTube on girls' laptop TCP
- chain=forward action=drop protocol=tcp dst-port=80,443 src-mac-address=00:24:D7:7E:66:90 content=youtube log=no log-prefix=""
- 13 ;;; Block YouTube on girls' laptop UDP
- chain=forward action=drop protocol=udp dst-port=80,443 src-mac-address=00:24:D7:7E:66:90 content=youtube log=no log-prefix=""
- 14 ;;; Block Twitter on girls' laptop
- chain=forward action=drop protocol=tcp dst-port=80,443 src-mac-address=00:24:D7:7E:66:90 content=twitter log=no log-prefix=""
- 15 ;;; Allow established connections
- chain=forward action=accept connection-state=established log=no log-prefix=""
- 16 ;;; Allow related connections
- chain=forward action=accept connection-state=related log=no log-prefix=""
- 17 ;;; Allow new connections
- chain=forward action=accept connection-state=new log=no log-prefix=""
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement