Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /ip firewall address-list
- add address=192.168.11.0/24 comment="DMZ Hosts" disabled=no list=dmz
- add address=10.20.31.0/24 comment="Mining Stuff" disabled=no list=myne
- add address=172.16.253.0/24 comment="Home Network" disabled=no list=home
- /ip firewall filter
- add action=jump chain=input comment="Jump for icmp input flow" disabled=no jump-target=ICMP protocol=icmp
- add action=jump chain=forward comment="Jump for icmp forward flow" disabled=no jump-target=ICMP protocol=icmp
- add action=drop chain=forward comment="Drop to bogon list" disabled=no dst-address-list=bogons
- add action=drop chain=input dst-port=53 in-interface=ether1-WAN protocol=udp
- add action=accept chain=input comment="Accept DNS - UDP" disabled=no port=53 protocol=udp
- add action=accept chain=input comment="Accept DNS - TCP" disabled=no port=53 protocol=tcp
- add action=accept chain=input comment="Accept to established connections" connection-state=established\
- disabled=no
- add action=accept chain=forward comment="Accept to established connections" connection-state=established\
- disabled=no
- add action=accept chain=forward comment="Accept jabber connections" protocol=tcp dst-port=5222
- add action=accept chain=forward comment="Accept plex connections" protocol=tcp dst-port=32443
- add action=accept chain=input comment="Accept to related connections" connection-state=related disabled=no
- add action=accept chain=forward comment="Allow all LAN outbound" disabled=no src-address-list=home dst-address=0.0.0.0/0
- add action=accept chain=input comment="Allow all LAN to Firewall" disabled=no src-address-list=home dst-address=172.16.253.99/32
- add action=drop chain=input comment="Drop anything else! # DO NOT ENABLE THIS RULE BEFORE YOU MAKE SURE ABOUT ALL ACCEPT RULES YOU NEED"\
- disabled=yes
- add action=drop chain=forward comment="Block DMZ to Home Subnet" disabled=no src-address-list=dmz dst-address-list=home
- add action=drop chain=ICMP comment="Block DMZ to Home Subnet" disabled=no src-address-list=dmz dst-address-list=home
- add action=drop chain=forward comment="Block DMZ to Miner Subnet" disabled=no src-address-list=dmz dst-address-list=myne
- add action=drop chain=ICMP comment="Block DMZ to Miner Subnet" disabled=no src-address-list=dmz dst-address-list=myne
- add action=drop chain=forward comment="Block Miner to Home Subnet" disabled=no src-address-list=myne dst-address-list=home
- add action=drop chain=ICMP comment="Block Miner to Home Subnet" disabled=no src-address-list=myne dst-address-list=home
- add action=drop chain=forward comment="Block Miner to DMZ Subnet" disabled=no src-address-list=myne dst-address-list=dmz
- add action=drop chain=ICMP comment="Block Miner to DMZ Subnet" disabled=no src-address-list=myne dst-address-list=dmz
- add action=accept chain=ICMP comment="Echo request - Avoiding Ping Flood" disabled=no icmp-options=8:0 limit=1,5 protocol=icmp
- add action=accept chain=ICMP comment="Echo reply" disabled=no icmp-options=0:0 protocol=icmp
- add action=accept chain=ICMP comment="Time Exceeded" disabled=no icmp-options=11:0 protocol=icmp
- add action=accept chain=ICMP comment="Destination unreachable" disabled=no icmp-options=3:0-1 protocol=icmp
- add action=accept chain=ICMP comment=PMTUD disabled=no icmp-options=3:4 protocol=icmp
- add action=drop chain=ICMP comment="Drop to the other ICMPs" disabled=no protocol=icmp
- add action=jump chain=output comment="Jump for icmp output" disabled=no jump-target=ICMP protocol=icmp
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement