Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /ip firewall export verbose
- # dec/13/2015 07:16:49 by RouterOS 6.33.3
- # software id = YJAX-K4H6
- #
- /ip firewall connection tracking
- set enabled=auto generic-timeout=10m icmp-timeout=10s tcp-close-timeout=10s tcp-close-wait-timeout=10s \
- tcp-established-timeout=1d tcp-fin-wait-timeout=10s tcp-last-ack-timeout=10s tcp-max-retrans-timeout=5m \
- tcp-syn-received-timeout=5s tcp-syn-sent-timeout=5s tcp-time-wait-timeout=10s tcp-unacked-timeout=5m \
- udp-stream-timeout=3m udp-timeout=10s
- /ip firewall filter
- add action=accept chain=input !connection-bytes !connection-limit !connection-mark !connection-nat-state \
- !connection-rate !connection-state !connection-type !content disabled=no !dscp !dst-address !dst-address-list \
- !dst-address-type !dst-limit dst-port=500 !fragment !hotspot !icmp-options !in-bridge-port !in-interface \
- !ingress-priority !ipsec-policy !ipv4-options !layer7-protocol !limit log=no log-prefix="" !nth !out-bridge-port \
- !out-interface !p2p !packet-mark !packet-size !per-connection-classifier !port !priority protocol=udp !psd !random \
- !routing-mark !routing-table src-address=HQ_IP !src-address-list !src-address-type !src-mac-address \
- !src-port !tcp-flags !tcp-mss !time !ttl
- add action=accept chain=input !connection-bytes !connection-limit !connection-mark !connection-nat-state \
- !connection-rate !connection-state !connection-type !content disabled=no !dscp !dst-address !dst-address-list \
- !dst-address-type !dst-limit !dst-port !fragment !hotspot !icmp-options !in-bridge-port !in-interface \
- !ingress-priority !ipsec-policy !ipv4-options !layer7-protocol !limit log=no log-prefix="" !nth !out-bridge-port \
- !out-interface !p2p !packet-mark !packet-size !per-connection-classifier !port !priority protocol=ipsec-esp !psd \
- !random !routing-mark !routing-table src-address=HQ_IP !src-address-list !src-address-type !src-mac-address \
- !src-port !tcp-flags !tcp-mss !time !ttl
- add action=accept chain=input comment="default configuration" !connection-bytes !connection-limit !connection-mark \
- !connection-nat-state !connection-rate !connection-state !connection-type !content disabled=no !dscp !dst-address \
- !dst-address-list !dst-address-type !dst-limit !dst-port !fragment !hotspot !icmp-options !in-bridge-port \
- !in-interface !ingress-priority !ipsec-policy !ipv4-options !layer7-protocol !limit log=no log-prefix="" !nth \
- !out-bridge-port !out-interface !p2p !packet-mark !packet-size !per-connection-classifier !port !priority protocol=\
- icmp !psd !random !routing-mark !routing-table !src-address !src-address-list !src-address-type !src-mac-address \
- !src-port !tcp-flags !tcp-mss !time !ttl
- add action=accept chain=input comment="default configuration" !connection-bytes !connection-limit !connection-mark \
- !connection-nat-state !connection-rate connection-state=established,related !connection-type !content disabled=no \
- !dscp !dst-address !dst-address-list !dst-address-type !dst-limit !dst-port !fragment !hotspot !icmp-options \
- !in-bridge-port !in-interface !ingress-priority !ipsec-policy !ipv4-options !layer7-protocol !limit log=no \
- log-prefix="" !nth !out-bridge-port !out-interface !p2p !packet-mark !packet-size !per-connection-classifier !port \
- !priority !protocol !psd !random !routing-mark !routing-table !src-address !src-address-list !src-address-type \
- !src-mac-address !src-port !tcp-flags !tcp-mss !time !ttl
- add action=accept chain=input !connection-bytes !connection-limit !connection-mark !connection-nat-state \
- !connection-rate !connection-state !connection-type !content disabled=no !dscp !dst-address !dst-address-list \
- !dst-address-type !dst-limit dst-port=80,8291,22 !fragment !hotspot !icmp-options !in-bridge-port !in-interface \
- !ingress-priority !ipsec-policy !ipv4-options !layer7-protocol !limit log=no log-prefix="" !nth !out-bridge-port \
- !out-interface !p2p !packet-mark !packet-size !per-connection-classifier !port !priority protocol=tcp !psd !random \
- !routing-mark !routing-table !src-address !src-address-list !src-address-type !src-mac-address !src-port !tcp-flags \
- !tcp-mss !time !ttl
- add action=accept chain=input !connection-bytes !connection-limit !connection-mark !connection-nat-state \
- !connection-rate !connection-state !connection-type !content disabled=no !dscp !dst-address !dst-address-list \
- !dst-address-type !dst-limit !dst-port !fragment !hotspot !icmp-options !in-bridge-port !in-interface \
- !ingress-priority !ipsec-policy !ipv4-options !layer7-protocol !limit log=no log-prefix="" !nth !out-bridge-port \
- !out-interface !p2p !packet-mark !packet-size !per-connection-classifier !port !priority protocol=icmp !psd !random \
- !routing-mark !routing-table !src-address !src-address-list !src-address-type !src-mac-address !src-port !tcp-flags \
- !tcp-mss !time !ttl
- add action=drop chain=input comment="default configuration" !connection-bytes !connection-limit !connection-mark \
- !connection-nat-state !connection-rate !connection-state !connection-type !content disabled=no !dscp !dst-address \
- !dst-address-list !dst-address-type !dst-limit !dst-port !fragment !hotspot !icmp-options !in-bridge-port \
- in-interface=ether1-gateway !ingress-priority !ipsec-policy !ipv4-options !layer7-protocol !limit log=no log-prefix=\
- "" !nth !out-bridge-port !out-interface !p2p !packet-mark !packet-size !per-connection-classifier !port !priority \
- !protocol !psd !random !routing-mark !routing-table !src-address !src-address-list !src-address-type \
- !src-mac-address !src-port !tcp-flags !tcp-mss !time !ttl
- add action=fasttrack-connection chain=forward comment="default configuration" !connection-bytes !connection-limit \
- !connection-mark !connection-nat-state !connection-rate connection-state=established,related !connection-type \
- !content disabled=no !dscp !dst-address !dst-address-list !dst-address-type !dst-limit !dst-port !fragment !hotspot \
- !icmp-options !in-bridge-port !in-interface !ingress-priority !ipsec-policy !ipv4-options !layer7-protocol !limit \
- log=no log-prefix="" !nth !out-bridge-port !out-interface !p2p !packet-mark !packet-size !per-connection-classifier \
- !port !priority !protocol !psd !random !routing-mark !routing-table !src-address !src-address-list !src-address-type \
- !src-mac-address !src-port !tcp-flags !tcp-mss !time !ttl
- add action=accept chain=forward comment="default configuration" !connection-bytes !connection-limit !connection-mark \
- !connection-nat-state !connection-rate connection-state=established,related !connection-type !content disabled=no \
- !dscp !dst-address !dst-address-list !dst-address-type !dst-limit !dst-port !fragment !hotspot !icmp-options \
- !in-bridge-port !in-interface !ingress-priority !ipsec-policy !ipv4-options !layer7-protocol !limit log=no \
- log-prefix="" !nth !out-bridge-port !out-interface !p2p !packet-mark !packet-size !per-connection-classifier !port \
- !priority !protocol !psd !random !routing-mark !routing-table !src-address !src-address-list !src-address-type \
- !src-mac-address !src-port !tcp-flags !tcp-mss !time !ttl
- add action=drop chain=forward comment="default configuration" !connection-bytes !connection-limit !connection-mark \
- !connection-nat-state !connection-rate connection-state=invalid !connection-type !content disabled=no !dscp \
- !dst-address !dst-address-list !dst-address-type !dst-limit !dst-port !fragment !hotspot !icmp-options \
- !in-bridge-port !in-interface !ingress-priority !ipsec-policy !ipv4-options !layer7-protocol !limit log=no \
- log-prefix="" !nth !out-bridge-port !out-interface !p2p !packet-mark !packet-size !per-connection-classifier !port \
- !priority !protocol !psd !random !routing-mark !routing-table !src-address !src-address-list !src-address-type \
- !src-mac-address !src-port !tcp-flags !tcp-mss !time !ttl
- add action=drop chain=forward comment="default configuration" !connection-bytes !connection-limit !connection-mark \
- connection-nat-state=!dstnat !connection-rate connection-state=new !connection-type !content disabled=no !dscp \
- !dst-address !dst-address-list !dst-address-type !dst-limit !dst-port !fragment !hotspot !icmp-options \
- !in-bridge-port in-interface=ether1-gateway !ingress-priority !ipsec-policy !ipv4-options !layer7-protocol !limit \
- log=no log-prefix="" !nth !out-bridge-port !out-interface !p2p !packet-mark !packet-size !per-connection-classifier \
- !port !priority !protocol !psd !random !routing-mark !routing-table !src-address !src-address-list !src-address-type \
- !src-mac-address !src-port !tcp-flags !tcp-mss !time !ttl
- /ip firewall nat
- add action=accept chain=srcnat !connection-bytes !connection-limit !connection-mark !connection-rate !connection-type \
- !content disabled=no !dscp dst-address=10.101.0.0/24 !dst-address-list !dst-address-type !dst-limit !dst-port \
- !fragment !hotspot !icmp-options !in-bridge-port !in-interface !ingress-priority !ipsec-policy !ipv4-options \
- !layer7-protocol !limit log=no log-prefix="" !nth !out-bridge-port !out-interface !packet-mark !packet-size \
- !per-connection-classifier !port !priority !protocol !psd !random !routing-mark !routing-table src-address=\
- 10.104.0.0/24 !src-address-list !src-address-type !src-mac-address !src-port !tcp-mss !time !to-addresses !to-ports \
- !ttl
- add action=accept chain=dstnat !connection-bytes !connection-limit !connection-mark !connection-rate !connection-type \
- !content disabled=no !dscp dst-address=10.104.0.0/24 !dst-address-list !dst-address-type !dst-limit !dst-port \
- !fragment !hotspot !icmp-options !in-bridge-port !in-interface !ingress-priority !ipsec-policy !ipv4-options \
- !layer7-protocol !limit log=no log-prefix="" !nth !out-bridge-port !out-interface !packet-mark !packet-size \
- !per-connection-classifier !port !priority !protocol !psd !random !routing-mark !routing-table src-address=\
- 10.101.0.0/24 !src-address-list !src-address-type !src-mac-address !src-port !tcp-mss !time !to-addresses !to-ports \
- !ttl
- add action=masquerade chain=srcnat comment="default configuration" !connection-bytes !connection-limit !connection-mark \
- !connection-rate !connection-type !content disabled=no !dscp !dst-address !dst-address-list !dst-address-type \
- !dst-limit !dst-port !fragment !hotspot !icmp-options !in-bridge-port !in-interface !ingress-priority !ipsec-policy \
- !ipv4-options !layer7-protocol !limit log=no log-prefix="" !nth !out-bridge-port out-interface=ether1-gateway \
- !packet-mark !packet-size !per-connection-classifier !port !priority !protocol !psd !random !routing-mark \
- !routing-table !src-address !src-address-list !src-address-type !src-mac-address !src-port !tcp-mss !time \
- !to-addresses !to-ports !ttl
- /ip firewall service-port
- set ftp disabled=no ports=21
- set tftp disabled=no ports=69
- set irc disabled=no ports=6667
- set h323 disabled=no
- set sip disabled=no ports=5060,5061 sip-direct-media=yes sip-timeout=1h
- set pptp disabled=no
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement