Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /ip firewall filter
- add action=accept chain=input connection-state=established,related
- add action=accept chain=forward connection-state=established,related
- add action=accept chain=input protocol=icmp
- add action=accept chain=forward protocol=icmp
- add action=accept chain=input dst-port=1723 in-interface-list=internetS protocol=tcp
- add action=drop chain=forward comment=Drop-Black-lists in-interface-list=internetS src-address-list=\
- drop
- add action=drop chain=forward in-interface-list=internetS log=yes log-prefix=drop-blacklist \
- src-address-list=Sip-Scan
- add action=drop chain=forward in-interface-list=internetS log=yes log-prefix=drop-blacklist \
- src-address-list=ALL-Drop
- add action=add-src-to-address-list address-list=drop address-list-timeout=none-static chain=input \
- dst-port=5061-5075 in-interface-list=internetS protocol=udp
- add action=add-src-to-address-list address-list=drop address-list-timeout=none-dynamic chain=input \
- dst-port=21-23,80,443 in-interface-list=internetS protocol=tcp
- add action=add-src-to-address-list address-list=drop address-list-timeout=none-static chain=input \
- dst-port=4569,5038 in-interface-list=internetS protocol=udp
- add action=drop chain=input comment=Invalid-drop connection-state=invalid
- add action=drop chain=forward connection-state=invalid
- add action=accept chain=forward in-interface-list=!internetS out-interface-list=internetS
- add action=drop chain=forward comment=Forrvard-Internet connection-nat-state=!srcnat,dstnat \
- in-interface-list=internetS
- add action=drop chain=input comment=Full-DROP in-interface-list=internetS
- add action=drop chain=forward in-interface-list=internetS
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement