Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 0 ;;; accept established,related,untracked
- chain=input action=accept connection-state=established,related,untracked
- 1 X ;;; accept WinBox
- chain=input action=accept protocol=tcp dst-port=8291 log=no log-prefix=""
- 2 ;;; accept SSTP
- chain=input action=accept protocol=tcp dst-port=443 log=no log-prefix=""
- 3 ;;; accept GRE
- chain=input action=accept protocol=gre log=no log-prefix=""
- 4 ;;; drop invalid
- chain=input action=drop connection-state=invalid
- 5 ;;; accept ICMP
- chain=input action=accept protocol=icmp
- 6 ;;; accept to local loopback (for CAPsMAN)
- chain=input action=accept dst-address=127.0.0.1
- 7 ;;; drop all not coming from LAN
- chain=input action=drop in-interface-list=!LAN
- 8 ;;; accept in ipsec policy
- chain=forward action=accept ipsec-policy=in,ipsec
- 9 ;;; accept out ipsec policy
- chain=forward action=accept ipsec-policy=out,ipsec
- 10 X ;;; fasttrack
- chain=forward action=fasttrack-connection connection-state=established,related log=no log-prefix=""
- 11 ;;; accept established,related, untracked
- chain=forward action=accept connection-state=established,related,untracked
- 12 ;;; drop invalid
- chain=forward action=drop connection-state=invalid
- 13 ;;; drop all from WAN not DSTNATed
- chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-interf
Advertisement
Add Comment
Please, Sign In to add comment