Advertisement
pcdok48

Untitled

Sep 26th, 2018
147
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.62 KB | None | 0 0
  1. /ip firewall filter
  2. add action=accept chain=input comment="default configuration" in-interface=pppoe-domru in-interface-list=WAN protocol=icmp
  3. add action=accept chain=forward comment="allow DSTNATed from WAN" connection-nat-state=dstnat connection-state=new \
  4. in-interface-list=WAN
  5. add action=accept chain=input connection-state=established,related in-interface-list=WAN
  6. add action=accept chain=forward connection-state=established,related in-interface-list=WAN
  7. add action=accept chain=forward in-interface-list=WAN src-address-list=pcdok-sc
  8. add action=accept chain=input in-interface-list=WAN protocol=tcp
  9. add action=drop chain=forward comment=Sip-Scan-Drop in-interface-list=WAN log-prefix=Sip-Scan-Drop src-address-list=\
  10. Sip-Scan
  11. add action=drop chain=forward in-interface-list=WAN src-address-list=ALL-Drop
  12. add action=add-src-to-address-list address-list=Sip-Scan address-list-timeout=none-dynamic chain=input dst-port=5061 \
  13. in-interface-list=WAN protocol=udp
  14. add action=add-src-to-address-list address-list=Sip-client address-list-timeout=none-dynamic chain=input dst-port=5060 \
  15. in-interface-list=WAN protocol=udp
  16. add action=add-src-to-address-list address-list=ssh-drop address-list-timeout=none-dynamic chain=input comment=ssh-drop \
  17. dst-port=21-23,80,443 in-interface-list=WAN protocol=tcp
  18. add action=drop chain=forward connection-state=invalid in-interface-list=WAN
  19. add action=drop chain=input connection-state=invalid in-interface-list=WAN
  20. add action=drop chain=forward comment="default configuration" connection-state=invalid
  21. add action=drop chain=input comment="default configuration" in-interface-list=WAN
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement