Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /ip firewall filter
- add action=drop chain=input comment=";;; Drop all INVALID" connection-state=invalid
- add action=drop chain=forward connection-state=invalid
- add action=accept chain=input comment=";;; Allow all ESTABLISHED" connection-state=established
- add action=accept chain=forward connection-state=established
- add action=accept chain=input comment=";;; Allow all RELATED" connection-state=related
- add action=accept chain=forward connection-state=related
- add action=accept chain=input comment=";;; Allow ICMP from all" protocol=icmp
- add action=accept chain=forward protocol=icmp
- add action=accept chain=input comment=";;; Enable IPsec" port=1701,500,4500 protocol=udp
- add action=accept chain=input protocol=ipsec-esp
- add action=accept chain=input comment="Allow DNS from LAN" dst-port=53 protocol=udp src-address=192.168.28.0/24
- add action=drop chain=input comment=";;; SSH anti-bruteforce" dst-port=22 protocol=tcp src-address-list=ssh_blacklist
- add action=add-src-to-address-list address-list=ssh_blacklist address-list-timeout=30m chain=input connection-state=new dst-port=22 protocol=tcp src-address-list=ssh_stage3
- add action=add-src-to-address-list address-list=ssh_stage3 address-list-timeout=1m chain=input connection-state=new dst-port=22 protocol=tcp src-address-list=ssh_stage2
- add action=add-src-to-address-list address-list=ssh_stage2 address-list-timeout=1m chain=input connection-state=new dst-port=22 protocol=tcp src-address-list=ssh_stage1
- add action=add-src-to-address-list address-list=ssh_stage1 address-list-timeout=1m chain=input connection-state=new dst-port=22 protocol=tcp
- add action=accept chain=input connection-state=new dst-port=22 protocol=tcp
- add action=accept chain=input comment=";;; Allow SSH from local network only" dst-port=22 protocol=tcp
- add action=accept chain=input comment=";;; Allow HTTP from local network" dst-port=80 protocol=tcp src-address=192.168.28.0/24
- add action=accept chain=input comment=";;; Allow HTTPS from all" dst-port=443 protocol=tcp
- add action=accept chain=input comment=";;; Allow WINBOX from Home" dst-port=8291 protocol=tcp src-address=192.168.28.0/24
- add action=accept chain=input comment=";;; Allow NTP from LAN" dst-port=123 protocol=udp src-address=192.168.28.0/24
- add action=accept chain=forward comment=";;; Allow Internet from LAN" src-address=192.168.28.0/24
- add action=accept chain=input dst-port=1900 protocol=udp src-address=192.168.28.0/24
- add action=accept chain=input dst-port=2828 protocol=tcp src-address=192.168.28.0/24
- add action=drop chain=input comment=";;; DROP ALL REQUEST"
- add action=drop chain=forward disabled=yes src-address=!192.168.28.0/24
- /ip firewall mangle
- add action=mark-routing chain=prerouting dst-address-list=VPN new-routing-mark=vpn
- /ip firewall nat
- add action=masquerade chain=srcnat out-interface=ether1
- dd action=dst-nat chain=dstnat comment="Web server" dst-port=80 in-interface=ether1 protocol=tcp to-addresses=192.168.28.10 to-ports=80
- add action=dst-nat chain=dstnat dst-port=443 in-interface=ether1 protocol=tcp to-addresses=192.168.28.10 to-ports=443
- add action=dst-nat chain=dstnat dst-port=8980 in-interface=ether1 protocol=tcp to-addresses=192.168.28.146 to-ports=8980
- add action=dst-nat chain=dstnat comment="Enable Jabber server port forwarding" dst-port=5222 in-interface=ether1 protocol=tcp to-addresses=192.168.28.10 to-ports=5222
- add action=dst-nat chain=dstnat dst-port=5269 in-interface=ether1 protocol=tcp to-addresses=192.168.28.10 to-ports=5269
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement