Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /ip firewall mangle
- add action=jump chain=prerouting comment="Common P2P-Blocking" disabled=no \
- dst-address-list=!dns-externt jump-target=p2p-service p2p=all-p2p
- add action=jump chain=prerouting disabled=no dst-address-list=!dns-externt \
- jump-target=p2p-service layer7-protocol=BITTORRENT
- add action=jump chain=prerouting disabled=no dst-address-list=!dns-externt \
- jump-target=p2p-service layer7-protocol=DIRECTCONNECT
- add action=jump chain=prerouting disabled=no dst-address-list=!dns-externt \
- jump-target=p2p-service layer7-protocol=GNUTELLA
- add action=add-dst-to-address-list address-list=p2p-users-ext \
- address-list-timeout=10m chain=prerouting comment=\
- "UDP-Bittorrent blocking" disabled=no dst-address-list=!dns-externt \
- dst-port=1024-65535 packet-size=62-500 protocol=udp src-address-list=\
- p2p-users src-port=!53
- add action=add-src-to-address-list address-list=p2p-users-ext \
- address-list-timeout=10m chain=prerouting disabled=no dst-address-list=\
- p2p-users dst-port=1024-65535 packet-size=62-500 protocol=udp \
- src-address-list=!dns-externt src-port=!53
- add action=add-dst-to-address-list address-list=p2p-users-ext \
- address-list-timeout=10m chain=prerouting comment="TCP-Tracker blocking" \
- connection-type=!ftp disabled=no dst-address-list=!dns-externt dst-port=\
- 1024-65535 packet-size=100-500 protocol=tcp src-address-list=p2p-users \
- src-port=1024-65535 tcp-flags=psh,ack
- add action=add-src-to-address-list address-list=p2p-users-ext \
- address-list-timeout=10m chain=prerouting connection-type=!ftp disabled=\
- no dst-address-list=p2p-users dst-port=1024-65535 packet-size=100-500 \
- protocol=tcp src-address-list=!dns-externt src-port=1024-65535 tcp-flags=\
- psh,ack
- add action=jump chain=prerouting connection-state=new disabled=no dst-port=\
- 443 jump-target=tcp-services protocol=tcp
- add action=jump chain=prerouting connection-state=new disabled=no \
- dst-address-list=!dns-externt dst-port=!443 jump-target=p2p-service \
- layer7-protocol=HTTPS protocol=tcp
- add action=jump chain=prerouting connection-state=new disabled=no \
- jump-target=tcp-services protocol=tcp
- add action=jump chain=prerouting connection-state=new disabled=no \
- jump-target=udp-services protocol=udp
- add action=jump chain=prerouting connection-state=new disabled=no \
- jump-target=other-services
- add action=add-src-to-address-list address-list=p2p-users \
- address-list-timeout=2m chain=p2p-service disabled=no src-address-list=\
- local-addr
- add action=mark-connection chain=p2p-service disabled=no new-connection-mark=\
- p2p passthrough=no
- add action=mark-connection chain=tcp-services disabled=no dst-port=20-21 \
- new-connection-mark=ftp passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=22 \
- new-connection-mark=ssh passthrough=no protocol=tcp src-port=513-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=23 \
- new-connection-mark=telnet passthrough=no protocol=tcp src-port=\
- 1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=25 \
- new-connection-mark=smtp passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=53 \
- new-connection-mark=dns passthrough=no protocol=tcp src-port=53
- add action=mark-connection chain=tcp-services disabled=no dst-port=53 \
- new-connection-mark=dns passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=80 \
- new-connection-mark=http passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=110 \
- new-connection-mark=pop3 passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=113 \
- new-connection-mark=auth passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=119 \
- new-connection-mark=nntp passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=137-139 \
- new-connection-mark=netbios passthrough=no protocol=tcp src-port=\
- 1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=143 \
- new-connection-mark=imap passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=161-162 \
- new-connection-mark=snmp passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-address-list=\
- spotify dst-port=443 new-connection-mark=spotify passthrough=no protocol=\
- tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-address-list=\
- !spotify dst-port=443 new-connection-mark=https passthrough=no protocol=\
- tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=445 \
- new-connection-mark=ms-ds passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=465 \
- new-connection-mark=smtps passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=990 \
- new-connection-mark=ftps passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=993 \
- new-connection-mark=imaps passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=995 \
- new-connection-mark=pop3s passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=1080 \
- new-connection-mark=socks passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=1723 \
- new-connection-mark=pptp passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=1863 \
- new-connection-mark=msn passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=2379 \
- new-connection-mark=kgs passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=3128 \
- new-connection-mark=squid-proxy passthrough=no protocol=tcp src-port=\
- 1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=3389 \
- new-connection-mark=win-ts passthrough=no protocol=tcp src-port=\
- 1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=3845 \
- new-connection-mark=smartpass passthrough=no protocol=tcp src-port=\
- 1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=4070 \
- new-connection-mark=spotify passthrough=no protocol=tcp src-port=\
- 1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=2000-3000 \
- new-connection-mark=bwtest passthrough=no protocol=tcp src-port=\
- 1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=4242-4243 \
- new-connection-mark=emule passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=1024-65535 \
- new-connection-mark=overnet passthrough=no protocol=tcp src-port=\
- 4661-4662
- add action=mark-connection chain=tcp-services disabled=no dst-port=1024-65535 \
- new-connection-mark=emule passthrough=no protocol=tcp src-port=4711
- add action=mark-connection chain=tcp-services disabled=no dst-port=5900-5901 \
- new-connection-mark=vnc passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=6667-6669 \
- new-connection-mark=irc passthrough=no protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=8080 \
- new-connection-mark=http-proxy passthrough=no protocol=tcp src-port=\
- 1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-address-list=\
- local-addr dst-port=8291 new-connection-mark=winbox passthrough=no \
- protocol=tcp src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=\
- 42041-42052 new-connection-mark=voddler passthrough=no protocol=tcp \
- src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no dst-port=\
- 55536-55663 new-connection-mark=ftp-passive passthrough=no protocol=tcp \
- src-port=1024-65535
- add action=mark-connection chain=tcp-services disabled=no \
- new-connection-mark=other-tcp passthrough=no protocol=tcp
- add action=mark-connection chain=udp-services disabled=no dst-port=53 \
- new-connection-mark=dns passthrough=no protocol=udp src-port=1024-65535
- add action=mark-connection chain=udp-services disabled=no dst-port=67 \
- new-connection-mark=dhcp passthrough=no protocol=udp src-port=67-68
- add action=mark-connection chain=udp-services disabled=no dst-port=123 \
- new-connection-mark=ntp passthrough=no protocol=udp src-port=123
- add action=mark-connection chain=udp-services disabled=no dst-port=123 \
- new-connection-mark=ntp passthrough=no protocol=udp src-port=1024-65535
- add action=mark-connection chain=udp-services disabled=no dst-port=137-139 \
- new-connection-mark=netbios passthrough=no protocol=udp src-port=\
- 1024-65535
- add action=mark-connection chain=udp-services disabled=no dst-port=161-162 \
- new-connection-mark=snmp passthrough=no protocol=udp src-port=1024-65535
- add action=mark-connection chain=udp-services disabled=no dst-port=514 \
- new-connection-mark=syslog passthrough=no protocol=udp src-port=\
- 1024-65535
- add action=mark-connection chain=udp-services disabled=no dst-port=1701 \
- new-connection-mark=l2tp passthrough=no protocol=udp src-port=1024-65535
- add action=mark-connection chain=udp-services disabled=no dst-port=3544 \
- new-connection-mark=ms-ipv6 passthrough=no protocol=udp src-port=\
- 1024-65535
- add action=mark-connection chain=udp-services disabled=no dst-port=4665 \
- new-connection-mark=emule passthrough=no protocol=udp src-port=1024-65535
- add action=mark-connection chain=udp-services disabled=no dst-port=4672 \
- new-connection-mark=emule passthrough=no protocol=udp src-port=1024-65535
- add action=mark-connection chain=udp-services disabled=no dst-port=2000-3000 \
- new-connection-mark=bwtest passthrough=no protocol=udp src-port=\
- 1024-65535
- add action=mark-connection chain=udp-services disabled=no dst-port=1024-65535 \
- new-connection-mark=emule passthrough=no protocol=udp src-port=4672
- add action=mark-connection chain=udp-services disabled=no dst-port=12053 \
- new-connection-mark=overnet passthrough=no protocol=udp src-port=\
- 1024-65535
- add action=mark-connection chain=udp-services disabled=no dst-port=20561 \
- new-connection-mark=mac-winbox passthrough=no protocol=udp src-port=\
- 1024-65535
- add action=mark-connection chain=udp-services disabled=no dst-port=\
- 42041-42052 new-connection-mark=voddler passthrough=no protocol=udp \
- src-port=1024-65535
- add action=mark-connection chain=udp-services disabled=no dst-port=1024-65535 \
- new-connection-mark=overnet passthrough=no protocol=udp src-port=12053
- add action=mark-connection chain=udp-services disabled=no dst-port=1024-65535 \
- new-connection-mark=skype passthrough=no protocol=udp src-port=36725
- add action=mark-connection chain=forward disabled=no layer7-protocol=\
- skypetoskype new-connection-mark=skype passthrough=no
- add action=mark-connection chain=udp-services disabled=no \
- new-connection-mark=other-udp passthrough=no protocol=udp
- add action=mark-connection chain=other-services disabled=no icmp-options=\
- 8:0-255 new-connection-mark=ping passthrough=no protocol=icmp
- add action=mark-connection chain=other-services disabled=no \
- new-connection-mark=gre passthrough=no protocol=gre
- add action=mark-connection chain=other-services disabled=no \
- new-connection-mark=igmp passthrough=no protocol=igmp
- add action=mark-connection chain=other-services disabled=no \
- new-connection-mark=other passthrough=no
RAW Paste Data