Advertisement
Guest User

11

a guest
Dec 15th, 2019
176
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.44 KB | None | 0 0
  1. Flags: X - disabled, I - invalid, D - dynamic
  2. 0 X ;;; DROP DNS request (see Mangle)
  3. chain=input action=drop packet-mark=DNS_block log=no log-prefix=""
  4.  
  5. 1 X ;;; INPUT DROP all country EXPECT RU & services
  6. chain=input action=drop src-address-list=!RU in-interface-list=WAN log=no log-prefix=""
  7.  
  8. 2 ;;; INPUT drop INVALID packet state
  9. chain=input action=drop connection-state=invalid log=no log-prefix="DROP_INVALID_INPUT"
  10.  
  11. 3 chain=input action=drop in-interface-list=VLAN log=no log-prefix=""
  12.  
  13. 4 ;;; INPUT other DROP
  14. chain=input action=drop in-interface-list=!LAN+PERSONAL log=no log-prefix="OTHER_INPUT_DROP"
  15.  
  16. 5 X ;;; DROP DNS request (see Mangle)
  17. chain=forward action=drop packet-mark=DNS_block log=no log-prefix=""
  18.  
  19. 6 X ;;; FORWARD drop hack soft
  20. chain=forward action=drop dst-address-list=SOFT log=yes log-prefix="TO HACK SOFT"
  21.  
  22. 7 X ;;; FORWARD drop to PSD-scan list via WAN&VPN
  23. chain=forward action=drop dst-address-list=PSD-scan in-interface-list=LAN+PERSONAL log=yes log-prefix="TO PSD-scan"
  24.  
  25. 8 X ;;; FORWARD drop to sbl spamhaus list via WAN&VPN
  26. chain=forward action=drop dst-address-list=sbl spamhaus in-interface-list=LAN+PERSONAL log=no log-prefix="TO sbl spamhaus"
  27.  
  28. 9 X ;;; FORWARD drop to sbl dshield list via WAN&VPN
  29. chain=forward action=drop dst-address-list=sbl dshield in-interface-list=LAN+PERSONAL log=no log-prefix="TO sbl dshield"
  30.  
  31. 10 X ;;; FORWARD drop to sbl blocklist.de list via WAN&VPN
  32. chain=forward action=drop dst-address-list=sbl blocklist.de in-interface-list=LAN+PERSONAL log=no log-prefix="TO sbl blocklist.de"
  33.  
  34. 11 ;;; FORWARD drop INVALID packet state
  35. chain=forward action=drop connection-state=invalid log=no log-prefix="DROP_INVALID_FORWARD"
  36.  
  37. 12 ;;; FORWARD DROP to WAN
  38. chain=forward action=drop src-address-list=notWAN dst-address-list=!notWAN_EXCLUDE out-interface-list=WAN log=no log-prefix=""
  39.  
  40. 13 ;;; FORWARD DROP from 191
  41. chain=forward action=drop src-address=172.22.22.191 log=no log-prefix=""
  42.  
  43. 14 ;;; FORWARD DROP from 192
  44. chain=forward action=drop src-address=172.22.22.192 log=no log-prefix=""
  45.  
  46. 15 ;;; FORWARD DROP from 197
  47. chain=forward action=drop src-address=172.22.22.197 log=no log-prefix=""
  48.  
  49. 16 X ;;; FORWARD DROP from 2
  50. chain=forward action=drop src-address=172.22.22.2 log=no log-prefix=""
  51.  
  52. 17 ;;; FORWARD DROP from 3
  53. chain=forward action=drop src-address=172.22.22.3 log=no log-prefix=""
  54.  
  55. 18 ;;; FORWARD drop from Chains & VPS
  56. chain=forward action=drop in-interface-list=Chain+VPS+VPS-TOR log=no log-prefix="VPS-forward"
  57.  
  58. 19 ;;; FORWARD drop from work VPN
  59. chain=forward action=drop src-address-list=!KNOCK_ACCEPT in-interface-list=VPN_work log=yes log-prefix="WORK_DROP"
  60.  
  61. 20 X ;;; FORWARD from mama
  62. chain=forward action=drop dst-address=!172.22.22.22 src-address-list=!KNOCK_ACCEPT in-interface=l2tp-in-mama log=yes log-prefix="mama DROP"
  63.  
  64. 21 chain=forward action=drop in-interface=vlan5_MON out-interface-list=!WAN+VPS log=no log-prefix=""
  65.  
  66. 22 chain=forward action=drop in-interface=vlan8_TESTING log=no log-prefix=""
  67.  
  68. 23 chain=forward action=drop in-interface=vlan9_WiFi-guest out-interface-list=!WAN+VPS log=no log-prefix=""
  69.  
  70. 24 ;;; FORWARD drop all from WAN not DST NATed
  71. chain=forward action=drop connection-nat-state=!dstnat in-interface-list=WAN log=yes log-prefix="WAN_FORWARD"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement