Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 4.Защищаем WAN порт от DoS атаки. Будем добавлять в черный список на сутки тех, кто пытается открыть больше 15 соединений в секунду.
- /ip firewall filter
- add action=jump chain=forward connection-state=new in-interface-list=WAN jump-target=Def-DoS
- add action=jump chain=input connection-state=new in-interface-list=WAN jump-target=Def-DoS
- add action=drop chain=forward connection-state=new src-address-list=BAN-Def-DoS
- add action=return chain=anti-DoS dst-limit=15,15,src-address/10s
- add action=add-src-to-address-list address-list=BAN-Def-DoS address-list-timeout=1d chain=Def-DoS
- add action=jump chain=input connection-state=new dst-port=22,8291 in-interface-list=WAN jump-target=anti-BruteForce protocol=tcp
- add action=drop chain=forward connection-state=new src-address-list=BAN-BruteForce
- add action=return chain=anti-BruteForce dst-limit=4/1m,1,src-address/1m40s
- add action=add-src-to-address-list address-list=BAN-BruteForce address-list-timeout=1d chain=anti-BruteForce
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement