Advertisement
Guest User

Untitled

a guest
Apr 23rd, 2018
78
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.50 KB | None | 0 0
  1. /ip firewall filter> print
  2. Flags: X - disabled, I - invalid, D - dynamic
  3. 0 D ;;; special dummy rule to show fasttrack counters
  4. chain=forward action=passthrough
  5.  
  6. 1 ;;; defconf: fasttrack
  7. chain=forward action=fasttrack-connection connection-state=established,related log=no log-prefix=""
  8.  
  9. 2 X ;;; defconf: drop invalid
  10. chain=forward action=drop connection-state=invalid log=no log-prefix=""
  11.  
  12. 3 X ;;; defconf: drop all from WAN not DSTNATed
  13. chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-interface=ether1 log=no
  14. log-prefix=""
  15.  
  16. 4 X chain=forward action=accept in-interface=all-ppp log=no log-prefix=""
  17.  
  18. 5 X ;;; WEBSERVER ????
  19. chain=forward action=accept protocol=tcp in-interface=pppoe-out1 dst-port=80 log=no log-prefix=""
  20.  
  21. 6 X chain=input action=accept protocol=icmp log=no log-prefix=""
  22.  
  23. 7 X chain=input action=accept connection-state=established log=no log-prefix=""
  24.  
  25. 8 X chain=input action=accept connection-state=related log=no log-prefix=""
  26.  
  27. 9 chain=input action=drop protocol=tcp in-interface=ether1 dst-port=53 log=no log-prefix=""
  28.  
  29. 10 chain=input action=drop protocol=udp in-interface=ether1 dst-port=53 log=no log-prefix=" "
  30.  
  31. 11 chain=input action=drop in-interface=ether1
  32.  
  33. 12 ;;; defconf: accept established,related
  34. chain=forward action=accept connection-state=established,related log=no log-prefix=""
  35.  
  36. 13 ;;; Drop Another INPUT
  37. chain=input action=drop
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement