Guest User

Untitled

a guest
Jul 28th, 2021
26
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.72 KB | None | 0 0
  1. /ip firewall filter
  2. add action=accept chain=input comment=\
  3. "defconf: accept established,related,untracked" connection-state=\
  4. established,related,untracked
  5. add action=drop chain=input dst-port=53,123 in-interface=eth1-wan protocol=udp
  6. add action=drop chain=input dst-port=53,123 in-interface=eth1-wan protocol=tcp
  7. add action=drop chain=input connection-state=new dst-port=123 in-interface=\
  8. eth1-wan log-prefix=" " protocol=udp
  9. add action=drop chain=input connection-state=new dst-port=123 in-interface=\
  10. eth1-wan log-prefix=" " protocol=tcp
  11. add action=drop chain=input comment="defconf: drop invalid" connection-state=\
  12. invalid
  13. add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
  14. add action=accept chain=input comment=\
  15. "defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
  16. add action=drop chain=input comment="defconf: drop all not coming from LAN" \
  17. in-interface-list=!LAN
  18. add action=accept chain=forward comment="defconf: accept in ipsec policy" \
  19. ipsec-policy=in,ipsec
  20. add action=accept chain=forward comment="defconf: accept out ipsec policy" \
  21. ipsec-policy=out,ipsec
  22. add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
  23. connection-state=established,related
  24. add action=accept chain=forward comment=\
  25. "defconf: accept established,related, untracked" connection-state=\
  26. established,related,untracked
  27. add action=drop chain=forward comment="defconf: drop invalid" connection-state=\
  28. invalid
  29. add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" \
  30. connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
  31. /ip firewall nat
  32. add action=redirect chain=dstnat dst-port=53 in-interface-list=LAN protocol=udp
  33. add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=\
  34. out,none out-interface-list=WAN
  35. /ip firewall raw
  36. add action=jump chain=prerouting dst-port=53 in-interface-list=WAN jump-target=\
  37. DNS-Flood-TCP-RAW protocol=tcp
  38. add action=jump chain=prerouting dst-port=53 in-interface-list=WAN jump-target=\
  39. DNS-Flood-UDP-RAW protocol=udp
  40. add action=add-src-to-address-list address-list=Attack-from-WAN \
  41. address-list-timeout=1d chain=DNS-Flood-TCP-RAW
  42. add action=add-src-to-address-list address-list=Attack-from-WAN \
  43. address-list-timeout=1d chain=DNS-Flood-UDP-RAW
  44. add action=drop chain=DNS-Flood-TCP-RAW
  45. add action=drop chain=DNS-Flood-UDP-RAW
  46. add action=drop chain=prerouting comment="sbl dshield" src-address-list=\
  47. "sbl dshield"
  48. add action=drop chain=prerouting comment="sbl spamhaus" src-address-list=\
  49. "sbl spamhaus"
  50. add action=drop chain=prerouting comment="sbl blocklist.de" src-address-list=\
  51. "sbl blocklist.de"
  52.  
Advertisement
Add Comment
Please, Sign In to add comment