Advertisement
Guest User

Untitled

a guest
Apr 8th, 2020
264
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 4.03 KB | None | 0 0
  1.  
  2.  0    ;;; Drop DNS
  3.       chain=input action=drop protocol=tcp in-interface=DomRu dst-port=53 log=no log-prefix=""
  4.  
  5.  1    chain=input action=drop protocol=udp in-interface=DomRu dst-port=53 log=no log-prefix=""
  6.  
  7.  2    ;;; DDos
  8.       chain=forward action=jump jump-target=Pre-DDoS connection-state=new in-interface=DomRu log=no log-prefix=""
  9.  
  10.  3    chain=input action=jump jump-target=Pre-DDoS connection-state=new in-interface=DomRu
  11.  
  12.  4    chain=forward action=drop connection-state=new src-address-list=ban-ddos
  13.  
  14.  5    chain=input action=drop connection-state=new src-address-list=ban-ddos
  15.  
  16.  6    chain=Pre-DDoS action=return dst-limit=32,32,src-address/10s
  17.  
  18.  7    chain=Pre-DDoS action=add-src-to-address-list address-list=ban-ddos address-list-timeout=2w1d
  19.  
  20.  8    ;;; Port scanners to list
  21.       chain=input action=add-src-to-address-list protocol=tcp psd=21,3s,3,1 address-list=port_scanners address-list-timeout=2w1d log=no log-prefix=""
  22.  
  23.  9    ;;; NMAP FIN Stealth scan
  24.       chain=input action=add-src-to-address-list tcp-flags=fin,!syn,!rst,!psh,!ack,!urg protocol=tcp address-list=port_scanners address-list-timeout=2w1d log=no log-prefix=""
  25.  
  26. 10    ;;; SYN/FIN scan
  27.       chain=input action=add-src-to-address-list tcp-flags=fin,syn protocol=tcp address-list=port_scanners address-list-timeout=2w1d log=no log-prefix=""
  28.  
  29. 11    ;;; SYN/RST scan
  30.       chain=input action=add-src-to-address-list tcp-flags=syn,rst protocol=tcp address-list=port_scanners address-list-timeout=2w1d log=no log-prefix=""
  31.  
  32. 12    ;;; FIN/PSH/URG scan
  33.       chain=input action=add-src-to-address-list tcp-flags=fin,psh,urg,!syn,!rst,!ack protocol=tcp address-list=port_scanners address-list-timeout=2w1d log=no log-prefix=""
  34.  
  35. 13    ;;; ALL/ALL scan
  36.       chain=input action=add-src-to-address-list tcp-flags=fin,syn,rst,psh,ack,urg protocol=tcp address-list=port_scanners address-list-timeout=2w1d log=no log-prefix=""
  37.  
  38. 14    ;;; NMAP NULL scan
  39.       chain=input action=add-src-to-address-list tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg protocol=tcp address-list=port_scanners address-list-timeout=2w1d log=no log-prefix=""
  40.  
  41. 15    ;;; Dropping port scanners
  42.       chain=input action=drop src-address-list=port_scanners log=no log-prefix=""
  43.  
  44. 16    ;;; IPsec l2tp
  45.       chain=input action=accept protocol=udp port=1701,500,4500 log=no log-prefix=""
  46.  
  47. 17    chain=input action=accept protocol=ipsec-esp
  48.  
  49. 18    ;;; Allow established related connections
  50.       chain=input action=accept connection-state=established,related log=no log-prefix=""
  51.  
  52. 19    ;;; Drop invalid connections
  53.       chain=input action=drop connection-state=invalid log=no log-prefix=""
  54.  
  55. 20    ;;; Allow address to lan
  56.       chain=input action=accept src-address-list=allow-ip in-interface=!DomRu log=no log-prefix=""
  57.  
  58. 21    ;;; Accept ICMP
  59.       chain=input action=accept protocol=icmp in-interface=DomRu log=no log-prefix=""
  60.  
  61. 22    ;;; Accept Winbox
  62.       chain=input action=accept protocol=tcp src-address-list=allow-ip in-interface=!DomRu dst-port=8291 log=no log-prefix=""
  63.  
  64. 23    ;;; Accept everything to internet
  65.       chain=output action=accept out-interface=DomRu log=no log-prefix=""
  66.  
  67. 24    ;;; Accept everything to non internet
  68.       chain=output action=accept out-interface=!DomRu log=no log-prefix=""
  69.  
  70. 25    ;;; Accept everything
  71.       chain=output action=accept log=no log-prefix=""
  72.  
  73. 26    ;;; Allow established related connections
  74.       chain=forward action=accept connection-state=established,related log=no log-prefix=""
  75.  
  76. 27    ;;; Drop invalid connections
  77.       chain=forward action=drop connection-state=invalid log=no log-prefix=""
  78.  
  79. 28    ;;; Accept ICMP
  80.       chain=forward action=accept protocol=icmp log=no log-prefix=""
  81.  
  82. 29    ;;; Accept from local to internet
  83.       chain=forward action=accept in-interface=!DomRu out-interface=DomRu log=no log-prefix=""
  84.  
  85. 30    ;;; Drop everything else
  86.       chain=forward action=drop log=no log-prefix=""
  87.  
  88. 31    ;;; Drop everything else
  89.       chain=input action=drop in-interface=DomRu log=no log-prefix=""
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement