Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /ip firewall filter
- add action=accept chain=input comment="accept established,related,untracked" connection-state=established,related,untracked
- add action=accept chain=input comment="accept WinBox" disabled=yes dst-port=8291 protocol=tcp
- add action=accept chain=input comment="accept SSTP" dst-port=443 protocol=tcp
- add action=accept chain=input comment="accept GRE" protocol=gre
- add action=drop chain=input comment="drop invalid" connection-state=invalid
- add action=accept chain=input comment="accept ICMP" protocol=icmp
- add action=accept chain=input comment="accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
- add action=drop chain=input comment="drop all not coming from LAN" in-interface-list=!LAN
- add action=accept chain=forward comment="accept in ipsec policy" ipsec-policy=in,ipsec
- add action=accept chain=forward comment="accept out ipsec policy" ipsec-policy=out,ipsec
- add action=fasttrack-connection chain=forward comment=fasttrack connection-state=established,related disabled=yes
- add action=accept chain=forward comment="accept established,related, untracked" connection-state=\
- established,related,untracked
- add action=drop chain=forward comment="drop invalid" connection-state=invalid
- add action=drop chain=forward comment="drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new \
- in-interface-list=WAN
Advertisement
Add Comment
Please, Sign In to add comment