Advertisement
Guest User

Untitled

a guest
Jul 18th, 2018
74
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.68 KB | None | 0 0
  1. /ip firewall address-list
  2. add address=45.63.18.43 list=SITES-LIBERADOS
  3. add address=208.67.222.222 list=SITES-LIBERADOS
  4. add address=208.67.222.220 list=SITES-LIBERADOS
  5. add address=8.8.8.8 list=SITES-LIBERADOS
  6. add address=8.8.4.4 list=SITES-LIBERADOS
  7. add address=1.1.1.1 list=SITES-LIBERADOS
  8. add address=172.16.100.2 list=SITES-LIBERADOS
  9. add address=172.16.150.2 list=SITES-LIBERADOS
  10. add address=10.24.0.0/22 list=BLOQUEADOS
  11.  
  12.  
  13. /ip firewall filter
  14. add action=drop chain=forward dst-address-list=!SITES-LIBERADOS src-address-list=BLOQUEADOS comment="SGP REGRAS"
  15.  
  16. /ip firewall nat
  17. add action=masquerade chain=srcnat comment="SGP REGRAS" src-address-list=\
  18. BLOQUEADOS
  19. add action=dst-nat chain=dstnat comment="SGP REGRAS" dst-address-list=\
  20. !SITES-LIBERADOS dst-port=80,443 log-prefix="" protocol=tcp \
  21. src-address-list=BLOQUEADOS to-addresses=45.63.18.43 to-ports=6403
  22. add action=dst-nat chain=dstnat comment="SGP REGRAS" connection-mark=\
  23. BLOQUEIO-AVISAR log-prefix="" protocol=tcp to-addresses=45.63.18.43 \
  24. to-ports=6402
  25.  
  26. # Aviso bloqueio
  27. /ip firewall mangle
  28. add chain=prerouting connection-state=new src-address-list=BLOQUEIO-AVISAR protocol=tcp dst-port=80 \
  29. action=mark-connection new-connection-mark=BLOQUEIO-VERIFICAR passthrough=yes comment="SGP REGRAS"
  30. add chain=prerouting connection-mark=BLOQUEIO-VERIFICAR src-address-list=!BLOQUEIO-AVISADOS \
  31. action=mark-connection new-connection-mark=BLOQUEIO-AVISAR comment="SGP REGRAS"
  32.  
  33. /ip firewall filter
  34. add chain=forward connection-mark=BLOQUEIO-AVISAR action=add-src-to-address-list \
  35. address-list=BLOQUEIO-AVISADOS address-list-timeout=2h comment="SGP REGRAS" dst-address=45.63.18.43 dst-port=6402 protocol=tcp
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement