Advertisement
Guest User

Untitled

a guest
Dec 17th, 2017
152
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.27 KB | None | 0 0
  1. /ip firewall filter
  2. add action=accept chain=forward comment="allow already established connections" \
  3. connection-state=established
  4. add action=accept chain=input connection-state=established in-interface=WAN
  5. add action=accept chain=forward comment="allow related connections" \
  6. connection-state=related
  7. add action=add-src-to-address-list address-list="port scanners" \
  8. address-list-timeout=2w chain=input comment="NMAP NULL scan" protocol=tcp \
  9. tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg
  10. add action=add-src-to-address-list address-list="port scanners" \
  11. address-list-timeout=2w chain=input comment="Port scanners to list " \
  12. protocol=tcp psd=21,3s,3,1
  13. add action=add-src-to-address-list address-list="port scanners" \
  14. address-list-timeout=2w chain=input comment="NMAP FIN Stealth scan" \
  15. protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg
  16. add action=add-src-to-address-list address-list="port scanners" \
  17. address-list-timeout=2w chain=input comment="SYN/FIN scan" protocol=tcp \
  18. tcp-flags=fin,syn
  19. add action=add-src-to-address-list address-list="port scanners" \
  20. address-list-timeout=2w chain=input comment="SYN/RST scan" protocol=tcp \
  21. tcp-flags=syn,rst
  22. add action=add-src-to-address-list address-list="port scanners" \
  23. address-list-timeout=2w chain=input comment="FIN/PSH/URG scan" protocol=tcp \
  24. tcp-flags=fin,psh,urg,!syn,!rst,!ack
  25. add action=add-src-to-address-list address-list="port scanners" \
  26. address-list-timeout=2w chain=input comment="ALL/ALL scan" protocol=tcp \
  27. tcp-flags=fin,syn,rst,psh,ack,urg
  28. add action=drop chain=forward comment="drop invalid connections" \
  29. connection-state="" disabled=yes
  30. add action=drop chain=input comment="Drop Invalid connections" \
  31. connection-state="" disabled=yes
  32. add action=drop chain=input comment="dropping port scanners" src-address-list=\
  33. "port scanners"
  34. add action=drop chain=forward comment="Block Bogon IP addresses" src-address=\
  35. 0.0.0.0/8
  36. add action=drop chain=forward dst-address=0.0.0.0/8
  37. add action=drop chain=forward src-address=127.0.0.0/8
  38. add action=drop chain=forward dst-address=127.0.0.0/8
  39. add action=drop chain=forward src-address=224.0.0.0/3
  40. add action=drop chain=forward dst-address=224.0.0.0/3
  41. add action=drop chain=input in-interface=WAN
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement