Advertisement
Guest User

Untitled

a guest
Jan 28th, 2020
89
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.01 KB | None | 0 0
  1. :global AUC "4822"
  2. :global ACC "4823"
  3. :global RADIUS "172.16.116.1"
  4. :global TOKENAQUI "dfb73cb7-bee5-4319-aae0-7364d0c7d1c3"
  5. :global LINKDOSGP "https://mnet.sgp.net.br"
  6. :global IP "167.71.109.194"
  7. :global AVS "6404"
  8. :global BLQ "6405"
  9. /ip firewall address-list
  10. add address=$IP list=SITES-LIBERADOS
  11. add address=208.67.222.222 list=SITES-LIBERADOS
  12. add address=208.67.222.220 list=SITES-LIBERADOS
  13. add address=8.8.8.8 list=SITES-LIBERADOS
  14. add address=8.8.4.4 list=SITES-LIBERADOS
  15. add address=1.1.1.1 list=SITES-LIBERADOS
  16. add address=45.227.76.22 list=SITES-LIBERADOS
  17. add address=45.227.79.1 list=SITES-LIBERADOS
  18. add address=10.24.0.0/22 list=BLOQUEADOS
  19. /ip firewall filter
  20. add action=drop chain=forward dst-address-list=!SITES-LIBERADOS src-address-list=BLOQUEADOS comment="SGP REGRAS"
  21. /ip firewall filter
  22. add chain=forward connection-mark=BLOQUEIO-AVISAR action=add-src-to-address-list \
  23. address-list=BLOQUEIO-AVISADOS address-list-timeout=2h comment="SGP REGRAS" dst-address=$IP dst-port=$AVS protocol=tcp
  24. /ip firewall nat
  25. add action=accept chain=srcnat comment="NAO FAZER NAT PARA O IP DO RADIUS" \
  26. dst-address=$RADIUS dst-port="$AUC-$ACC,3799" protocol=udp
  27. add action=masquerade chain=srcnat comment="SGP REGRAS" src-address-list=\
  28. BLOQUEADOS
  29. add action=dst-nat chain=dstnat comment="SGP REGRAS" dst-address-list=\
  30. !SITES-LIBERADOS dst-port=80,443 log-prefix="" protocol=tcp \
  31. src-address-list=BLOQUEADOS to-addresses=$IP to-ports=$BLQ
  32. add action=dst-nat chain=dstnat comment="SGP REGRAS" connection-mark=\
  33. BLOQUEIO-AVISAR log-prefix="" protocol=tcp to-addresses=$IP to-ports=$AVS
  34. # Aviso bloqueio
  35. /ip firewall mangle
  36. add chain=prerouting connection-state=new src-address-list=BLOQUEIO-AVISAR protocol=tcp dst-port=80 \
  37. action=mark-connection new-connection-mark=BLOQUEIO-VERIFICAR passthrough=yes comment="SGP REGRAS"
  38. add chain=prerouting connection-mark=BLOQUEIO-VERIFICAR src-address-list=!BLOQUEIO-AVISADOS \
  39. action=mark-connection new-connection-mark=BLOQUEIO-AVISAR comment="SGP REGRAS"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement