Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /interface ethernet
- set [ find default-name=ether2 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full comment=\
- Servidor name=ether1
- set [ find default-name=ether1 ] comment=Wi-Fi name=ether2
- /interface pppoe-client
- add add-default-route=yes comment=Modem disabled=no interface=ether1 max-mru=1492 max-mtu=1500 name=pppoe-out1 \
- password=algaralgar use-peer-dns=yes user=algar@algar
- /ip neighbor discovery
- set ether1 comment=Servidor
- set ether2 comment=Wi-Fi
- set pppoe-out1 comment=Modem
- /interface wireless security-profiles
- set [ find default=yes ] supplicant-identity=MikroTik
- /ip pool
- add name=dhcp_pool1 ranges=192.168.1.2
- add name=dhcp_pool2 ranges=192.168.1.6
- /ip dhcp-server
- add address-pool=dhcp_pool1 disabled=no interface=ether2 name=dhcp2
- add address-pool=dhcp_pool2 disabled=no interface=ether1 name=dhcp1
- /queue simple
- add max-limit=3M/50M name="Controle De Banda Roteador Wi-Fi" target=ether2
- /ip settings
- set tcp-syncookies=yes
- /ip address
- add address=192.168.1.5/30 comment=Servidor interface=ether1 network=192.168.1.4
- add address=192.168.1.1/30 comment=Wi-Fi interface=ether2 network=192.168.1.0
- /ip dhcp-client
- add default-route-distance=0 dhcp-options=hostname,clientid interface=ether1
- /ip dhcp-server network
- add address=192.168.1.0/30 gateway=192.168.1.1
- add address=192.168.1.4/30 gateway=192.168.1.5
- /ip dns
- set servers=192.168.0.1,8.8.8.8
- /ip firewall address-list
- add address=192.168.1.0/24 list=support
- /ip firewall filter
- add action=jump chain=forward comment="Jump for icmp forward flow" jump-target=ICMP log-prefix="" protocol=icmp
- add action=accept chain=input comment="Accept DNS - UDP" log-prefix="" port=53 protocol=udp
- add action=accept chain=ICMP comment="Time Exceeded" icmp-options=11:0 log-prefix="" protocol=icmp
- add action=accept chain=ICMP comment="Destination unreachable" icmp-options=3:0-1 log-prefix="" protocol=icmp
- add action=accept chain=ICMP comment=PMTUD icmp-options=3:4 log-prefix="" protocol=icmp
- add action=drop chain=ICMP comment="Drop to the other ICMPs" log-prefix="" protocol=icmp
- add action=jump chain=output comment="Jump for icmp output" jump-target=ICMP log-prefix="" protocol=icmp
- add action=add-src-to-address-list address-list=blocked-addr address-list-timeout=1w3d chain=input comment=\
- "SYN Flood protect" connection-limit=100,32 in-interface=pppoe-out1 log-prefix="" protocol=tcp
- add action=tarpit chain=input comment="SYN Flood protect" connection-limit=3,32 log-prefix="" protocol=tcp \
- src-address-list=blocked-addr
- add action=jump chain=forward comment="SYN Flood protect" connection-state=new jump-target=SYN-Protect log-prefix=\
- "" protocol=tcp tcp-flags=syn
- add action=drop chain=SYN-Protect comment="SYN Flood protect" connection-limit=100,32 connection-state=new log=yes \
- log-prefix="DROP SYN FLOOD" protocol=tcp tcp-flags=syn
- add action=jump chain=forward comment="anti DDoS" connection-state=new jump-target=detect-ddos log-prefix=""
- add action=return chain=detect-ddos dst-limit=32,32,src-and-dst-addresses/10s dst-port=27165,7787 log-prefix=""
- protocol=udp
- add action=add-dst-to-address-list address-list=ddosed address-list-timeout=1w4d chain=detect-ddos log=yes \
- log-prefix=ATACANTE
- add action=return chain=detect-ddos comment="DDoS protect" log-prefix="" src-address=192.168.1.0/24
- add action=add-dst-to-address-list address-list=ddosed address-list-timeout=1w3d chain=detect-ddos comment=\
- "DDoS protect" log-prefix=""
- add action=add-src-to-address-list address-list=ddoser address-list-timeout=1w3d chain=detect-ddos comment=\
- "DDoS protect" log-prefix=""
- /ip firewall mangle
- add action=mark-routing chain=prerouting dst-address-list=ddosed log=yes log-prefix=BLACKHOLE new-routing-mark=\
- ddoser-route-mark passthrough=no src-address-list=ddoser
- /ip firewall nat
- add action=masquerade chain=srcnat comment=Internet log-prefix="" out-interface=pppoe-out1
- add action=dst-nat chain=dstnat comment="open ports" dst-address-type=local log-prefix=OPENPORTS to-addresses=\
- 192.168.1.6
- /ip firewall service-port
- set ftp disabled=yes
- set tftp disabled=yes
- set irc disabled=yes
- set h323 disabled=yes
- set sip disabled=yes
- set pptp disabled=yes
- set udplite disabled=yes
- set dccp disabled=yes
- set sctp disabled=yes
- /ip route
- add distance=1 routing-mark=ddoser-route-mark type=blackhole
- add distance=1 dst-address=192.168.2.0/24 gateway=192.168.1.2
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www disabled=yes
- set ssh disabled=yes
- set api disabled=yes
- set winbox address=0.0.0.0/0 port=9191
- set api-ssl disabled=yes
- /ip traffic-flow
- set active-flow-timeout=1m cache-entries=1M enabled=yes
- /ip traffic-flow target
- add dst-address=192.168.0.150 port=27165
- /system identity
Advertisement
Add Comment
Please, Sign In to add comment