Advertisement
Guest User

Untitled

a guest
Jan 28th, 2020
152
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 1.40 KB | None | 0 0
  1. /ip firewall filter
  2. add action=accept chain=input comment="allow in established" connection-state=established
  3. add action=accept chain=input comment="allow in related" connection-state=related
  4. add action=accept chain=input comment="allow icmp in" protocol=icmp
  5. add action=accept chain=input comment="allow MGMT-ACL address list inbound mgmt" protocol=tcp src-address-list=MGMT-ACL
  6. add action=accept chain=forward src-address-list=Telnyx
  7. add action=accept chain=forward dst-address-list=Telnyx
  8. add action=drop chain=input comment="default drop input"
  9.  
  10. /ip firewall nat
  11. add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN
  12. add action=dst-nat chain=dstnat dst-address=<public-ip> dst-port=9000-10999 protocol=udp to-addresses=<local-ip> to-ports=9000-10999
  13. add action=dst-nat chain=dstnat dst-address=<public-ip> dst-port=5060 protocol=tcp to-addresses=<local-ip> to-ports=5060
  14. add action=dst-nat chain=dstnat dst-address=<public-ip> dst-port=5090 protocol=tcp to-addresses=<local-ip> to-ports=5090
  15. add action=dst-nat chain=dstnat dst-address=<public-ip> dst-port=5061 protocol=tcp to-addresses=<local-ip> to-ports=5061
  16. add action=dst-nat chain=dstnat dst-address=<public-ip> dst-port=5060 protocol=udp to-addresses=<local-ip> to-ports=5060
  17. add action=dst-nat chain=dstnat dst-address=<public-ip> dst-port=5090 protocol=udp to-addresses=<local-ip> to-ports=5090
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement