Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /ip firewall filter
- add action=add-src-to-address-list address-list=Suspect.Spam \
- address-list-timeout=none-dynamic chain=forward comment=\
- "Log Spammer To Address List" dst-port=25,465,587 protocol=tcp \
- src-address-list=Spammer
- add action=tarpit chain=forward comment="Block Spammer Or Infected IP" \
- dst-port=25,143,587 protocol=tcp src-address-list=Spammer
- add action=add-src-to-address-list address-list=Spammer address-list-timeout=\
- 3d chain=forward comment="Detect & Add-list SMTP Virus Or Spammers" \
- connection-limit=30,32 dst-port=25,465,587 limit=50,5:packet protocol=tcp \
- src-address-list=!WhiteListSpam
- add action=passthrough chain=unused-hs-chain comment=\
- "place hotspot rules here"
- add action=drop chain=Virus comment="port block warning" dst-port=1434 \
- protocol=tcp
- add action=drop chain=Virus dst-port=1434 protocol=udp
- add action=drop chain=Virus dst-port=2745 protocol=udp
- add action=drop chain=Virus dst-port=6344-6381 protocol=tcp
- add action=drop chain=Virus dst-port=6344-6381 protocol=udp
- add action=drop chain=Virus comment=MyDoom dst-port=1080 protocol=tcp
- add action=drop chain=Virus dst-port=1214 protocol=tcp
- add action=drop chain=Virus dst-port=593 protocol=tcp
- add action=drop chain=Virus dst-port=1024-1030 protocol=tcp
- add action=drop chain=Virus comment=SNPP dst-port=444 protocol=tcp
- add action=drop chain=Virus comment="Blaster Worm" dst-port=135-139 protocol=\
- tcp
- add action=drop chain=Virus comment="Messenger Worm" dst-port=135-139 \
- protocol=udp
- add action=add-src-to-address-list address-list=ip-infected-virus \
- address-list-timeout=3d chain=Virus comment="Blaster Worm" \
- dst-address-list=!smb-flooder dst-port=445 protocol=tcp src-address-list=\
- smb-flooder
- add action=drop chain=Virus comment="Blaster Worm" dst-address-list=\
- !smb-flooder dst-port=445 protocol=tcp src-address-list=smb-flooder
- add action=drop chain=Virus comment="Blaster Worm" dst-address-list=\
- !smb-flooder dst-port=445 protocol=udp src-address-list=smb-flooder
- add action=drop chain=Virus comment="ndm requester" dst-port=1363 protocol=\
- tcp
- add action=drop chain=Virus comment="ndm server" dst-port=1364 protocol=tcp
- add action=drop chain=Virus comment="screen cast" dst-port=1368 protocol=tcp
- add action=drop chain=Virus comment=hromgrafx dst-port=1373 protocol=tcp
- add action=drop chain=Virus comment=cichlid dst-port=1377 protocol=tcp
- add action=drop chain=Virus comment=Worm dst-port=1433-1434 protocol=tcp
- add action=drop chain=Virus comment="Bagle Virus" dst-port=2745 protocol=tcp
- add action=drop chain=Virus comment="Drop Dumaru.Y" dst-port=2283 protocol=\
- tcp
- add action=drop chain=Virus comment="Drop Beagle" dst-port=2235 protocol=tcp
- add action=drop chain=Virus comment="Drop Beagle.C-K" dst-port=2745 protocol=\
- tcp
- add action=drop chain=Virus comment="Drop MyDoom" dst-port=3127-3128 \
- protocol=tcp
- add action=drop chain=Virus comment="Drop Backdoor OptixPro" dst-port=3410 \
- protocol=tcp
- add action=drop chain=Virus comment=Worm dst-port=4444 protocol=tcp
- add action=drop chain=Virus comment=Worm dst-port=4444 protocol=udp
- add action=drop chain=Virus comment="Drop Sasser" dst-port=5554 protocol=tcp
- add action=drop chain=Virus comment="Drop Beagle.B" dst-port=8866 protocol=\
- tcp
- add action=drop chain=Virus comment="Drop Dabber.A-B" dst-port=9898 protocol=\
- tcp
- add action=drop chain=Virus comment="Drop Dumaru.Y" dst-port=10000 protocol=\
- tcp
- add action=drop chain=Virus comment="Drop MyDoom.B" dst-port=10080 protocol=\
- tcp
- add action=drop chain=Virus comment="Drop NetBus" dst-port=12345 protocol=tcp
- add action=drop chain=Virus comment="Drop Kuang2" dst-port=17300 protocol=tcp
- add action=drop chain=Virus comment="Drop PhatBot, Agobot, Gaobot" dst-port=\
- 65506 protocol=tcp
- add action=drop chain=Virus comment="Drop SubSeven" dst-port=27374 protocol=\
- tcp
- add action=drop chain=forward connection-state=invalid
- add action=accept chain=forward connection-state=related
- add action=accept chain=forward connection-state=established
- add action=jump chain=forward jump-target=Virus
- add action=drop chain=input connection-state=invalid
- add action=accept chain=input connection-state=related
- add action=accept chain=input connection-state=established
- add action=jump chain=input jump-target=Virus
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement