Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ```ngnix[Blindside@RB4011] /ip firewall filter> print
- Flags: X - disabled, I - invalid, D - dynamic
- 0 D ;;; special dummy rule to show fasttrack counters
- chain=forward action=passthrough
- 1 chain=forward action=accept protocol=icmp
- 2 ;;; defconf: accept established,related,untracked
- chain=input action=accept connection-state=established,related,untracked
- 3 ;;; defconf: drop invalid
- chain=input action=drop connection-state=invalid
- 4 ;;; RouterAccess
- chain=input action=accept protocol=tcp src-address-list=InternalSubnet
- dst-port=8291,1111,1112,1113,1118 log=no log-prefix=""
- 5 ;;; defconf: accept ICMP
- chain=input action=accept protocol=icmp
- 6 ;;; defconf: drop all not coming from LAN
- chain=input action=drop in-interface-list=!LAN
- 7 ;;; defconf: accept in ipsec policy
- chain=forward action=accept ipsec-policy=in,ipsec
- 8 ;;; defconf: accept out ipsec policy
- chain=forward action=accept ipsec-policy=out,ipsec
- 9 ;;; defconf: fasttrack
- chain=forward action=fasttrack-connection
- connection-state=established,related
- 10 ;;; defconf: accept established,related, untracked
- chain=forward action=accept
- connection-state=established,related,untracked
- 11 ;;; defconf: drop invalid
- chain=forward action=drop connection-state=invalid
- 12 ;;; defconf: drop all from WAN not DSTNATed
- chain=forward action=drop connection-state=new
- connection-nat-state=!dstnat in-interface-list=WAN
- 13 ;;; defconf: accept established,related
- chain=forward action=accept connection-state=established,related
- 14 ;;; defconf: drop invalid
- chain=forward action=drop connection-state=invalid
- 15 chain=input action=accept protocol=udp port=69
- 16 chain=forward action=accept protocol=udp port=69
- 17 ;;; defconf: drop all from WAN not DSTNATed
- chain=forward action=drop connection-state=new
- connection-nat-state=!dstnat in-interface=ether1
- 18 ;;; Drop to bogon list
- chain=forward action=drop dst-address-list=Bogons
- 19 chain=input action=accept connection-state=established
- 20 chain=input action=accept connection-state=related
- 21 chain=input action=drop in-interface=ether1
- ```
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement