Advertisement
axezkode

MKFirewallFilter

Sep 29th, 2018
118
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.59 KB | None | 0 0
  1. /ip firewall filter
  2. add action=accept chain=input disabled=yes protocol=icmp
  3. add action=drop chain=port-scan comment="DROPING BAD HOMBRES (Scanners)" src-address-list=bad-hombres
  4. add action=jump chain=input jump-target=port-scan
  5. add action=add-src-to-address-list address-list=bad-hombres address-list-timeout=none-static chain=port-scan comment="Port scanners to list " protocol=tcp psd=21,5s,3,1
  6. add action=add-src-to-address-list address-list=bad-hombres address-list-timeout=none-static chain=port-scan comment="NMAP FIN Stealth scan" protocol=tcp tcp-flags=\
  7. fin,!syn,!rst,!psh,!ack,!urg
  8. add action=add-src-to-address-list address-list=bad-hombres address-list-timeout=none-static chain=port-scan comment="SYN/FIN scan" protocol=tcp tcp-flags=fin,syn
  9. add action=add-src-to-address-list address-list=bad-hombres address-list-timeout=none-static chain=port-scan comment="SYN/RST scan" protocol=tcp tcp-flags=syn,rst
  10. add action=add-src-to-address-list address-list=bad-hombres address-list-timeout=none-static chain=port-scan comment="FIN/PSH/URG scan" protocol=tcp tcp-flags=\
  11. fin,psh,urg,!syn,!rst,!ack
  12. add action=add-src-to-address-list address-list=bad-hombres address-list-timeout=none-static chain=port-scan comment="NMAP NULL scan" protocol=tcp tcp-flags=\
  13. !fin,!syn,!rst,!psh,!ack,!urg
  14. add action=add-src-to-address-list address-list=bad-hombres address-list-timeout=none-static chain=port-scan comment="ALL/ALL scan" protocol=tcp tcp-flags=\
  15. fin,syn,rst,psh,ack,urg
  16. add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
  17. add action=drop chain=input comment="DROP INVALID" connection-state=invalid
  18. add action=drop chain=input comment="DROP ALL NOT COMING FROM LAN" src-address-list=!whitelisted
  19. add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
  20. add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
  21. add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
  22. add action=drop chain=forward comment="Drop tries to reach not public addresses from LAN" dst-address-list=Especial-Purpose-IP in-interface=Bridge-LAN log=yes \
  23. log-prefix=!public_from_LAN out-interface=ether1
  24. add action=drop chain=forward comment="Drop incoming from internet which is not public IP" in-interface=ether1 log=yes log-prefix=!public src-address-list=\
  25. Especial-Purpose-IP
  26. add action=drop chain=input in-interface=!Bridge-LAN
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement