RouterOS防火牆
/ ip firewall filter
add chain=input connection-state=invalid action=drop comment="丟棄非法連線資料" disabled=no
/ip firewall filter
add chain=input protocol=icmp action=drop comment="禁止外網Ping" disabled=no in-interface=ADSL
add chain=input protocol=tcp psd=21,3s,3,1 action=drop comment="探測並丟棄埠掃描連線" disabled=no
add chain=input protocol=tcp connection-limit=3,32 src-address-list=black_list action=tarpit comment="壓制DoS攻擊" disabled=no
add chain=input protocol=tcp connection-limit=10,32 action=add-src-to-address-list address-list=black_list address-list-timeout=1d comment="探測DoS攻擊" disabled=no
add chain=input dst-address-type=!local action=drop comment="丟棄掉非本地資料" disabled=no
add chain=input protocol=icmp action=jump jump-target=ICMP comment="跳轉到ICMP連結串列" disabled=no
add chain=ICMP protocol=icmp icmp-options=0:0-255 limit=5,5 action=accept comment="Ping應答限制為每秒5個包" disabled=no
add chain=ICMP protocol=icmp icmp-options=3:3 limit=5,5 action=accept comment="Traceroute限制為每秒5個包" disabled=no
add chain=ICMP protocol=icmp icmp-options=3:4 limit=5,5 action=accept comment="MTU線路探測限制為每秒5個包" disabled=no
add chain=ICMP protocol=icmp icmp-options=8:0-255 limit=5,5 action=accept comment="Ping請求限制為每秒5個包" disabled=no
add chain=ICMP protocol=icmp icmp-options=11:0-255 limit=5,5 action=accept comment="Trace TTL限制為每秒5個包" disabled=no
add chain=ICMP protocol=icmp action=drop comment="丟棄掉任何ICMP資料" disabled=no
add chain=forward connection-state=invalid action=drop comment="丟棄非法資料包" disabled=no
add chain=forward src-address-type=!unicast action=drop comment="丟棄掉所有非單播資料" disabled=no
add chain=forward protocol=icmp action=jump jump-target=ICMP comment="跳轉到ICMP連結串列" disabled=no[@more@]
add chain=input connection-state=invalid action=drop comment="丟棄非法連線資料" disabled=no
/ip firewall filter
add chain=input protocol=icmp action=drop comment="禁止外網Ping" disabled=no in-interface=ADSL
add chain=input protocol=tcp psd=21,3s,3,1 action=drop comment="探測並丟棄埠掃描連線" disabled=no
add chain=input protocol=tcp connection-limit=3,32 src-address-list=black_list action=tarpit comment="壓制DoS攻擊" disabled=no
add chain=input protocol=tcp connection-limit=10,32 action=add-src-to-address-list address-list=black_list address-list-timeout=1d comment="探測DoS攻擊" disabled=no
add chain=input dst-address-type=!local action=drop comment="丟棄掉非本地資料" disabled=no
add chain=input protocol=icmp action=jump jump-target=ICMP comment="跳轉到ICMP連結串列" disabled=no
add chain=ICMP protocol=icmp icmp-options=0:0-255 limit=5,5 action=accept comment="Ping應答限制為每秒5個包" disabled=no
add chain=ICMP protocol=icmp icmp-options=3:3 limit=5,5 action=accept comment="Traceroute限制為每秒5個包" disabled=no
add chain=ICMP protocol=icmp icmp-options=3:4 limit=5,5 action=accept comment="MTU線路探測限制為每秒5個包" disabled=no
add chain=ICMP protocol=icmp icmp-options=8:0-255 limit=5,5 action=accept comment="Ping請求限制為每秒5個包" disabled=no
add chain=ICMP protocol=icmp icmp-options=11:0-255 limit=5,5 action=accept comment="Trace TTL限制為每秒5個包" disabled=no
add chain=ICMP protocol=icmp action=drop comment="丟棄掉任何ICMP資料" disabled=no
add chain=forward connection-state=invalid action=drop comment="丟棄非法資料包" disabled=no
add chain=forward src-address-type=!unicast action=drop comment="丟棄掉所有非單播資料" disabled=no
add chain=forward protocol=icmp action=jump jump-target=ICMP comment="跳轉到ICMP連結串列" disabled=no[@more@]
來自 “ ITPUB部落格 ” ,連結:http://blog.itpub.net/124805/viewspace-1047088/,如需轉載,請註明出處,否則將追究法律責任。
相關文章
- WAb防火牆與傳統防火牆防火牆
- 防火牆防火牆
- 防火牆(firewall)防火牆
- SQL防火牆SQL防火牆
- 防火牆IPTABLES防火牆
- iptables防火牆防火牆
- 防火牆配置防火牆
- 防火牆入侵於檢測——————3、思科 PIX 防火牆和 ASA 防火牆產品線防火牆
- AutoRun病毒防火牆如何使用 AutoRun病毒防火牆教程防火牆
- 軟體防火牆與硬體防火牆詳解防火牆
- 全面分析防火牆及防火牆的滲透(轉)防火牆
- CentOS 防火牆操作CentOS防火牆
- 防火牆介紹防火牆
- CentOS 7.0防火牆CentOS防火牆
- linux 防火牆Linux防火牆
- 防火牆透明模式防火牆模式
- 配置防火牆示例防火牆
- 電影:防火牆防火牆
- 防火牆部署案例防火牆
- ubuntu 關閉防火牆命令 ubuntu怎樣關閉防火牆Ubuntu防火牆
- 選用單防火牆DMZ還是雙防火牆DMZ(轉)防火牆
- 防火牆 搜尋 釋出 防火牆是什麼?怎麼理解?防火牆
- 八種防火牆產品評測(企業級防火牆)(轉)防火牆
- 資料庫防火牆資料庫防火牆
- Iptables防火牆應用防火牆
- iptables防火牆規則防火牆
- LINUX 防火牆 firewalldLinux防火牆
- CentOS 7 防火牆操作CentOS防火牆
- 防火牆的分類防火牆
- CentOS關閉防火牆CentOS防火牆
- entos 7中防火牆防火牆
- ADDS與防火牆防火牆
- CiscoPIX防火牆配置指南防火牆
- linux防火牆iptablesLinux防火牆
- OpenSUSE關閉防火牆防火牆
- linux 防火牆配置Linux防火牆
- Linux 配置防火牆Linux防火牆
- 防火牆iptables 設定防火牆