|
马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。
您需要 登录 才可以下载或查看,没有账号?注册
×
/ ip firewall filter
add chain=input src-address=192.168.0.0/24 action=accept comment="" \
disabled=no
add chain=input action=drop comment="" disabled=no
add chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list \
address-list="port scanners" address-list-t
scanners to list " disabled=no
add chain=input protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg \
action=add-src-to-address-list address-list="port scanners" \
address-list-timeout=2w comment="NMAP FIN Stealth scan" disabled=no
add chain=input protocol=tcp tcp-flags=fin,syn action=add-src-to-address-list \
address-list="port scanners" address-list-timeout=2w comment="SYN/FIN \
scan" disabled=no
add chain=input protocol=tcp tcp-flags=syn,rst action=add-src-to-address-list \
address-list="port scanners" address-list-timeout=2w comment="SYN/RST \
scan" disabled=no
add chain=input protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack \
action=add-src-to-address-list address-list="port scanners" \
address-list-timeout=2w comment="FIN/PSH/URG scan" disabled=no
add chain=input protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg \
action=add-src-to-address-list address-list="port scanners" \
address-list-timeout=2w comment="ALL/ALL scan" disabled=no
add chain=input protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg \
action=add-src-to-address-list address-list="port scanners" \
address-list-timeout=2w comment="NMAP NULL scan" disabled=no
add chain=input src-address-list="port scanners" action=drop comment="dropping \
port scanners" disabled=no
add chain=input connection-state=invalid action=drop \
comment="丢弃非法连接packets" disabled=no
add chain=input protocol=tcp dst-port=80 connection-limit=60,0 action=drop \
comment="限制总http?
add chain=input protocol=tcp psd=21,3s,3,1 action=drop \
comment="探测并丢弃端口扫描连接" disabled=no
add chain=input protocol=tcp connection-limit=3,32 src-address-list=black_list \
action=tarpit comment="压制DoS攻击" disabled=no
add chain=input protocol=tcp connection-limit=10,32 \
action=add-src-to-address-list address-list=black_list \
address-list-timeout=1d comment="探测DoS攻击" disabled=no
add chain=input dst-address-type=!local action=drop comment="丢弃掉非本地数据" \
disabled=no
add chain=input src-address-type=!unicast action=drop \
comment="丢弃掉所有非单播数据" disabled=no
add chain=input protocol=tcp action=jump jump-target=virus \
comment="跳转到病毒链表" disabled=no
add chain=forward connection-state=established action=accept \
comment="接受以连接的数据包" disabled=no
add chain=forward connection-state=related action=accept \
comment="接受相关数据包" disabled=no
add chain=forward connection-state=invalid action=drop \
comment="丢弃非法数据包" disabled=no
add chain=forward protocol=tcp connection-limit=30,32 action=drop \
comment="限制每个主机TCP连接数为30条" disabled=no
add chain=forward src-address-type=!unicast action=drop \
comment="丢弃掉所有非单播数据" disabled=no
add chain=forward action=jump jump-target=virus comment="跳转到病毒链表" \
disabled=no
add chain=forward action=accept comment="接受任何数据" disabled=no
add chain=virus protocol=tcp dst-port=41 action=drop \
comment="DeepThroat.Trojan-1" disabled=no
add chain=virus protocol=tcp ds
comment="Worm.NetSky.Y@mm" disabled=noin
Password:
MMM
add chain=virus protocol=tcp dst-port=113 action=drop \ KKK
comment="W32.Korgo.A/B/C/D/E/F-1" disabled=no TTTTTTTTTTT KKK
add chain=virus protocol=tcp dst-port=2041 action=drop \
MMM MMMM MMM III KKK KKK RRRRRR OOOOOO
comment="W33.Korgo.A/B/C/D/E/F-2" disabled=no
add chain=virus protocol=tcp dst-port=3150 action=drop \ TTT III KKKKK
comment="DeepThroat.Trojan-2" disabled=no MMM III KKK KKK RRRRRR OOO OOO T
add chain=virus protocol=tcp dst-port=3067 action=drop \
MMM MMM III
comment="W32.Korgo.A/B/C/D/E/F-3" disabled=noK KKK
add chain=virus protocol=tcp dst-port=3422 action=d
comment="Worm.NetSky.S/T/U@mm" disabled=no
.168.0.254 v
add chain=virus protocol=tcp dst-port=8787 action=drop \ing single line input mode
comment="Back.Orifice.2000.Trojan-1" disabled=no pri
no such comma
add chain=virus protocol=tcp dst-port=8879 action=drop \admin@MikroTik] > /ip fri fil pri
comment="Back.Orifice.2000.Trojan-2" disabled=no
[admin@MikroTik] > ip fr
add chain=virus protocol=tcp dst-p
add chain=virus protocol=tcp dst-port=20034 action=drop \
1 chain=input action=drop
comment="Block.NetBus.Trojan-2" disabled=no
chain=input protocol=tc
add chain=virus protocol=tcp dst-port=21554 action=drop \
comment="GirlFriend.Trojan-1" disabled=nolist-timeout=2w
add chain=virus protocol=tcp dst-port=31666 action=drop \
chain=input protocol=t
comment="Back.Orifice.2000.Trojan-3" disabled=no
add chain=virus protocol=tcp dst-port=43958 action=drpo
action=add-s
comment="DeepThroat.Trojan-3" disabled=no
add chain=virus protocol=tcp dst-port=6670 action=drop \
5 ;;; SYN/RST scan
comment="DeepThroat.Trojan-4" disabled=noyn,rst
add chain=virus protocol=tcp dst-port=6771 action=drop \=port scanners
comment="DeepThroat.Trojan-5" disabled=no=2w
6 ;;; FIN
add chain=virus protocol=tcp dst-port=60000 action=drop \otocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack
comment="DeepThroat.Trojan-6" disabled=no
action=add-src-to-address-lis
add chain=virus protocol=tcp dst-port=2140 action=dro
comment="Delta.Source.Trojan-1" disabled=non=drop
add chain=virus protocol=tcp dst-port=26274 action=drop \
chain=input protocol=tcp dst-port=80
comment="Delta.Source.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=4444 action=drop \
chain=input protocol=tcp psd=2
comment="Delta.Source.Trojan-3" disabled=no
13 ;;; 压制DoS攻
add chain=virus protocol=tcp dst-port=47262 action=drop \ction-limit=3,32
comment="Delta.Source.Trojan-4" disabled=noon=tarpit
add chain=virus protocol=tcp dst-port=3791 action=drop \hain=input protocol=tcp connection-limit=10,32
comment="Eclypse.Trojan-1" disabled=no action=add-src-to-address-list addres
add chain=virus protocol=tcp dst-port=3801 action=dr
chain
add chain=virus protocol=tcp dst-port=5880-5882 action=drop \
17 ;;; 跳转到病毒链表
comment="Y3K.RAT.Trojan-1" disabled=nootocol=tcp action=jump jump-target=virus
add chain=virus protocol=tcp dst-port=5888-5889 action=drop \ ;;; 接受以连接的数据包
chai
comment="Y3K.RAT.Trojan-2" disabled=noon=accept
add chain=virus protocol=tcp dst-port=30100-30103 action=drop \
chain=forward connection-state=related action
comment="NetSphere.Trojan-1" disabled=no
20 ;;; 丢弃非法数据包
add chain=virus protocol=tcp dst-port=30133 action=drotate=invali
23 ;;; 跳转到病毒链表
comment="NetMonitor.Trojan-2" disabled=novirus
add chain=virus protocol=tcp dst-port=79 action=drop \ chain=forward action=accept
comment="FireHotcker.Trojan-1" disabled=no
chain=virus protocol=
add chain=virus protocol=tcp dst-port=5031 action=drop \
26 ;;; Worm.NetSky.Y@mm
comment="FireHotcker.Trojan-2" disabled=nocp dst-port=82 action=drop
add chain=virus protocol=tcp dst-port=5321 action=go.A/B/C/D/E/F-1
30 ;;; W32.Korgo.A/B/C/D/E/F-3
add chain=virus protocol=tcp dst-port=1047 action=drop \p dst-port=3067 action=drop
comment="GateCrasher.Trojan-1" disabled=noRC.Aladdinz.R-1
add chain=virus protocol=tcp dst-port=6969-6970 action=drop \
32 ;;
comment="GateCrasher.Trojan-2" disabled=no
chain=virus protocol=tcp dst-p
add chain=virus protocol=tcp dst-port=2774 action=drop
33 ;;; Worm.Net
chain=virus protocol=tcp
disabled=notion=drop
add chain=virus protocol=tcp dst-port=6711-6713 action=drop \2.Dabber.A/B-3
chain=virus prot
comment="SubSeven-5" disabled=no
add chain=virus protocol=tcp dst-port=16959 action=drop comment="SubSeven-7" \ chain=virus protocol=tcp dst-port=20034 action=drop
disabled=no
41 ;;; Backdoor.IRC.Aladd
comment="Moonpie.Trojan-2" disabled=no chain=virus protocol=tcp dst-port=4395
add chain=virus protocol=tcp dst-port=31337-31339 action=drop \
42 ;;; DeepThroat.Trojan-3
comment="NetSpy.Trojan-3" disabled=no9 action=drop
add chain=virus protocol=tcp dst-port=8102 action=drop comment="Trojan" \
chain=virus protocol=tcp dst-port=6670 action=drop
disabled=no
add chain=virus protocol=tcp dst-port=8011 action=drop comment="WAY.Trojan" \ chain=virus protocol=tcp dst-port=6771 action=drop
disabled=no
comment="Trojan.NianSeHoYian" disabled=nochain=virus protocol=tcp dst-port=10067 actio
add chain=virus protocol=tcp dst-port=23444-23445 action=drop \48 ;;; Portal.of.Doom.Trojan-2
comment="NetBull.Trojan" disabled=no10167 action=drop
add chain=virus protocol=tcp dst-port=2583 action=drop \m.Trojan-3
chain=vi
comment="WinCrash.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=3024 action=drop \
chain=virus protocol=tcp dst-po
comment="WinCrash.Trojan-2" disabled=no
5
comment="Doly1.0/1.35/1.5trojan-1" disabled=no
chain=virus protocol=tcp dst-port=47
add chain=virus protocol=tcp dst-port=1015 action=drop \
55 ;;; Eclypse.Trojan-1
comment="Doly1.0/1.35/1.5trojan-2" disabled=no791 action=drop
add chain=virus protocol=tcp dst-port=2001-2005 action=drop \
chain=virus protocol=tcp dst-port=3801 action
comment="TransScout.Trojan-1
chain=virus protocol=tcp dst-port=7306-7308 actio
comment="BackDoorTrojan-2" disabled=no
64 ;;; FireHotc
add chain=virus protocol=tcp dst-port=5698 action=drop \s protocol=tcp dst-port=79 action=drop
comment="BackDoorTrojan-3" disabled=no;; FireHotcker.Trojan-2
add chain=virus protocol=tcp dst-port=31554 action=drop \ion=drop
comment="SchainwindlerTrojan-2" disabled=no
chain=virus protocol=tc
add chain=virus protocol=tcp dst-port=18753 action=drop \
67 ;;; TheThing.Trojan-1
comment="Shaft.DDoS.Trojan-1" disabled=nol=tcp dst-port=6400 action=drop
add chain=virus protocol=tcp dst-port=20432 action=drop \ng.Trojan-2
chain=virus pr
comment="Shaft.DDoS.Trojan-2" disabled=no
cha
add chain=virus protocol=tcp dst-port=29559 action=drop \
72 ;;; Su
comment="LatinusTrojan-2" disabled=nous protocol=tcp dst-port=27374 action=dro
add chain=virus protocol=tcp dst-port=1784 action=drop \
73 ;;; SubSeven-3
chain=viru
comment="Snid.X2Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=3586 action=drop \ chain=virus protocol=tcp dst-port=1234 action=drop
comment="Snid.X2Trojan-2" disabled=no
75 ;;; SubSeven-5
comment="Worm.BBeagle.a.Bagle.a." disabled=nochain=virus protocol=tcp dst-port=7626 action=dro
add chain=virus protocol=tcp dst-port=8866 action=drop \
83 ;;; Trojan.NianSeHoYian
comment="Worm.BBeagle.b" disabled=no19191 action=drop
add chain=virus protocol=tcp dst-port=2745 action=drop \n
chain=virus protocol=tcp d
comment="Worm.BBeagle.c-g/j-l" disabled=no
add chain=virus protocol=tcp dst-port=2556 action=drop \ chain=virus protocol=tcp dst-port=2583 action=drop
comment="Worm.BBeagle.p/q/r/n" disabled=no
86 ;;; WinCrash.Trojan-2
add chain=virus protocol=tcp dst-port=20742 action=drop \action=drop
comment="Worm.BBEagle.m-2" disabled=no
89 ;;; Doly1.0/1.35/1.5trojan-1
comment="Worm.BBeagle.aa/ab/w/x-z-2" disabled=nocp dst-port=1010-1012 action=drop
add chain=virus protocol=tcp dst-port=5238 action=drop \.0/1.35/1.5trojan-2
comment="Worm.LovGate.r.RpcExploit" disabled=no
add chain=virus protocol=tcp dst-port=1068 action=drop comment="Worm.Sasser.a" \rotocol=tcp dst-port=2001-2005 action=drop
disabled=no
92 ;;;
comment="Worm.Lovgate.a/b/c/d" disabled=no
add chain=virus protocol=tcp dst-port=20808 action=drop \
comment="Worm.Lovgate.v.QQ" disabled=no
add chain=virus protocol=tcp dst-port=1092 action=drop \
comment="Worm.Lovgate.f/g" disabled=no
add chain=virus protocol=tcp dst-port=20168 action=drop \
comment="Worm.Lovgate.f/g" disabled=no
add chain=virus protocol=tcp dst-port=1363-1364 action=drop \
comment="ndm.requester" disabled=no
add chain=virus protocol=tcp dst-port=1368 action=drop comment="screen.cast" \
disabled=no
add chain=virus protocol=tcp dst-port=1373 action=drop comment="hromgrafx" \
disabled=no
add chain=virus protocol=tcp dst-port=1377 action=drop comment="cichainlid" \
disabled=no
add chain=virus protocol=tcp dst-port=3410 action=drop \
comment="Backdoor.Optixprotocol" disabled=no
add chain=virus protocol=tcp dst-port=8888 action=drop \
comment="Worm.BBeagle.b" disabled=no
add chain=virus protocol=udp dst-port=44444 action=drop \
comment="Delta.Source.Trojan-7" disabled=no
add chain=virus protocol=udp dst-port=8998 action=drop \
comment="Worm.Sobig.f-3" disabled=no
怎么看起来不规则.
就这模样什么都不动.以后再导入会不会有什么样的问题. |
|