|
马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。
您需要 登录 才可以下载或查看,没有账号?注册
×
我安装的是 routeros2.9.6 现在是其他的网站都正常.但是不能上访问搜狐和新浪!我安装的是3条adsl线路分流!
所有的脚本为:
- # nov/06/2008 10:11:19 by RouterOS 2.9.6
- # software id = 8ILR-19T
- #
- / interface ethernet
- set lan name="lan" mtu=1500 mac-address=00:1C:F0:0E:3E:BF arp=enabled \
- disable-running-check=yes auto-negotiation=yes full-duplex=yes \
- cable-settings=default speed=100Mbps comment="" disabled=no
- set wan2 name="wan2" mtu=1500 mac-address=00:1C:F0:0E:9B:63 arp=enabled \
- disable-running-check=yes auto-negotiation=yes full-duplex=yes \
- cable-settings=default speed=100Mbps comment="" disabled=no
- set wan3 name="wan3" mtu=1500 mac-address=00:1C:F0:0E:3E:C7 arp=enabled \
- disable-running-check=yes auto-negotiation=yes full-duplex=yes \
- cable-settings=default speed=100Mbps comment="" disabled=no
- set wan1 name="wan1" mtu=1500 mac-address=00:1C:F0:0E:2F:00 arp=enabled \
- disable-running-check=yes auto-negotiation=yes full-duplex=yes \
- cable-settings=default speed=100Mbps comment="" disabled=no
- / interface wireless security-profiles
- set default name="default" mode=none wpa-unicast-ciphers="" \
- wpa-group-ciphers="" pre-shared-key="" static-algo-0=none static-key-0="" \
- static-algo-1=none static-key-1="" static-algo-2=none static-key-2="" \
- static-algo-3=none static-key-3="" static-transmit-key=key-0 \
- static-sta-private-algo=none static-sta-private-key="" \
- radius-mac-authentication=no group-key-update=5m
- / interface wireless align
- set frame-size=300 active-mode=yes receive-all=no \
- audio-monitor=00:00:00:00:00:00 filter-mac=00:00:00:00:00:00 ssid-all=no \
- frames-per-second=25 audio-min=-100 audio-max=-20
- / interface wireless snooper
- set multiple-channels=yes channel-time=200ms receive-errors=no
- / interface wireless sniffer
- set multiple-channels=no channel-time=200ms only-headers=no receive-errors=no \
- memory-limit=10 file-name="" file-limit=10 streaming-enabled=no \
- streaming-server=0.0.0.0 streaming-max-rate=0
- / interface bridge port
- set lan bridge=none priority=128 path-cost=10
- set wan2 bridge=none priority=128 path-cost=10
- set wan3 bridge=none priority=128 path-cost=10
- set wan1 bridge=none priority=128 path-cost=10
- / interface l2tp-server server
- set enabled=no max-mtu=1460 max-mru=1460 \
- authentication=pap,chap,mschap1,mschap2 default-profile=default-encryption
- / interface pptp-server server
- set enabled=no max-mtu=1460 max-mru=1460 authentication=mschap1,mschap2 \
- keepalive-timeout=30 default-profile=default-encryption
- / interface pppoe-client
- add name="pppoe-out1" max-mtu=1492 max-mru=1492 interface=wan1 \
- user="123" password="123" profile=default service-name="" \
- ac-name="" add-default-route=no dial-on-demand=no use-peer-dns=no \
- allow=pap,chap,mschap1,mschap2 disabled=no
- add name="pppoe-out2" max-mtu=1492 max-mru=1492 interface=wan2 \
- user="456" password="456" profile=default service-name="" \
- ac-name="" add-default-route=no dial-on-demand=no use-peer-dns=no \
- allow=pap,chap,mschap1,mschap2 disabled=no
- add name="pppoe-out3" max-mtu=1492 max-mru=1492 interface=wan3 \
- user="789" password="789" profile=default service-name="" \
- ac-name="" add-default-route=no dial-on-demand=no use-peer-dns=no \
- allow=pap,chap,mschap1,mschap2 disabled=no
- / ip pool
- add name="dhcp_pool1" ranges=192.168.0.10-192.168.0.21
- / ip telephony region
- / ip telephony gatekeeper
- set gatekeeper=none remote-id="" remote-address=0.0.0.0
- / ip telephony aaa
- set use-radius-accounting=no interim-update=0s
- / ip telephony codec
- move G.711-uLaw-64k/sw
- move G.711-ALaw-64k/sw
- move G.729A-8k/sw
- move G.729-8k/sw
- move G.723.1-6.3k/sw
- move GSM-06.10-13.2k/sw
- move LPC-10-2.5k/sw
- / ip accounting
- set enabled=yes account-local-traffic=yes threshold=256
- / ip accounting web-access
- set accessible-via-web=no address=0.0.0.0/0
- / ip service
- set telnet port=23 address=0.0.0.0/0 disabled=yes
- set ftp port=21 address=0.0.0.0/0 disabled=no
- set www port=80 address=0.0.0.0/0 disabled=no
- set ssh port=22 address=0.0.0.0/0 disabled=yes
- set www-ssl port=443 address=0.0.0.0/0 certificate=none disabled=yes
- / ip socks
- set enabled=no port=1080 connection-idle-timeout=2m max-connections=200
- / ip arp
- add address=192.168.0.134 mac-address=00:14:6C:73:64:93 interface=lan \
- comment="" disabled=no
- add address=192.168.0.112 mac-address=00:1E:2A:3F:4C:F7 interface=lan \
- comment="" disabled=no
- add address=192.168.0.141 mac-address=00:1E:2A:3F:3D:61 interface=lan \
- comment="" disabled=no
- add address=192.168.0.180 mac-address=00:1E:2A:3F:4C:CF interface=lan \
- comment="" disabled=no
- add address=192.168.0.206 mac-address=00:14:6C:8C:CA:7A interface=lan \
- comment="" disabled=no
- add address=192.168.0.101 mac-address=00:1E:2A:3F:4C:E5 interface=lan \
- comment="" disabled=no
- add address=192.168.0.181 mac-address=00:1E:2A:3F:3D:1B interface=lan \
- comment="" disabled=no
- add address=192.168.0.102 mac-address=00:1E:2A:3F:49:2E interface=lan \
- comment="" disabled=no
- add address=192.168.0.148 mac-address=00:14:6C:8C:0B:3E interface=lan \
- comment="" disabled=no
- add address=192.168.0.147 mac-address=00:1E:2A:39:50:C4 interface=lan \
- comment="" disabled=no
- add address=192.168.0.179 mac-address=00:1E:2A:3F:3A:92 interface=lan \
- comment="" disabled=no
- add address=192.168.0.131 mac-address=00:1E:2A:3F:4C:E4 interface=lan \
- comment="" disabled=no
- add address=192.168.0.10 mac-address=00:1D:60:79:29:81 interface=lan \
- comment="" disabled=no
- add address=192.168.0.133 mac-address=00:14:6C:CB:01:46 interface=lan \
- comment="" disabled=no
- add address=192.168.0.171 mac-address=00:14:6C:C4:AC:BC interface=lan \
- comment="" disabled=no
- add address=192.168.0.137 mac-address=00:1E:2A:3F:48:6F interface=lan \
- comment="" disabled=no
- add address=192.168.0.205 mac-address=00:1E:2A:39:4E:81 interface=lan \
- comment="" disabled=no
- add address=192.168.0.201 mac-address=00:14:6C:8B:B8:53 interface=lan \
- comment="" disabled=no
- add address=192.168.0.109 mac-address=00:1E:2A:3F:49:1A interface=lan \
- comment="" disabled=no
- add address=192.168.0.162 mac-address=00:1E:2A:39:50:AF interface=lan \
- comment="" disabled=no
- add address=192.168.0.150 mac-address=00:14:6C:86:9A:07 interface=lan \
- comment="" disabled=no
- add address=192.168.0.178 mac-address=00:14:6C:8A:4F:61 interface=lan \
- comment="" disabled=no
- add address=192.168.0.184 mac-address=00:14:6C:C4:AA:BE interface=lan \
- comment="" disabled=no
- add address=192.168.0.135 mac-address=00:1E:2A:3F:49:23 interface=lan \
- comment="" disabled=no
- add address=192.168.0.104 mac-address=00:1E:2A:3F:4A:E8 interface=lan \
- comment="" disabled=no
- add address=192.168.0.17 mac-address=00:13:CE:D4:66:E0 interface=lan \
- comment="" disabled=no
- add address=192.168.0.163 mac-address=00:1E:2A:39:50:92 interface=lan \
- comment="" disabled=no
- add address=192.168.0.164 mac-address=00:1E:2A:39:4F:18 interface=lan \
- comment="" disabled=no
- add address=192.168.0.166 mac-address=00:14:6C:74:B4:9A interface=lan \
- comment="" disabled=no
- add address=192.168.0.207 mac-address=00:1E:2A:3F:3A:9F interface=lan \
- comment="" disabled=no
- add address=192.168.0.139 mac-address=00:1E:2A:3F:49:32 interface=lan \
- comment="" disabled=no
- add address=192.168.0.117 mac-address=00:1E:2A:39:50:CB interface=lan \
- comment="" disabled=no
- add address=192.168.0.165 mac-address=00:14:6C:C4:CE:73 interface=lan \
- comment="" disabled=no
- add address=192.168.0.183 mac-address=00:1E:2A:3F:49:28 interface=lan \
- comment="" disabled=no
- add address=192.168.0.122 mac-address=00:1E:2A:39:50:C5 interface=lan \
- comment="" disabled=no
- add address=192.168.0.105 mac-address=00:1E:2A:3F:3A:95 interface=lan \
- comment="" disabled=no
- add address=192.168.0.152 mac-address=00:18:4D:70:4A:F5 interface=lan \
- comment="" disabled=no
- add address=192.168.0.211 mac-address=00:18:4D:70:54:CC interface=lan \
- comment="" disabled=no
- add address=192.168.0.169 mac-address=00:14:6C:74:EB:C9 interface=lan \
- comment="" disabled=no
- add address=218.30.64.199 mac-address=00:00:00:00:00:00 interface=lan \
- comment="" disabled=no
- add address=192.168.0.168 mac-address=00:1E:2A:39:4B:FA interface=lan \
- comment="" disabled=no
- add address=192.168.0.13 mac-address=00:14:A4:35:CB:97 interface=lan \
- comment="" disabled=no
- add address=192.168.0.116 mac-address=00:1E:2A:3F:4C:D0 interface=lan \
- comment="" disabled=no
- add address=192.168.0.210 mac-address=00:1E:2A:39:50:CC interface=lan \
- comment="" disabled=no
- add address=192.168.0.172 mac-address=00:14:6C:8C:58:3E interface=lan \
- comment="" disabled=no
- add address=192.168.0.151 mac-address=00:1E:2A:3F:49:18 interface=lan \
- comment="" disabled=no
- add address=192.168.0.175 mac-address=00:1E:2A:3F:49:28 interface=lan \
- comment="" disabled=no
- add address=192.168.0.155 mac-address=00:1E:2A:39:4F:0C interface=lan \
- comment="" disabled=no
- add address=192.168.0.106 mac-address=00:1E:2A:3F:49:30 interface=lan \
- comment="" disabled=no
- add address=192.168.0.115 mac-address=00:1E:2A:3F:3A:E3 interface=lan \
- comment="" disabled=no
- / ip upnp
- set enabled=no allow-disable-external-interface=yes show-dummy-rule=yes
- / ip traffic-flow
- set enabled=no interfaces=all cache-entries=4k active-flow-timeout=30m \
- inactive-flow-timeout=15s
- / ip dns
- set primary-dns=202.100.96.68 secondary-dns=222.75.152.129 \
- allow-remote-requests=yes cache-size=2048KiB cache-max-ttl=1d3h46m40s
- / ip address
- add address=192.168.0.1/24 network=192.168.0.0 broadcast=192.168.0.255 \
- interface=lan comment="lan" disabled=no
- add address=222.75.55.145/32 network=222.75.55.145 broadcast=222.75.55.145 \
- interface=pppoe-out1 comment="adsl1" disabled=no
- add address=124.224.53.212/32 network=124.224.53.212 broadcast=124.224.53.212 \
- interface=pppoe-out2 comment="adsl2" disabled=no
- add address=222.75.55.157/32 network=222.75.55.157 broadcast=222.75.55.157 \
- interface=pppoe-out3 comment="adsl3" disabled=no
- / ip proxy
- set enabled=no ports=8080 parent-proxy=0.0.0.0:0 \
- maximal-client-connecions=1000 maximal-server-connectons=1000 \
- cache-administrator="webmaster" max-object-size=4096KiB \
- max-disk-cache-size=none max-ram-cache-size=unlimited disk-database=yes
- / ip proxy drive
- set
- / ip proxy access
- add dst-port=23-25 action=deny comment="block telnet & spam e-mail relaying" \
- disabled=no
- add method=CONNECT dst-port=443 action=allow comment="allow CONNECT only to \
- SSL ports 443 \[https\] and 563 \[snews\]" disabled=no
- add method=CONNECT dst-port=563 action=allow comment="allow CONNECT only to \
- SSL ports 443 \[https\] and 563 \[snews\]" disabled=no
- add method=CONNECT action=deny comment="allow CONNECT only to SSL ports 443 \
- \[https\] and 563 \[snews\]" disabled=no
- / ip neighbor discovery
- set lan discover=yes
- set wan2 discover=yes
- set wan3 discover=yes
- set wan1 discover=yes
- set pppoe-out1 discover=no
- set pppoe-out2 discover=no
- set pppoe-out3 discover=no
- / ip route
- add dst-address=0.0.0.0/0 gateway=222.75.55.145 check-gateway=ping scope=255 \
- target-scope=10 routing-mark=adsl1 comment="adsl1" disabled=no
- add dst-address=0.0.0.0/0 gateway=124.224.53.212 check-gateway=ping scope=255 \
- target-scope=10 routing-mark=adsl2 comment="adsl2" disabled=no
- add dst-address=0.0.0.0/0 gateway=222.75.55.157 check-gateway=ping scope=255 \
- target-scope=10 routing-mark=adsl3 comment="adsl3" disabled=no
- / ip firewall mangle
- add chain=prerouting src-address=192.168.0.10-192.168.0.21 action=mark-routing \
- new-routing-mark=adsl1 passthrough=yes comment="" disabled=no
- add chain=prerouting src-address=192.168.0.100-192.168.0.139 \
- action=mark-routing new-routing-mark=adsl1 passthrough=yes comment="" \
- disabled=no
- add chain=prerouting src-address=192.168.0.140-192.168.0.179 \
- action=mark-routing new-routing-mark=adsl2 passthrough=yes comment="" \
- disabled=no
- add chain=prerouting src-address=192.168.0.180-192.168.0.220 \
- action=mark-routing new-routing-mark=adsl3 passthrough=yes comment="" \
- disabled=no
- add chain=prerouting action=mark-packet new-packet-mark=all_mark \
- passthrough=yes comment="" disabled=no
- / ip firewall nat
- add chain=srcnat action=masquerade comment="" disabled=no
- / ip firewall connection tracking
- set enabled=yes tcp-syn-sent-timeout=2m30s tcp-syn-received-timeout=2m30s \
- tcp-established-timeout=10h tcp-fin-wait-timeout=2m30s \
- tcp-close-wait-timeout=2m30s tcp-last-ack-timeout=2m30s \
- tcp-time-wait-timeout=2m30s tcp-close-timeout=30s udp-timeout=2m30s \
- udp-stream-timeout=6m icmp-timeout=2m30s generic-timeout=20m
- / ip firewall filter
- add chain=input connection-state=invalid action=drop \
- comment="丢弃非法连接数据" disabled=yes
- add chain=input protocol=tcp dst-port=80 connection-limit=20,0 action=drop \
- comment="限制总http连接数为20" disabled=yes
- add chain=input protocol=tcp psd=21,3s,3,1 action=drop \
- comment="探测并丢弃端口扫描连接" disabled=yes
- add chain=input protocol=tcp connection-limit=3,32 src-address-list=black_list \
- action=tarpit comment="压制DoS攻击" disabled=yes
- add chain=input protocol=tcp connection-limit=10,32 \
- action=add-src-to-address-list address-list=black_list \
- address-list-timeout=1d comment="探测DoS攻击" disabled=yes
- add chain=input dst-address-type=!local action=drop comment="丢弃掉非本地数据" \
- disabled=yes
- add chain=input protocol=icmp action=jump jump-target=ICMP \
- comment="跳转到ICMP链表" disabled=no
- add chain=ICMP protocol=icmp icmp-options=0:0-255 limit=5,5 action=accept \
- comment="Ping应答限制为每秒5个包" disabled=no
- add chain=ICMP protocol=icmp icmp-options=3:3 limit=5,5 action=accept \
- comment="Traceroute限制为每秒5个包" disabled=no
- add chain=ICMP protocol=icmp icmp-options=3:4 limit=5,5 action=accept \
- comment="MTU线路探测限制为每秒5个包" disabled=no
- add chain=ICMP protocol=icmp icmp-options=8:0-255 limit=5,5 action=accept \
- comment="Ping请求限制为每秒5个包" disabled=no
- add chain=ICMP protocol=icmp icmp-options=11:0-255 limit=5,5 action=accept \
- comment="Trace TTL限制为每秒5个包" disabled=no
- add chain=ICMP protocol=icmp action=drop comment="丢弃掉任何ICMP数据" \
- disabled=no
- add chain=forward connection-state=invalid action=drop \
- comment="丢弃非法数据包" disabled=yes
- add chain=forward protocol=tcp connection-limit=80,32 action=drop \
- comment="限制每个主机TCP连接数为80条" disabled=yes
- add chain=forward src-address-type=!unicast action=drop \
- comment="丢弃掉所有非单播数据" disabled=yes
- add chain=forward content=.exe action=drop comment="禁止.exe文件通过" \
- disabled=yes
- add chain=forward content=.dll action=drop comment="禁止.dll文件通过" \
- disabled=yes
- add chain=forward protocol=icmp action=jump jump-target=ICMP \
- comment="跳转到ICMP链表" disabled=no
- add chain=forward action=jump jump-target=virus comment="跳转到病毒链表" \
- disabled=no
- add chain=virus protocol=tcp dst-port=41 action=drop \
- comment="DeepThroat.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=82 action=drop \
- comment="Worm.NetSky.Y@mm" disabled=no
- add chain=virus protocol=tcp dst-port=113 action=drop \
- comment="W32.Korgo.A/B/C/D/E/F-1" disabled=no
- add chain=virus protocol=tcp dst-port=2041 action=drop \
- comment="W33.Korgo.A/B/C/D/E/F-2" disabled=no
- add chain=virus protocol=tcp dst-port=3150 action=drop \
- comment="DeepThroat.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=3067 action=drop \
- comment="W32.Korgo.A/B/C/D/E/F-3" disabled=no
- add chain=virus protocol=tcp dst-port=3422 action=drop \
- comment="Backdoor.IRC.Aladdinz.R-1" disabled=no
- add chain=virus protocol=tcp dst-port=6667 action=drop \
- comment="W32.Korgo.A/B/C/D/E/F-4" disabled=no
- add chain=virus protocol=tcp dst-port=6789 action=drop \
- comment="Worm.NetSky.S/T/U@mm" disabled=no
- add chain=virus protocol=tcp dst-port=8787 action=drop \
- comment="Back.Orifice.2000.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=8879 action=drop \
- comment="Back.Orifice.2000.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=8967 action=drop \
- comment="W32.Dabber.A/B-2" disabled=no
- add chain=virus protocol=tcp dst-port=9999 action=drop \
- comment="W32.Dabber.A/B-3" disabled=no
- add chain=virus protocol=tcp dst-port=20034 action=drop \
- comment="Block.NetBus.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=21554 action=drop \
- comment="GirlFriend.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=31666 action=drop \
- comment="Back.Orifice.2000.Trojan-3" disabled=no
- add chain=virus protocol=tcp dst-port=43958 action=drop \
- comment="Backdoor.IRC.Aladdinz.R-2" disabled=no
- add chain=virus protocol=tcp dst-port=999 action=drop \
- comment="DeepThroat.Trojan-3" disabled=no
- add chain=virus protocol=tcp dst-port=6670 action=drop \
- comment="DeepThroat.Trojan-4" disabled=no
- add chain=virus protocol=tcp dst-port=6771 action=drop \
- comment="DeepThroat.Trojan-5" disabled=no
- add chain=virus protocol=tcp dst-port=60000 action=drop \
- comment="DeepThroat.Trojan-6" disabled=no
- add chain=virus protocol=tcp dst-port=2140 action=drop \
- comment="DeepThroat.Trojan-7" disabled=no
- add chain=virus protocol=tcp dst-port=10067 action=drop \
- comment="Portal.of.Doom.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=10167 action=drop \
- comment="Portal.of.Doom.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=3700 action=drop \
- comment="Portal.of.Doom.Trojan-3" disabled=no
- add chain=virus protocol=tcp dst-port=9872-9875 action=drop \
- comment="Portal.of.Doom.Trojan-4" disabled=no
- add chain=virus protocol=tcp dst-port=6883 action=drop \
- comment="Delta.Source.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=26274 action=drop \
- comment="Delta.Source.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=4444 action=drop \
- comment="Delta.Source.Trojan-3" disabled=no
- add chain=virus protocol=tcp dst-port=47262 action=drop \
- comment="Delta.Source.Trojan-4" disabled=no
- add chain=virus protocol=tcp dst-port=3791 action=drop \
- comment="Eclypse.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=3801 action=drop \
- comment="Eclypse.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=65390 action=drop \
- comment="Eclypse.Trojan-3" disabled=no
- add chain=virus protocol=tcp dst-port=5880-5882 action=drop \
- comment="Y3K.RAT.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=5888-5889 action=drop \
- comment="Y3K.RAT.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=30100-30103 action=drop \
- comment="NetSphere.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=30133 action=drop \
- comment="NetSphere.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=7300-7301 action=drop \
- comment="NetMonitor.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=7306-7308 action=drop \
- comment="NetMonitor.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=79 action=drop \
- comment="FireHotcker.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=5031 action=drop \
- comment="FireHotcker.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=5321 action=drop \
- comment="FireHotcker.Trojan-3" disabled=no
- add chain=virus protocol=tcp dst-port=6400 action=drop \
- comment="TheThing.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=7777 action=drop \
- comment="TheThing.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=1047 action=drop \
- comment="GateCrasher.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=6969-6970 action=drop \
- comment="GateCrasher.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=2774 action=drop comment="SubSeven-1" \
- disabled=no
- add chain=virus protocol=tcp dst-port=27374 action=drop comment="SubSeven-2" \
- disabled=no
- add chain=virus protocol=tcp dst-port=1243 action=drop comment="SubSeven-3" \
- disabled=no
- add chain=virus protocol=tcp dst-port=1234 action=drop comment="SubSeven-4" \
- disabled=no
- add chain=virus protocol=tcp dst-port=6711-6713 action=drop \
- comment="SubSeven-5" disabled=no
- add chain=virus protocol=tcp dst-port=16959 action=drop comment="SubSeven-7" \
- disabled=no
- add chain=virus protocol=tcp dst-port=25685-25686 action=drop \
- comment="Moonpie.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=25982 action=drop \
- comment="Moonpie.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=31337-31339 action=drop \
- comment="NetSpy.Trojan-3" disabled=no
- add chain=virus protocol=tcp dst-port=8102 action=drop comment="Trojan" \
- disabled=no
- add chain=virus protocol=tcp dst-port=8011 action=drop comment="WAY.Trojan" \
- disabled=no
- add chain=virus protocol=tcp dst-port=7626 action=drop comment="Trojan.BingHe" \
- disabled=no
- add chain=virus protocol=tcp dst-port=19191 action=drop \
- comment="Trojan.NianSeHoYian" disabled=no
- add chain=virus protocol=tcp dst-port=23444-23445 action=drop \
- comment="NetBull.Trojan" disabled=no
- add chain=virus protocol=tcp dst-port=2583 action=drop \
- comment="WinCrash.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=3024 action=drop \
- comment="WinCrash.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=4092 action=drop \
- comment="WinCrash.Trojan-3" disabled=no
- add chain=virus protocol=tcp dst-port=5714 action=drop \
- comment="WinCrash.Trojan-4" disabled=no
- add chain=virus protocol=tcp dst-port=1010-1012 action=drop \
- comment="Doly1.0/1.35/1.5trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=1015 action=drop \
- comment="Doly1.0/1.35/1.5trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=2004-2005 action=drop \
- comment="TransScout.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=9878 action=drop \
- comment="TransScout.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=2773 action=drop \
- comment="Backdoor.YAI..Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=7215 action=drop \
- comment="Backdoor.YAI.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=54283 action=drop \
- comment="Backdoor.YAI.Trojan-3" disabled=no
- add chain=virus protocol=tcp dst-port=1003 action=drop \
- comment="BackDoorTrojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=5598 action=drop \
- comment="BackDoorTrojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=5698 action=drop \
- comment="BackDoorTrojan-3" disabled=no
- add chain=virus protocol=tcp dst-port=31554 action=drop \
- comment="SchainwindlerTrojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=18753 action=drop \
- comment="Shaft.DDoS.Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=20432 action=drop \
- comment="Shaft.DDoS.Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=65000 action=drop \
- comment="Devil.DDoS.Trojan" disabled=no
- add chain=virus protocol=tcp dst-port=11831 action=drop \
- comment="LatinusTrojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=29559 action=drop \
- comment="LatinusTrojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=1784 action=drop \
- comment="Snid.X2Trojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=3586 action=drop \
- comment="Snid.X2Trojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=7609 action=drop \
- comment="Snid.X2Trojan-3" disabled=no
- add chain=virus protocol=tcp dst-port=12348-12349 action=drop \
- comment="BionetTrojan-1" disabled=no
- add chain=virus protocol=tcp dst-port=12478 action=drop \
- comment="BionetTrojan-2" disabled=no
- add chain=virus protocol=tcp dst-port=57922 action=drop \
- comment="BionetTrojan-3" disabled=no
- add chain=virus protocol=tcp dst-port=3127 action=drop \
- comment="Worm.Novarg.a.Mydoom.a1." disabled=no
- add chain=virus protocol=tcp dst-port=6777 action=drop \
- comment="Worm.BBeagle.a.Bagle.a." disabled=no
- add chain=virus protocol=tcp dst-port=8866 action=drop \
- comment="Worm.BBeagle.b" disabled=no
- add chain=virus protocol=tcp dst-port=2745 action=drop \
- comment="Worm.BBeagle.c-g/j-l" disabled=no
- add chain=virus protocol=tcp dst-port=2556 action=drop \
- comment="Worm.BBeagle.p/q/r/n" disabled=no
- add chain=virus protocol=tcp dst-port=20742 action=drop \
- comment="Worm.BBEagle.m-2" disabled=no
- add chain=virus protocol=tcp dst-port=4751 action=drop \
- comment="Worm.BBeagle.s/t/u/v" disabled=no
- add chain=virus protocol=tcp dst-port=2535 action=drop \
- comment="Worm.BBeagle.aa/ab/w/x-z-2" disabled=no
- add chain=virus protocol=tcp dst-port=5238 action=drop \
- comment="Worm.LovGate.r.RpcExploit" disabled=no
- add chain=virus protocol=tcp dst-port=1068 action=drop comment="Worm.Sasser.a" \
- disabled=no
- add chain=virus protocol=tcp dst-port=5554 action=drop \
- comment="Worm.Sasser.b/c/f" disabled=no
- add chain=virus protocol=tcp dst-port=9996 action=drop \
- comment="Worm.Sasser.b/c/f" disabled=no
- add chain=virus protocol=tcp dst-port=9995 action=drop comment="Worm.Sasser.d" \
- disabled=no
- add chain=virus protocol=tcp dst-port=10168 action=drop \
- comment="Worm.Lovgate.a/b/c/d" disabled=no
- add chain=virus protocol=tcp dst-port=20808 action=drop \
- comment="Worm.Lovgate.v.QQ" disabled=no
- add chain=virus protocol=tcp dst-port=1092 action=drop \
- comment="Worm.Lovgate.f/g" disabled=no
- add chain=virus protocol=tcp dst-port=20168 action=drop \
- comment="Worm.Lovgate.f/g" disabled=no
- add chain=virus protocol=tcp dst-port=1363-1364 action=drop \
- comment="ndm.requester" disabled=no
- add chain=virus protocol=tcp dst-port=1368 action=drop comment="screen.cast" \
- disabled=no
- add chain=virus protocol=tcp dst-port=1373 action=drop comment="hromgrafx" \
- disabled=no
- add chain=virus protocol=tcp dst-port=1377 action=drop comment="cichainlid" \
- disabled=no
- add chain=virus protocol=tcp dst-port=3410 action=drop \
- comment="Backdoor.Optixprotocol" disabled=no
- add chain=virus protocol=tcp dst-port=8888 action=drop \
- comment="Worm.BBeagle.b" disabled=no
- add chain=virus protocol=udp dst-port=44444 action=drop \
- comment="Delta.Source.Trojan-7" disabled=no
- add chain=virus protocol=udp dst-port=8998 action=drop \
- comment="Worm.Sobig.f-3" disabled=no
- add chain=virus protocol=udp dst-port=123 action=drop comment="Worm.Sobig.f-1" \
- disabled=no
- add chain=virus protocol=tcp dst-port=3198 action=drop \
- comment="Worm.Novarg.a.Mydoom.a2." disabled=no
- add chain=virus protocol=tcp dst-port=139 action=drop comment="Drop Blaster \
- Worm" disabled=no
- add chain=virus protocol=tcp dst-port=135 action=drop comment="Drop Blaster \
- Worm" disabled=no
- add chain=virus protocol=tcp dst-port=445 action=drop comment="Drop Blaster \
- Worm" disabled=no
- add chain=forward action=accept comment="接受所有数据" disabled=no
- add chain=input action=jump jump-target=virus comment="跳转到病毒链表" \
- disabled=no
- add chain=output action=jump jump-target=virus comment="跳转到病毒链表" \
- disabled=no
- add chain=output protocol=icmp action=jump jump-target=ICMP \
- comment="跳转到ICMP链表" disabled=no
- / ip firewall service-port
- set ftp ports=21 disabled=no
- set tftp ports=69 disabled=no
- set irc ports=6667 disabled=no
- set h323 disabled=yes
- set quake3 disabled=no
- set mms disabled=no
- set gre disabled=yes
- set pptp disabled=yes
- / ip dhcp-server
- add name="dhcp1" interface=lan lease-time=3d address-pool=dhcp_pool1 \
- bootp-support=static disabled=no
- / ip dhcp-server config
- set store-leases-disk=5m
- / ip dhcp-server lease
- / ip dhcp-server network
- add address=192.168.0.0/24 gateway=192.168.0.1 \
- dns-server=192.168.0.1,202.100.96.68,222.75.152.129 comment=""
- / ip hotspot service-port
- set ftp ports=21 disabled=no
- / ip hotspot profile
- set default name="default" hotspot-address=0.0.0.0 dns-name="" \
- html-directory=hotspot rate-limit="" http-proxy=0.0.0.0:0 \
- smtp-server=0.0.0.0 login-by=cookie,http-chap http-cookie-lifetime=3d \
- split-user-domain=no use-radius=no
- / ip hotspot user profile
- set default name="default" idle-timeout=none keepalive-timeout=2m \
- status-autorefresh=1m shared-users=1 transparent-proxy=yes \
- open-status-page=always advertise=no
- / ip ipsec proposal
- add name="default" auth-algorithms=sha1 enc-algorithms=3des lifetime=30m \
- lifebytes=0 pfs-group=modp1024 disabled=no
- / system logging
- add topics=info prefix="" action=memory disabled=no
- add topics=error prefix="" action=memory disabled=no
- add topics=warning prefix="" action=memory disabled=no
- add topics=critical prefix="" action=echo disabled=no
- / system logging action
- set memory name="memory" target=memory memory-lines=100 memory-stop-on-full=no
- set disk name="disk" target=disk disk-lines=100 disk-stop-on-full=no
- set echo name="echo" target=echo remember=yes
- set remote name="remote" target=remote remote=0.0.0.0:514
- / system script
- add name="script1" source=":foreach i in=\[/ip arp find dynamic=yes \] \
- do=\[/ip arp add copy-from=\$i\]" \
- policy=ftp,reboot,read,write,policy,test,winbox,password
- / system upgrade mirror
- set enabled=no primary-server=0.0.0.0 secondary-server=0.0.0.0 \
- check-interval=1d user=""
- / system clock dst
- set dst-delta=+01:00 dst-start="jan/01/1970 00:00:00" dst-end="jan/01/1970 \
- 00:00:00"
- / system watchdog
- set reboot-on-failure=yes watch-address=none watchdog-timer=yes \
- no-ping-delay=5m automatic-supout=yes auto-send-supout=no
- / system console
- add port=serial0 term="" disabled=no
- set FIXME term="linux" disabled=no
- set FIXME term="linux" disabled=no
- set FIXME term="linux" disabled=no
- set FIXME term="linux" disabled=no
- set FIXME term="linux" disabled=no
- set FIXME term="linux" disabled=no
- set FIXME term="linux" disabled=no
- set FIXME term="linux" disabled=no
- / system console screen
- set line-count=25
- / system identity
- set name="FuYuanJiuDian"
- / system note
- set show-at-login=yes note=""
- / system scheduler
- add name="schedule1" on-event=":local assign-address
- \n:local \
- new-address
- \n:local status
- \n:local x
- \n:set x 3
- \n:for i from=1 to=\$x \
- do={
- \n:set status \[/interface get \[/interface find name=("pppoe-out" \
- . \$i)\] running\]
- \n:if (\$status=true) do={
- \n:set new-address \[/ip \
- address get \[/ip address find dynamic=yes interface=("pppoe-out" . \
- \$i)\] address\]
- \n:set new-address \[:pick \$new-address 0 \[:find \
- \$new-address "/"\]\]
- \n:set assign-address \[/ip address get \[/ip \
- address find dynamic=no interface=("pppoe-out" . \$i)\] address\]
- \n:set \
- assign-address \[:pick \$assign-address 0 \[:find \$assign-address \
- "/"\]\]
- \n:if (\$assign-address != \$new-address) do={
- \n/ip address set \
- \[/ip address find comment=("adsl" . \$i)\] address=\$new-address \
- network=\$new-address broadcast=\$new-address
- \n/ip route set \[/ip route \
- find comment=("adsl" . \$i)\] gateway=\$new-address
- \n}
- \n}
- \n}" \
- start-date=jan/01/1970 start-time=00:00:00 interval=30s comment="自动改IP" \
- disabled=no
- / system gps
- set enabled=no set-system-time=no
- / system lcd
- set enabled=no type=24x4 port=parallel contrast=0
- / system lcd page
- set time display-time=5s disabled=yes
- set resources display-time=5s disabled=yes
- set uptime display-time=5s disabled=yes
- set packets display-time=5s disabled=yes
- set bits display-time=5s disabled=yes
- set version display-time=5s disabled=yes
- set pppoe-out2 display-time=5s disabled=yes
- set pppoe-out3 display-time=5s disabled=yes
- set lan display-time=5s disabled=yes
- set wan1 display-time=5s disabled=yes
- set wan2 display-time=5s disabled=yes
- set wan3 display-time=5s disabled=yes
- set pppoe-out1 display-time=5s disabled=yes
- / system ntp server
- set enabled=no broadcast=no multicast=no manycast=yes
- / system ntp client
- set enabled=no mode=unicast primary-ntp=0.0.0.0 secondary-ntp=0.0.0.0
- / system routerboard bios
- set
- / system health
- set state-after-reboot=enabled
- / port
- set serial0 name="serial0" baud-rate=9600 data-bits=8 parity=none stop-bits=1 \
- flow-control=hardware
- set serial1 name="serial1" baud-rate=9600 data-bits=8 parity=none stop-bits=1 \
- flow-control=hardware
- / ppp profile
- set default name="default" use-compression=default use-vj-compression=default \
- use-encryption=default only-one=default change-tcp-mss=default comment=""
- set default-encryption name="default-encryption" use-compression=default \
- use-vj-compression=default use-encryption=yes only-one=default \
- change-tcp-mss=default comment=""
- / ppp aaa
- set use-radius=no accounting=yes interim-update=0s
- / queue type
- set default name="default" kind=pfifo pfifo-limit=50
- set ethernet-default name="ethernet-default" kind=pfifo pfifo-limit=50
- set wireless-default name="wireless-default" kind=sfq sfq-perturb=5 \
- sfq-allot=1514
- set synchronous-default name="synchronous-default" kind=red red-limit=60 \
- red-min-threshold=10 red-max-threshold=50 red-burst=20 red-avg-packet=1000
- set hotspot-default name="hotspot-default" kind=sfq sfq-perturb=5 \
- sfq-allot=1514
- add name="pcq-down" kind=pcq pcq-rate=1000000 pcq-limit=50 \
- pcq-classifier=dst-address pcq-total-limit=2000
- add name="pcq-up" kind=pcq pcq-rate=128000 pcq-limit=50 \
- pcq-classifier=src-address pcq-total-limit=2000
- / queue tree
- add name="pcqdown" parent=global-in packet-mark=all_mark limit-at=0 \
- queue=pcq-down priority=8 max-limit=0 burst-limit=0 burst-threshold=0 \
- burst-time=0s disabled=yes
- add name="pcqup" parent=global-out packet-mark=all_mark limit-at=0 \
- queue=pcq-up priority=8 max-limit=0 burst-limit=0 burst-threshold=0 \
- burst-time=0s disabled=yes
- / user
- add name="mark" group=full address=0.0.0.0/0 comment="system default user" \
- disabled=no
- / user group
- add name="read" policy=local,telnet,ssh,reboot,read,test,winbox,password,web,!f\
- tp,!write,!policy
- add name="write" policy=local,telnet,ssh,reboot,read,write,test,winbox,password\
- ,web,!ftp,!policy
- add name="full" policy=local,telnet,ssh,ftp,reboot,read,write,policy,test,winbo\
- x,password,web
- / user aaa
- set use-radius=no accounting=yes interim-update=0s default-group=read
- / radius incoming
- set accept=no port=1700
- / driver
- / snmp
- set enabled=no contact="" location=""
- / snmp community
- set public name="public" address=0.0.0.0/0 read-access=yes
- / tool bandwidth-server
- set enabled=yes authenticate=yes allocate-udp-ports-from=2000 max-sessions=10
- / tool mac-server ping
- set enabled=yes
- / tool e-mail
- set server=0.0.0.0 from="<>"
- / tool sniffer
- set interface=all only-headers=no memory-limit=10 file-name="" file-limit=10 \
- streaming-enabled=no streaming-server=0.0.0.0 filter-stream=yes \
- filter-protocol=ip-only filter-address1=0.0.0.0/0:0-65535 \
- filter-address2=0.0.0.0/0:0-65535
- / tool graphing
- set store-every=5min
- / tool graphing interface
- add interface=all allow-address=0.0.0.0/0 store-on-disk=yes disabled=no
复制代码 |
|