You are on page 1of 41

Routeros 的安装和电信/网通双线光纤,策略路由/双线分流/双线备份,全局速度限

制,线程限制,DHCP 服务器,PPPOE 服务器和 VPN,Hossport 设置 WEB 认

证上网方式,防火墙,图文教程 本人 QQ:157357366

注意因为网上有很多现成的图片教程,但是真真假假,版本不明,所以我这个集合

教程里有很多图片不是原创,并且这里所有技术全部可以使用在 2.9 以上版本的

ROS 上。。虽然里面整理的不全部是原创,但是经过我的整理以及一些地方的衔接

修改,现在这些东西变得简单易懂了。只要稍微动动脑,这些功能你都能实现,而

且几乎这些功能对你都有用处。呵呵,说了这么多废话,意思大概就是只要你认真

按着我的这个教程去做,那就一定会打造出属于你自己的路由器的。

RouterOS 的安装和破解:
软件的安装:
a. 在 BIOS 中设置从光盘启动计算机。
b. 使用光盘启动计算机时,会出现下面的界面:让你选择安装的模块,呵呵,我选择全部
安 装 , 键 盘 输 入 a , 然 后 输 入 i 开 始 安 装 。

计算机提醒你是不是要保留以前的设置,我是全新安装的,我按n回车,不保留。然后计算
机提示继续否,废话,不继续干嘛,按y继续。计算机开始安装了。
你就等着安装完成出现让你按回车键继续的画面,计算机重新启动后就行了。

由于我安装的是破解的系统,所以计算机重新启动之后就没有要求我输入什么许可证之类的。
若你下载的是需要破解的系统,请自己找资料破解,嘿嘿!

在字符界面下,系统的简单初始设置:系统安装之后重新启动,然后出现登陆界面,
输入初始用户名 admin,口令直接回车。进入 RouterOS 的字符界面,好了,现在开始我们的简
单初始设置阶段。
1、 更改网卡的名称以方便区分不同的网络接口。为方便区分我们作如下规定:接入互联网的
网络接口命名为 Wan,其接入互联网的方式是通过 dhcp 客户端动态获取 IP 地址。接入局域网
的互联网接口我们命名为 Lan,网卡的 IP 地址我们规定为 192.168.0.254。另外,我们设定内
部网络的地址是 192.168.0.0,网络掩码为 255.255.255.0(也就是/24),网关地址为 0.0.0.0
(特别提示,这里一定要设定为 0.0.0.0,有的教程中把这里设定为 192.168.0.254,甚至于
有的教程里把 Lan 的地址设定为 192.168.0.1 之后还把网关设定为 192.168.0.254,我认为这
些设定都是不对的。因为我按照那些教程里设定之后局域网无法共享上网)。
命令执行过程和显示界面如下:
输入:int 进入网卡的设置界面,

然后输入 print 查看网卡是否启用

(备注:默认是启用的,标志是网卡名字前面显示 R,比如我的网卡 ether1 前面显示 R。若没


有启动,则显示 X。若没有启用网卡,则输入命令 en 0 和 en 1)。
输入如下命令更改网卡的名称
en 0
en 1
set 0 name=Lan
set 1 name=Wan
输入/
退回到根目录,设定网卡地址等信息。
输入 setup

我们开始设定服务器网卡的信息,输入 a 出现如下界面
在 输 入 一 个 a 系 统 让 你 设 定 网 卡 的 ip 地 址 , 我 们 要 设 定 局 域 网 接 口 Lan 的 地 址 ,

(备注,若这里出现的不是 Lan,而是 Wan,你需要把它改成 Lan)


输入我们设定的 Lan 的 IP 地址 192.168.0.254/24
系统然后让你输入网关的地址,千万要注意不要输入默认的地址,而是要改为 0.0.0.0,特别提
醒你哇。

设定完成之后,我们输入 x 退出局域网网卡的设定。
好了,局域网网卡我们设定成功了,我们终于在一次输入 x 来退出这个字符界面了,下一步我们
将通过 windows 下的 winbox 来设定 RouterOS。

进入 winbox 界面。
在 局 域 网 的 另 外 一 台 安 装 有 windows 的 计 算 机 上 , 设 定 其 ip 地 址 为 192.168.0.1-
192.168.0.253 中的任意一个就行,然后掩码输入 255.255.255.0,网关设定为 192.168.0.254。
比如我在另外的一台安装有 windows XP 的计算机上设定如下图:

设定完成之后,就可以打开 IE 浏览器,在地址栏中输入 http://192.168.0.254 来访问我们的


RouterOS 服务器了。(备注:若你的计算机无法访问 192.168.0.254,则首先请你检查 RouterOS
服务器上接局域网的那根网线是否接到了 Wan 口上了。若接线正确则请你检查网络的物理连接以
及 windows 操作系统的网络设置等等,网络连接问题不是本文重点,若存在这个问题请你上网查
资料来解决)。

我们点击 Winbox 的图标来下载 winbox.exe 程序,然后运行这个程序

在 connect to 中输入我们的 RouterOS 服务器的地址 192.168.0.254,用户名中输入 admin,我


们没有设定密码,所以密码不输入,为了便于以后进入服务器,我们按 save 按钮保存此次设置。
如下图

然后我们点击 connect 按钮,登陆我们的 RouterOS 系统。

好了,从今往后,我们基本都在这个 winbox 模式下对 routeros 进行操作了。


点击 WINBOX 里的第一项 Interfaces 在弹出画面里 修改网卡名称,分别给三张网

卡命名,便于区分传输介质。

设定公网网络接口 Wan。
依次点击 ip/address, 按“+”号,在 interface 中选择公网接口 Wan,输入公网地址,广播地址
等信息,然后 apply,接着 OK 就行了。其他的上网方式请上网找资料进行设置)。
做 MASQ 伪装 设定局域网共享上网。
在 winbox 下,依次点击 ip /firewall /nat/ ,选择 + 号,chain 中选择 srcnat,在 action,
action 里面选择 masquerade ,其余选择默认即可,然后 apply,接着 OK 就行了。至此,局域网
可以共享上网了。

做双线有 3 种方法,最早的方法就是添加路由表,策略效率较低。此方法是最简单的,还有一种
方法是利用地址列表做 MANGLE 标记。
做双线备份另外种方法,最简单的就是利用 Distance 的优先级来做,选择 PING 检

测,主线优先级高于备份路由的优先级,当主线 DOWN 掉就会显示蓝色失效状态,

备份的路由规则就自然生效接替使用。不需要脚本就完成自动切换。
下面讲讲双线分流的做法。双线分流一般都是同 ISP 的几条线路达到减轻单线带宽

不足的情况。下面是最基本的就是平均分配 100 台机器,50 台走一条线。更好的做

法可以做到光纤玩游戏,ADSL 线路可做分流 QQ,WEB 等,具体做法就是在目标

端口上填写 QQ 是 8000 端口,UDP 协议,WEB 当然是 80 端口了。都是很灵活的。


下面是 网通 CNC 的路由表,以电信为主线

/ ip route rule
add dst-address=58.14.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=58.16.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=58.17.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=58.18.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=58.21.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=58.30.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=58.42.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=58.43.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=58.44.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=58.58.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=58.59.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=58.60.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=58.87.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=58.100.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=58.116.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=58.128.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=58.144.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=58.192.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=58.194.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=58.196.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=58.200.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=58.240.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=58.242.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=58.244.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=58.248.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=59.51.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=59.51.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=59.64.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=59.68.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=59.72.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=59.74.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=59.76.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=59.77.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=59.78.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=59.108.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=59.192.0.0/10 action=lookup table=wangtong comment="" disable=no
add dst-address=60.0.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=60.8.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=60.10.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=60.11.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=60.12.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=60.13.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=60.13.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=60.14.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=60.16.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=60.24.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=60.28.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=60.30.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=60.31.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=60.200.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=60.204.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=60.208.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=60.216.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=60.218.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=60.220.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=60.232.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=60.255.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=61.45.128.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=61.48.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=61.133.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=61.134.96.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=61.134.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=61.135.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=61.136.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=61.137.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=61.138.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=61.138.128.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=61.139.128.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=61.148.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=61.156.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=61.158.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=61.159.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=61.161.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=61.161.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=61.162.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=61.163.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=61.167.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=61.168.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=61.176.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=61.179.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=61.180.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=61.181.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=61.182.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=61.189.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=125.32.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=125.80.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=125.88.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=134.196.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=162.105.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=166.111.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=192.83.122.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=192.83.169.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=192.124.154.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=192.188.170.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=198.17.7.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.0.110.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.0.160.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.0.176.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.3.77.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.4.128.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.4.252.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.14.88.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.14.235.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.14.236.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.14.238.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.20.120.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.0.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.2.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.4.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.8.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.64.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.96.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.130.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.135.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.136.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.137.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.138.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.140.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.142.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.143.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.144.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.146.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.149.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.150.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.152.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.154.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.156.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.158.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.160.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.164.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.168.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.169.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.170.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.171.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.172.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.173.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.175.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.184.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.38.192.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.41.152.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.43.144.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.46.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.46.224.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.60.112.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.63.248.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.70.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.75.208.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.90.0.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.90.224.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.90.252.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.91.0.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.91.128.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.92.0.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.92.252.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.94.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.95.0.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.95.4.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.95.8.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.95.16.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.95.252.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.96.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.96.64.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.96.72.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.96.80.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.97.96.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.97.112.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.97.128.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.97.192.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.97.224.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.97.232.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.97.240.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.98.0.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.98.8.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.98.16.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.64.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.96.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.104.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.112.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.128.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.160.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.168.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.176.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.192.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.200.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.208.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.224.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.232.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.99.240.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.102.128.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.102.136.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.102.144.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.102.160.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.102.224.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.102.232.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.102.240.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.106.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=202.107.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=202.108.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=202.110.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=202.110.192.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.111.128.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.111.192.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.112.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=202.113.16.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.113.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.113.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.113.128.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.113.192.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.113.224.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.113.240.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.114.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.114.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.114.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.114.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=202.115.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.115.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.115.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=202.116.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.116.32.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.116.48.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.116.64.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.116.96.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.116.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=202.117.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.117.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.117.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=202.118.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.118.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.118.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.118.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=202.119.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.119.64.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.119.80.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.119.96.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.119.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=202.120.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.120.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=202.120.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=202.121.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=202.122.0.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.122.112.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.122.128.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.123.96.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.2.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.4.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.5.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.6.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.40.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.128.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.192.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.194.0/23 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.196.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.208.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.209.0/24 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.212.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.216.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.127.224.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.130.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.130.224.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.131.48.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.136.48.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.136.208.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.136.224.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.136.252.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=202.142.16.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.149.224.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.150.16.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.152.176.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.158.160.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.165.96.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.168.160.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.168.176.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=202.170.128.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.173.8.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=202.180.128.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=202.192.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=202.200.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=202.204.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=203.79.0.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=203.81.16.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=203.86.64.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=203.86.80.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=203.88.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=203.89.0.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=203.90.0.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=203.91.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=203.91.96.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=203.92.0.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=203.94.0.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=203.94.4.0/22 action=lookup table=wangtong comment="" disable=no
add dst-address=203.94.8.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=203.94.16.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=203.95.96.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=203.100.32.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=203.100.96.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=203.119.24.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=203.128.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=203.130.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=203.132.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=203.134.240.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=203.135.96.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=203.135.160.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=203.187.160.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=203.191.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=203.192.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=203.196.0.0/21 action=lookup table=wangtong comment="" disable=no
add dst-address=203.207.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=203.207.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=203.208.0.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=203.212.0.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=203.222.192.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=203.223.0.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=210.2.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.12.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=210.12.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=210.12.128.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=210.12.192.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=210.13.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=210.13.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=210.13.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=210.14.64.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.14.160.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.14.192.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.14.224.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.15.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.15.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.15.64.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.15.96.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.15.128.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=210.16.128.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=210.21.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=210.22.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=210.25.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=210.26.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=210.28.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=210.32.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=210.36.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=210.40.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=210.51.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=210.52.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=210.56.192.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.72.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=210.72.128.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.72.192.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=210.73.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.73.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=210.73.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=210.74.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.74.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.74.64.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.74.96.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.74.160.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.76.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.76.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=210.77.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=210.78.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.78.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.78.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=210.78.128.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.78.160.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.78.192.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=210.79.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=210.79.224.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.82.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=210.87.128.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=210.87.144.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=210.87.160.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.192.96.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=210.211.0.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=211.64.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=211.68.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=211.70.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=211.80.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=211.81.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=211.82.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=211.83.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=211.84.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=211.86.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=211.90.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=211.92.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=211.94.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=211.96.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=211.98.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=211.100.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=211.101.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=211.101.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=211.101.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=211.102.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=211.103.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=211.103.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=211.136.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=211.140.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=211.142.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=211.142.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=211.143.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=211.144.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=211.147.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=211.152.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=211.160.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=211.164.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=218.7.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=218.8.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=218.12.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=218.21.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=218.24.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=218.28.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=218.56.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=218.60.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=218.62.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=218.67.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=218.68.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=218.104.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=218.108.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=218.109.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=218.192.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=218.193.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=218.194.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=218.195.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=218.196.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=218.200.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=218.204.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=218.206.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=218.240.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=218.246.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=219.82.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=219.142.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=219.154.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=219.156.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=219.158.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=219.158.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=219.159.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=219.216.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=219.218.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=219.220.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=219.221.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=219.222.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=219.224.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=219.226.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=219.227.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=219.228.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=219.230.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=219.232.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=219.236.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=219.238.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=219.242.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=219.244.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=220.101.192.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=220.192.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=220.194.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=220.196.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=220.200.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=220.231.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=220.231.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=220.232.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=220.248.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=221.0.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=221.2.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=221.3.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=221.3.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=221.4.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=221.5.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=221.5.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=221.6.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=221.7.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=221.7.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=221.7.64.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=221.7.96.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=221.7.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=221.8.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=221.10.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=221.11.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=221.11.128.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=221.11.192.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=221.12.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=221.12.128.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=221.13.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=221.13.64.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=221.13.96.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=221.13.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=221.14.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=221.130.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=221.172.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=221.176.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=221.192.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=221.194.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=221.195.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=221.196.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=221.198.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=221.199.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=221.199.32.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=221.199.128.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=221.200.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=221.204.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=221.206.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=221.207.0.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=221.207.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=221.207.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=221.208.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=221.212.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=221.213.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=221.214.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=221.216.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=222.16.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=222.18.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=222.20.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=222.22.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=222.23.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=222.24.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=222.26.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=222.28.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=222.32.0.0/11 action=lookup table=wangtong comment="" disable=no
add dst-address=222.125.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=222.128.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=222.132.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=222.136.0.0/13 action=lookup table=wangtong comment="" disable=no
add dst-address=222.160.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=222.162.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=222.163.0.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=222.163.32.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=222.163.64.0/18 action=lookup table=wangtong comment="" disable=no
add dst-address=222.163.128.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=222.192.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=222.196.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=222.198.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=222.199.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=222.200.0.0/14 action=lookup table=wangtong comment="" disable=no
add dst-address=222.204.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=222.206.0.0/15 action=lookup table=wangtong comment="" disable=no
add dst-address=222.248.0.0/16 action=lookup table=wangtong comment="" disable=no
add dst-address=222.249.0.0/17 action=lookup table=wangtong comment="" disable=no
add dst-address=222.249.128.0/19 action=lookup table=wangtong comment="" disable=no
add dst-address=222.249.160.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=222.249.176.0/20 action=lookup table=wangtong comment="" disable=no
add dst-address=222.249.192.0/18 action=lookup table=wangtong comment="" disable=no

下面讲一下全局限制速度和限制线程

限速脚本+ 限线程脚本(2.9.X)

限线程脚本:
:for aaa from 2 to 254 do={/ip firewall filter add chain=forward src-address=(192.168.0. .
$aaa) protocol=tcp connection-limit=50,32 action=drop}
限速脚本:
:for user from 2 to 254 do={/queue simple add name=(" 第 " . $user . " 号 机 ") dst-
address=("192.168.0." . $user . "/32") max-limit=2048000/1024000}
说明:
aaa 是变量
2 to 254 是 2~254
192.168.0. . $aaa 是 IP
192.168.0." . $user 也是 IP
上两句加起来是 192.168.0.2~192.168.0.254
connection-limit=50 是线程数这里为 50
max-limit=2048000/1024000 是上行/下行

使用:
WinBox-System-Scripts-+
Name(脚本名程)
Source(脚本)
OK-选择要运行的脚本-Run Script

查看:
限线程:WinBox-IP-Firewall-Filter Rules(看是否已经填加进来)
限速:WinBox-Queues-Simple Queues(看是否已经填加进来)

设定 dhcp 服务器。
ip/dhcp server /setup/,在 dhcp interface 中选择 Lan,next,dhcp server space 中输入
192.168.0.0/24,next,整个局域网的网关是 192.168.0.254 所以在 gateway for dhcp network
中输入 192.168.0.254,然后 next,一路 next 就行了。
除此之外,你可能希望某台计算机一直获取某个固定的 ip 地址,你可以这样设定:ip/dhcp
server/leases/选择+号/,address 中输入你想分配给他的 ip 地址,然后再 mac address 中输入
他的计算机的网卡 mac 地址,然后 apply,接着 OK 就行了。

设定 vpn 服务器。
建立 vpn 的方式有很多种,可以通过 pptp 协议也可以通过 L2TP 等,我们这里依 pptp 协议举例。
Interfaces/在 Wan 上面右击鼠标,在弹出的菜单中选择 add /pptp server/apply/ok。
在 IP--Pool 里 添 加 地 址 池 。 我 输 入 的 是 192.168.0.100-192.168.0.150 , 名 称 命 名 为 pptp-pool
/apply/ok。
在 PPP--Profiles 中添加规则,在 name 中输入 pptp-Profile,然后在 local address 中选择我们刚才
建立的地址池 pptp-pool,Remote address 中选择 pptp-pool。然后在压缩、加密等 3 个选择 yes,最
后一个选择 defaule。

在 PPP--Secrets 中添加拨号用户,在 name 中输入你设定的登陆 pptp 的用户名。我设定为:pptp-test,


密码也设定为 pptp-test,service 选择 pptp,profile 选择我们刚才建立的 pptp-Profile。(注意,若
我们在 pptp-Profile 文件中没有设定 Remote address,则这里一定要设定一个地址,具体什么地址
你随便输入一个就行了,否则 window 登陆的时候会出问题。)

然后 ppp/interfaces/pptp server/,在 enabled 前面打上钩,在 pap 和 chap 等 4 个选项全打上


钩。Apply/ok 就行了。
若要添加更过的用户,请重复在 PPP—Secrets 中的步骤,添加更多的用户。
Vpn 服务器建立之后,你可以用 Windows XP 建立一个到 Wan 口的公网地址的 VPN 连接(注意
是公网地址哇,别搞错了),然后测试是否成功,呵呵!

建立 PPPOE 服务器。
在局域网建立 PPPOE 服务器可以彻底根绝 ARP 流窜,呵呵,大致步骤和建立 vpn 服务器差
不多。但是要注意我们是建立在 Lan 口上的。
Interfaces/在 Lan 上面右击鼠标,在弹出的菜单中选择 add /pppoe server/apply/ok。
在 IP--Pool 里添加地址池。我输入的是 192.168.0.151-192.168.0.200,名称命名为 pppoe-pool
/apply/ok。
在 PPP--Profiles 中添加规则,在 name 中输入 pppoe-Profile,然后在 local address 中选择我
们刚才建立的地址池 pppoe-pool,Remote address 中选择 pppoe-pool。然后在压缩、加密等 3 个选择
yes,最后一个选择 defaule。

在 PPP--Secrets 中添加拨号用户,在 name 中输入你设定的登陆 pppoe 的用户名。我设定为:


pppoe-test,密码也设定为 pppoe-test,service 选择 pppoe,profile 选择我们刚才建立的 pppoe-Profile。
(注意,若我们在 pppoe-Profile 文件中没有设定 Remote address,则这里一定要设定一个地址,
具体什么地址你随便输入一个就行了,否则 window 登陆的时候会出问题。)

然后 ppp/interfaces/pppoe server/按+号,在 pap 和 chap 等 4 个选项全打上钩。Apply/ok


就行了。
若要添加更过的用户,请重复在 PPP—Secrets 中的步骤,添加更多的用户。
PPPOE 服务器建立之后,你可以用 Windows XP 建立一个 PPPOE 拨号连接测试是否成功

hosspot 设置
Hosspot 是一个很有用的功能,可以控制网络中的计算机对网络的访问,其实现的功能和
PPPOE 类似。
当局域网中设置了 Hosspot 服务之后,若客户计算机通过浏览器访问网页时,首先会弹出一
个认证页面(类似于国内好像叫作“城市热点”公司的产品提供的局域网认证管理功能),要求
输入用户名和密码,只有通过认证的客户才能访问互联网,即便你的计算机设置了 DHCP 服务并
从 DHCP 服务器获取网关的地址也不行,呵呵!我觉得这方面比 PPPOE 更好(但是 PPPOE 可以
防止 Mac 地址欺骗)。好了,下面我们开始设置我们的 Hosspot 服务了。
首先我们要更改 www 服务的端口。过程如下:从 WinBox 中,依次点击:IP/Services,然后
双击 WWW,在弹出的窗口的 Port 处中输入一个端口号码,我这里输入 8080。然后 apply /OK。
然后,在 Lan 口增加 hotspot 服务,过程如下:从 winbox 中,依次点击:IP/hotspot,点击 servers
中的 setup 按钮,在 hotspot Interfaces 中选择 Lan,Next,Local address of network 中不要使用默
认的 IP192.168.0.254/24,而要设置为其他的与你的真实的局域网的地址不同的 IP 段,比如我设
置为 10.10.10.1/24,否则远程客户通过 VPN 连接以及 PPPOE 客户端通过 Lan 连接的时候会出问
题 ,NEXT,address pool of network 中输入通过 hotspot 认证后的客户的 IP 地址的地址段(我采
用了默认的 IP 段 10.10.10.2-10.10.10.254),NETX,在 sele certificate 中不作选择(这是认证的方
式,为简单起见,我选择了 None),在 Ip address of smtp server 中不输入,next,dns server 中输
入 dns 服务器的地址,netx,dns name 中随便输入,然后在 create local hotspot user (建立本地 hotspot
用户)中,输入你要登陆的用户名和密码),next,OK。什么,这时候 winbox 提示网络连接断
开?
呵呵,不要着急,这代表我们的 hotspot 服务已经建立并开始运行了。客户机输入任何网址,
都自动跳转到登陆页面,输入账号密码,继续浏览。如果使用 ftp、pop3 等,也必须先通过网页
登录,才可以使用,当然使用 winbox 的时候也必须先登录。我们现在在地址栏中输入一个网址,
在弹出的登陆页面中输入我们刚才的用户名和密码吧。出现欢迎界面之后(这时候不要在网页中
点击 log off),你就可以再一次启动 winbox 了。
若你要增加更多的 hotspot 服务的用户,请在 winbox 中依次点击 ip/hotspot/user/按“+”
号,增加用户并输入密码!

下面是防火墙部分

/ ip firewall filter
add chain=input connection-state=invalid action=drop \
comment="丢弃非法连接数据" disabled=no
add chain=input protocol=tcp dst-port=80 connection-limit=20,0 action=drop \
comment="限制总http连接数为20" disabled=no
add chain=input protocol=tcp psd=21,3s,3,1 action=drop \
comment="探测并丢弃端口扫描连接" disabled=no
add chain=input protocol=tcp connection-limit=3,32 src-address-list=black_list \
action=tarpit comment="压制DoS攻击" disabled=no
add chain=input protocol=tcp connection-limit=10,32 \
action=add-src-to-address-list address-list=black_list \
address-list-timeout=1d comment="探测DoS攻击" disabled=no
add chain=input dst-address-type=!local action=drop comment="丢弃掉非本地数据" \
disabled=no
add chain=input protocol=icmp action=jump jump-target=ICMP \
comment="跳转到ICMP链表" disabled=no
add chain=ICMP protocol=icmp icmp-options=0:0-255 limit=5,5 action=accept \
comment="Ping应答限制为每秒5个包" disabled=no
add chain=ICMP protocol=icmp icmp-options=3:3 limit=5,5 action=accept \
comment="Traceroute限制为每秒5个包" disabled=no
add chain=ICMP protocol=icmp icmp-options=3:4 limit=5,5 action=accept \
comment="MTU线路探测限制为每秒5个包" disabled=no
add chain=ICMP protocol=icmp icmp-options=8:0-255 limit=5,5 action=accept \
comment="Ping请求限制为每秒5个包" disabled=no
add chain=ICMP protocol=icmp icmp-options=11:0-255 limit=5,5 action=accept \
comment="Trace TTL限制为每秒5个包" disabled=no
add chain=ICMP protocol=icmp action=drop comment="丢弃掉任何ICMP数据" \
disabled=no
add chain=forward connection-state=invalid action=drop \
comment="丢弃非法数据包" disabled=no
add chain=forward protocol=tcp connection-limit=80,32 action=drop \
comment="限制每个主机TCP连接数为80条" disabled=no
add chain=forward src-address-type=!unicast action=drop \
comment="丢弃掉所有非单播数据" disabled=no
add chain=forward content=.exe action=drop comment="禁止.exe文件通过" \
disabled=yes
add chain=forward content=.dll action=drop comment="禁止.dll文件通过" \
disabled=yes
add chain=forward protocol=icmp action=jump jump-target=ICMP \
comment="跳转到ICMP链表" disabled=no
add chain=forward action=jump jump-target=virus comment="跳转到病毒链表" \
disabled=no
add chain=virus protocol=tcp dst-port=41 action=drop \
comment="DeepThroat.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=82 action=drop \
comment="Worm.NetSky.Y@mm" disabled=no
add chain=virus protocol=tcp dst-port=113 action=drop \
comment="W32.Korgo.A/B/C/D/E/F-1" disabled=no
add chain=virus protocol=tcp dst-port=2041 action=drop \
comment="W33.Korgo.A/B/C/D/E/F-2" disabled=no
add chain=virus protocol=tcp dst-port=3150 action=drop \
comment="DeepThroat.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=3067 action=drop \
comment="W32.Korgo.A/B/C/D/E/F-3" disabled=no
add chain=virus protocol=tcp dst-port=3422 action=drop \
comment="Backdoor.IRC.Aladdinz.R-1" disabled=no
add chain=virus protocol=tcp dst-port=6667 action=drop \
comment="W32.Korgo.A/B/C/D/E/F-4" disabled=no
add chain=virus protocol=tcp dst-port=6789 action=drop \
comment="Worm.NetSky.S/T/U@mm" disabled=no
add chain=virus protocol=tcp dst-port=8787 action=drop \
comment="Back.Orifice.2000.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=8879 action=drop \
comment="Back.Orifice.2000.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=8967 action=drop \
comment="W32.Dabber.A/B-2" disabled=no
add chain=virus protocol=tcp dst-port=9999 action=drop \
comment="W32.Dabber.A/B-3" disabled=no
add chain=virus protocol=tcp dst-port=20034 action=drop \
comment="Block.NetBus.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=21554 action=drop \
comment="GirlFriend.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=31666 action=drop \
comment="Back.Orifice.2000.Trojan-3" disabled=no
add chain=virus protocol=tcp dst-port=43958 action=drop \
comment="Backdoor.IRC.Aladdinz.R-2" disabled=no
add chain=virus protocol=tcp dst-port=999 action=drop \
comment="DeepThroat.Trojan-3" disabled=no
add chain=virus protocol=tcp dst-port=6670 action=drop \
comment="DeepThroat.Trojan-4" disabled=no
add chain=virus protocol=tcp dst-port=6771 action=drop \
comment="DeepThroat.Trojan-5" disabled=no
add chain=virus protocol=tcp dst-port=60000 action=drop \
comment="DeepThroat.Trojan-6" disabled=no
add chain=virus protocol=tcp dst-port=2140 action=drop \
comment="DeepThroat.Trojan-7" disabled=no
add chain=virus protocol=tcp dst-port=10067 action=drop \
comment="Portal.of.Doom.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=10167 action=drop \
comment="Portal.of.Doom.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=3700 action=drop \
comment="Portal.of.Doom.Trojan-3" disabled=no
add chain=virus protocol=tcp dst-port=9872-9875 action=drop \
comment="Portal.of.Doom.Trojan-4" disabled=no
add chain=virus protocol=tcp dst-port=6883 action=drop \
comment="Delta.Source.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=26274 action=drop \
comment="Delta.Source.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=4444 action=drop \
comment="Delta.Source.Trojan-3" disabled=no
add chain=virus protocol=tcp dst-port=47262 action=drop \
comment="Delta.Source.Trojan-4" disabled=no
add chain=virus protocol=tcp dst-port=3791 action=drop \
comment="Eclypse.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=3801 action=drop \
comment="Eclypse.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=65390 action=drop \
comment="Eclypse.Trojan-3" disabled=no
add chain=virus protocol=tcp dst-port=5880-5882 action=drop \
comment="Y3K.RAT.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=5888-5889 action=drop \
comment="Y3K.RAT.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=30100-30103 action=drop \
comment="NetSphere.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=30133 action=drop \
comment="NetSphere.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=7300-7301 action=drop \
comment="NetMonitor.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=7306-7308 action=drop \
comment="NetMonitor.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=79 action=drop \
comment="FireHotcker.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=5031 action=drop \
comment="FireHotcker.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=5321 action=drop \
comment="FireHotcker.Trojan-3" disabled=no
add chain=virus protocol=tcp dst-port=6400 action=drop \
comment="TheThing.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=7777 action=drop \
comment="TheThing.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=1047 action=drop \
comment="GateCrasher.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=6969-6970 action=drop \
comment="GateCrasher.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=2774 action=drop comment="SubSeven-1" \
disabled=no
add chain=virus protocol=tcp dst-port=27374 action=drop comment="SubSeven-2" \
disabled=no
add chain=virus protocol=tcp dst-port=1243 action=drop comment="SubSeven-3" \
disabled=no
add chain=virus protocol=tcp dst-port=1234 action=drop comment="SubSeven-4" \
disabled=no
add chain=virus protocol=tcp dst-port=6711-6713 action=drop \
comment="SubSeven-5" disabled=no
add chain=virus protocol=tcp dst-port=16959 action=drop comment="SubSeven-7" \
disabled=no
add chain=virus protocol=tcp dst-port=25685-25686 action=drop \
comment="Moonpie.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=25982 action=drop \
comment="Moonpie.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=31337-31339 action=drop \
comment="NetSpy.Trojan-3" disabled=no
add chain=virus protocol=tcp dst-port=8102 action=drop comment="Trojan" \
disabled=no
add chain=virus protocol=tcp dst-port=8011 action=drop comment="WAY.Trojan" \
disabled=no
add chain=virus protocol=tcp dst-port=7626 action=drop comment="Trojan.BingHe" \
disabled=no
add chain=virus protocol=tcp dst-port=19191 action=drop \
comment="Trojan.NianSeHoYian" disabled=no
add chain=virus protocol=tcp dst-port=23444-23445 action=drop \
comment="NetBull.Trojan" disabled=no
add chain=virus protocol=tcp dst-port=2583 action=drop \
comment="WinCrash.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=3024 action=drop \
comment="WinCrash.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=4092 action=drop \
comment="WinCrash.Trojan-3" disabled=no
add chain=virus protocol=tcp dst-port=5714 action=drop \
comment="WinCrash.Trojan-4" disabled=no
add chain=virus protocol=tcp dst-port=1010-1012 action=drop \
comment="Doly1.0/1.35/1.5trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=1015 action=drop \
comment="Doly1.0/1.35/1.5trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=2004-2005 action=drop \
comment="TransScout.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=9878 action=drop \
comment="TransScout.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=2773 action=drop \
comment="Backdoor.YAI..Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=7215 action=drop \
comment="Backdoor.YAI.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=54283 action=drop \
comment="Backdoor.YAI.Trojan-3" disabled=no
add chain=virus protocol=tcp dst-port=1003 action=drop \
comment="BackDoorTrojan-1" disabled=no
add chain=virus protocol=tcp dst-port=5598 action=drop \
comment="BackDoorTrojan-2" disabled=no
add chain=virus protocol=tcp dst-port=5698 action=drop \
comment="BackDoorTrojan-3" disabled=no
add chain=virus protocol=tcp dst-port=31554 action=drop \
comment="SchainwindlerTrojan-2" disabled=no
add chain=virus protocol=tcp dst-port=18753 action=drop \
comment="Shaft.DDoS.Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=20432 action=drop \
comment="Shaft.DDoS.Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=65000 action=drop \
comment="Devil.DDoS.Trojan" disabled=no
add chain=virus protocol=tcp dst-port=11831 action=drop \
comment="LatinusTrojan-1" disabled=no
add chain=virus protocol=tcp dst-port=29559 action=drop \
comment="LatinusTrojan-2" disabled=no
add chain=virus protocol=tcp dst-port=1784 action=drop \
comment="Snid.X2Trojan-1" disabled=no
add chain=virus protocol=tcp dst-port=3586 action=drop \
comment="Snid.X2Trojan-2" disabled=no
add chain=virus protocol=tcp dst-port=7609 action=drop \
comment="Snid.X2Trojan-3" disabled=no
add chain=virus protocol=tcp dst-port=12348-12349 action=drop \
comment="BionetTrojan-1" disabled=no
add chain=virus protocol=tcp dst-port=12478 action=drop \
comment="BionetTrojan-2" disabled=no
add chain=virus protocol=tcp dst-port=57922 action=drop \
comment="BionetTrojan-3" disabled=no
add chain=virus protocol=tcp dst-port=3127 action=drop \
comment="Worm.Novarg.a.Mydoom.a1." disabled=no
add chain=virus protocol=tcp dst-port=6777 action=drop \
comment="Worm.BBeagle.a.Bagle.a." disabled=no
add chain=virus protocol=tcp dst-port=8866 action=drop \
comment="Worm.BBeagle.b" disabled=no
add chain=virus protocol=tcp dst-port=2745 action=drop \
comment="Worm.BBeagle.c-g/j-l" disabled=no
add chain=virus protocol=tcp dst-port=2556 action=drop \
comment="Worm.BBeagle.p/q/r/n" disabled=no
add chain=virus protocol=tcp dst-port=20742 action=drop \
comment="Worm.BBEagle.m-2" disabled=no
add chain=virus protocol=tcp dst-port=4751 action=drop \
comment="Worm.BBeagle.s/t/u/v" disabled=no
add chain=virus protocol=tcp dst-port=2535 action=drop \
comment="Worm.BBeagle.aa/ab/w/x-z-2" disabled=no
add chain=virus protocol=tcp dst-port=5238 action=drop \
comment="Worm.LovGate.r.RpcExploit" disabled=no
add chain=virus protocol=tcp dst-port=1068 action=drop comment="Worm.Sasser.a" \
disabled=no
add chain=virus protocol=tcp dst-port=5554 action=drop \
comment="Worm.Sasser.b/c/f" disabled=no
add chain=virus protocol=tcp dst-port=9996 action=drop \
comment="Worm.Sasser.b/c/f" disabled=no
add chain=virus protocol=tcp dst-port=9995 action=drop comment="Worm.Sasser.d" \
disabled=no
add chain=virus protocol=tcp dst-port=10168 action=drop \
comment="Worm.Lovgate.a/b/c/d" disabled=no
add chain=virus protocol=tcp dst-port=20808 action=drop \
comment="Worm.Lovgate.v.QQ" disabled=no
add chain=virus protocol=tcp dst-port=1092 action=drop \
comment="Worm.Lovgate.f/g" disabled=no
add chain=virus protocol=tcp dst-port=20168 action=drop \
comment="Worm.Lovgate.f/g" disabled=no
add chain=virus protocol=tcp dst-port=1363-1364 action=drop \
comment="ndm.requester" disabled=no
add chain=virus protocol=tcp dst-port=1368 action=drop comment="screen.cast" \
disabled=no
add chain=virus protocol=tcp dst-port=1373 action=drop comment="hromgrafx" \
disabled=no
add chain=virus protocol=tcp dst-port=1377 action=drop comment="cichainlid" \
disabled=no
add chain=virus protocol=tcp dst-port=3410 action=drop \
comment="Backdoor.Optixprotocol" disabled=no
add chain=virus protocol=tcp dst-port=8888 action=drop \
comment="Worm.BBeagle.b" disabled=no
add chain=virus protocol=udp dst-port=44444 action=drop \
comment="Delta.Source.Trojan-7" disabled=no
add chain=virus protocol=udp dst-port=8998 action=drop \
comment="Worm.Sobig.f-3" disabled=no
add chain=virus protocol=udp dst-port=123 action=drop comment="Worm.Sobig.f-1" \
disabled=no
add chain=virus protocol=tcp dst-port=3198 action=drop \
comment="Worm.Novarg.a.Mydoom.a2." disabled=no
add chain=virus protocol=tcp dst-port=139 action=drop comment="Drop Blaster \
Worm" disabled=no
add chain=virus protocol=tcp dst-port=135 action=drop comment="Drop Blaster \
Worm" disabled=no
add chain=virus protocol=tcp dst-port=445 action=drop comment="Drop Blaster \
Worm" disabled=no
add chain=forward action=accept comment="接受所有数据" disabled=no

将这个脚本复制之后保存为 firewall.rsc 文件然后通过 FTP://路由器 IP 地址


将 firewall.rsc 文件拷贝到路由器 FTP 目录上
在终端操作下(Terminal)执行 import 命令导入防火墙规则:
[admin@NAT] > import firewall.rsc
如果提示以下内容说明操作成功:
Opening script file firewall.rsc
Script file loaded and executed successfully

注意添加对.exe 和.dll 文件内容的过滤,这两条规则默认为禁用,可以选择使用。


在防火墙规则链中增加了 ICMP 和 virus 两个链表,ICMP 是对 ICMP 协议的数据做过滤(包括 ping、
traceroute 等)。在 virus 中是对常见的病毒端口进行过滤,在 foreward 的链表中,增加了限制 TCP
连接数为 80 的规则

控制上班时间上网的方法
如下:
需要打开控制的时候把
“ALL”那项删除!
另外也可以添加 自己的私人通道!!
如 VIP 那项!!我自己的内部 IP :192.168.1.184/32
这里的 192.168.1.0/24 只是示例 请根据自己的网段设置,如果自己的是 192.168.0.0 网段就设置
成 192.168.0.0/24
上班的时候其他员工不能上网
总不能 让他们以为断线什么的吧!!
现在我们可以通过
D-nat 的办法!把所有 IP 都解析到公司的网站或者内部 WWW 或者 OA 系统!!嘎嘎
好阴险哦
这样公司员工不管输入什么 IP 或者地址都只能访问公司的网站或者 OA 系统而已!!

现在我们开始编写脚本
其实照着抄就可以拉
不过你得懂得原理
就更好拉
到这个步骤就是
计划任务的事情了
应该能看得懂吧
WinBox-System-Scheduler-+
这个步骤只要稍微用心点就能看明白的,多做几次就熟悉了。

下面讲一下基于 IPIP 连接方式的虚拟双线教程

环境测试二台 ROS2.96 的路由。电信(单线)IP:219.159.78.68(以下就称为 A 机内网 IP 段


192.168.88 段) 网通(单线) IP:219.159.78.87(以下就称为 B 机内网 IP 段 192.168.0 段)
好了看我的说明:
A 机设置:先在 AB 机之间建一个虚拟通道连接方式用 IPIP。
[admin@219.159.78.68] interface ipip> add local-address=219.159.78.68 \
remote-address=219.159.78.87 disabled=no
[admin@219.159.78.68] ip address> add address=10.0.0.1/24 interface=ipip1 把 10.0.0.1 这
个 IP 分

配给 IPIP1 这块虚拟网卡
B 机设置:
[admin@219.159.78.87] interface ipip> add local-address=219.159.78.87 \
remote-address=219.159.78.68 disabled=no
[admin@219.159.78.87] ip address> add address=10.0.0.2/24 interface=ipip1 把 10.0.0.2 这
个 IP 分配给 IPIP1 这块虚拟网卡
-------------------------------------------------------------------------------------------------------------------
---------------
通过这样设置就可以在 A 机的命令控制台里 ping 通 10.0.0.2(也就是 B 机的虚拟网卡的 IP) 这
个 IP 了。基本上 AB 机的虚拟通道就算建立起来了。
然后在 A 机的 IP routes 加规则 套用我上面发的那个路由表就可以了,导入 IP 规则,然后建立
策略路由 MARK 处别忘了选择 CHINANET 网关处把虚拟网卡 IP 添上

You might also like