You are on page 1of 1

/ip firewall filter

add action=reject chain=input comment="Ataque dns" dst-port=53 protocol=udp reject-


with=icmp-port-unreachable
add action=reject chain=input comment="Ataque dns" dst-port=53 protocol=tcp reject-
with=icmp-port-unreachable
add action=accept chain=input comment="Conex\F5es estabelecidas e relatas"
connection-state=established,related
add action=drop chain=input comment="Conex\F5es inv\E1lidas" connection-
state=invalid
add action=jump chain=input comment="Controle ICMP" jump-target=ICMP protocol=icmp
add action=drop chain=input comment="Detecta e descarta conex\F5es por Scan"
protocol=tcp psd=10,3s,3,1
add action=add-src-to-address-list address-list=black-list address-list-timeout=1d
chain=input comment="Detecta ataque DOS" connection-limit=10,32 protocol=tcp
add action=tarpit chain=input comment="Suprime atque DOS" connection-limit=3,32
protocol=tcp
add action=accept chain=ICMP limit=5,5:packet protocol=icmp
add action=accept chain=ICMP limit=5,5:packet protocol=icmp
add action=accept chain=ICMP limit=5,5:packet protocol=icmp
add action=accept chain=ICMP limit=5,5:packet protocol=icmp
add action=accept chain=ICMP limit=5,5:packet protocol=icmp
add action=drop chain=input protocol=icmp
add action=accept chain=forward comment="Conex\F5es estabelecidas e reladas"
connection-state=established,related
add action=drop chain=forward comment="Conex\F5es inv\E1lidas" connection-
state=invalid
add action=jump chain=forward comment="Salto a ICMP" jump-target=ICMP protocol=icmp
add action=accept chain=forward comment="Permiss\E3o a navegar na internet" src-
address-list=pppoe
add action=drop chain=forward

You might also like