防火墙的设置
上一篇 / 下一篇 2008-01-10 23:14:42 / 个人分类:网络
防火墙的设置远景无限博客/B0O:}Ah#M7I&\4nB
9?_7C-j
P!X
E3N/w0将下面的文件保存为文件后辍名为.rsc即可远景无限博客"X*fX"M"C3H
本文转自深度
5U'\Z,r^'I(r0远景无限博客{X/C)YE$~
# jan/12/2006 21:47:17 by RouterOS 2.9.7
*E];xt#JVr0yzZ$S0# software id = 3FMQ-Z6N远景无限博客 gpZu+Y?@$Q
#
f6V\;A3m0/ ip firewall connection tracking
8U?u:Ow0set enabled=yes tcp-syn-sent-timeout=2m tcp-syn-received-timeout=1m \
p/~ ^~"Qc0 tcp-established-timeout=10h tcp-fin-wait-timeout=2m \
r]9ig"`gcC0 tcp-close-wait-timeout=1m tcp-last-ack-timeout=30s \
0cgCf%JG0 tcp-time-wait-timeout=2m tcp-close-timeout=10s udp-timeout=30s \
h-v mw
\j)v'N4`m0 udp-stream-timeout=3m icmp-timeout=30s generic-timeout=10m远景无限博客OESgI:l8oV
/ ip firewall filter远景无限博客oI"jX9{&o[
add chain=input src-address-list=black_list action=drop comment="Drop Black list 屏蔽黑名单IP " disabled=no
\[%@H?T/b0add chain=input connection-state=invalid action=drop comment="drop invalid \远景无限博客"Gwg
t5Z/j3L8r)@|
packets" disabled=no
W;LpH.{M8\0add chain=input connection-state=related action=accept comment="accept related \
H
wr
hT:cw0 packets" disabled=no远景无限博客Y+^ Xg`6X3WbO%n
add chain=input connection-state=established action=accept comment="accept \
tk7Ee/LhWW\0 established packets" disabled=no远景无限博客'Qm-T z-c-T
add chain=input protocol=tcp psd=21,3s,3,1 action=drop comment="detect and \远景无限博客4{j0P0t2g5h
drop port scan connections" disabled=no远景无限博客1^j/A/OmYw,~.{
add chain=input protocol=tcp connection-limit=3,32 src-address-list=black_list \远景无限博客(xW"e-d(T;e
action=tarpit comment="suppress DoS attack" disabled=no远景无限博客8X3OR1} YO5Ft~qE
add chain=input protocol=tcp connection-limit=10,32 \远景无限博客;BZ0hf)lp/W
action=add-src-to-address-list address-list=black_list \
Ev+kKc0 address-list-timeout=1d comment="detect DoS attack" disabled=no远景无限博客u8A}B1M7Od
add chain=input dst-address-type=!local action=drop comment="drop all that is \远景无限博客;HY)Ad R"Sa.m
not to local" disabled=no远景无限博客QY;p&P;\'Pm`]
add chain=input protocol=icmp action=jump jump-target=ICMP comment="jump to \远景无限博客dJ+G{)jMDAo8T
chain ICMP" disabled=no
4L3QDN.B#S'}Gn&[,Z@'@c0add chain=input action=jump jump-target=services comment="Jump to service" \
8N8A%lI {s.gBB0 disabled=no远景无限博客d.[LG3Oqf!u9@
add chain=input action=jump jump-target=virus comment="jump to Virus" \
1a9VY)F+A3^.J$s0 disabled=no远景无限博客!lK ^
_3oA4k5U0YrM~
add chain=ICMP protocol=icmp icmp-options=0:0-255 limit=5,5 action=accept \远景无限博客Z~0B ?L4yMl!G
comment="0:0 and limit for 5pac/s" disabled=no远景无限博客Z4}2|
Cmmk-C
add chain=ICMP protocol=icmp icmp-options=3:3 limit=5,5 action=accept \
!sX#fh-L/G1K k0 comment="3:3 and limit for 5pac/s" disabled=no
`/`)C:b*v"]!L0add chain=ICMP protocol=icmp icmp-options=3:4 limit=5,5 action=accept \
+igI&n|"m6^0 comment="3:4 and limit for 5pac/s" disabled=no
|?!K
k X,M
Ae-q@$j0add chain=ICMP protocol=icmp icmp-options=8:0-255 limit=5,5 action=accept \远景无限博客/nj!j3~z4v}
comment="8:0 and limit for 5pac/s" disabled=no