Differences
This shows you the differences between two versions of the page.
— |
mikrotik:simple-firewall [2015/08/24 12:42] (current) a created |
||
---|---|---|---|
Line 1: | Line 1: | ||
+ | |||
+ | < | ||
+ | /ip firewall address-list | ||
+ | add address=x.x.x.x list=ipsec-allow | ||
+ | add address=z.z.z.z list=ssh-allow | ||
+ | add address=192.168.0.0/ | ||
+ | add address=10.0.0.0/ | ||
+ | add address=172.16.0.0/ | ||
+ | /ip firewall connection tracking | ||
+ | set generic-timeout=5m tcp-established-timeout=10m | ||
+ | |||
+ | /ip firewall filter | ||
+ | add chain=input comment=" | ||
+ | add chain=input connection-state=related in-interface=eth0-WAN | ||
+ | add chain=input comment=" | ||
+ | add chain=input comment=" | ||
+ | add action=drop chain=input comment=" | ||
+ | add chain=input comment=" | ||
+ | add chain=input dst-port=1723 in-interface=eth0-WAN protocol=tcp | ||
+ | add chain=input comment=" | ||
+ | add chain=input dst-port=4500 in-interface=eth0-WAN protocol=udp src-address-list=ipsec-allow | ||
+ | add chain=input in-interface=eth0-WAN protocol=ipsec-esp src-address-list=ipsec-allow | ||
+ | add chain=input in-interface=eth0-WAN protocol=ipsec-ah src-address-list=ipsec-allow | ||
+ | add chain=input comment=" | ||
+ | add chain=input comment=" | ||
+ | add chain=input comment=" | ||
+ | add action=drop chain=input comment=" | ||
+ | add chain=forward comment=" | ||
+ | add chain=forward connection-state=related | ||
+ | add chain=forward comment=" | ||
+ | add chain=forward comment=" | ||
+ | add chain=forward dst-address=192.168.69.40 dst-port=61413-61420 protocol=tcp | ||
+ | add chain=forward dst-address=192.168.69.40 dst-port=61413-61420 protocol=udp | ||
+ | add action=log chain=forward comment=" | ||
+ | add action=drop chain=forward | ||
+ | |||
+ | /ip firewall nat | ||
+ | add action=masquerade chain=srcnat dst-address=!192.168.0.0/ | ||
+ | add action=src-nat chain=srcnat dst-address=192.168.69.0/ | ||
+ | add action=dst-nat chain=dstnat dst-port=61413-61420 protocol=udp to-addresses=192.168.69.40 to-ports=61413-61420 | ||
+ | add action=dst-nat chain=dstnat dst-port=61413-61420 protocol=tcp to-addresses=192.168.69.40 to-ports=61413-61420 | ||
+ | </ | ||