You are on page 1of 2

/ ip firewall filter

add chain=input src-address=!192.168.9.0/24 protocol=tcp src-port=1024-65535 dst-port=8080


add chain=input protocol=udp dst-port=12667 action=drop comment="Trinoo" disabled=no
add chain=input protocol=udp dst-port=27665 action=drop comment="Trinoo" disabled=no
add chain=input protocol=udp dst-port=31335 action=drop comment="Trinoo" disabled=no
add chain=input protocol=udp dst-port=27444 action=drop comment="Trinoo" disabled=no
add chain=input protocol=udp dst-port=34555 action=drop comment="Trinoo" disabled=no
add chain=input protocol=udp dst-port=35555 action=drop comment="Trinoo" disabled=no
add chain=input protocol=tcp dst-port=27444 action=drop comment="Trinoo" disabled=no
add chain=input protocol=tcp dst-port=27665 action=drop comment="Trinoo" disabled=no
add chain=input protocol=tcp dst-port=31335 action=drop comment="Trinoo" disabled=no
add chain=input protocol=tcp dst-port=31846 action=drop comment="Trinoo" disabled=no
add chain=input protocol=tcp dst-port=34555 action=drop comment="Trinoo" disabled=no
add chain=input protocol=tcp dst-port=35555 action=drop comment="Trinoo" disabled=no
add chain=forward src-address=0.0.0.0/8 action=drop comment="" disabled=no
add chain=forward dst-address=0.0.0.0/8 action=drop comment="" disabled=no
add chain=forward src-address=127.0.0.0/8 action=drop comment="" disabled=no
add chain=forward dst-address=127.0.0.0/8 action=drop comment="" disabled=no
add chain=forward src-address=224.0.0.0/3 action=drop comment="" disabled=no
add chain=forward dst-address=224.0.0.0/3 action=drop comment="" disabled=no
add chain=forward protocol=tcp action=jump jump-target=tcp comment="" disabled=no
add chain=forward protocol=udp action=jump jump-target=udp comment="" disabled=no
add chain=forward protocol=icmp action=jump jump-target=icmp comment="" disabled=no
add chain=tcp protocol=tcp dst-port=69 action=drop comment="deny TFTP" disabled=no
add chain=tcp protocol=tcp dst-port=111 action=drop comment="deny RPC portmapper" disabled=
add chain=tcp protocol=tcp dst-port=135 action=drop comment="deny RPC portmapper" disabled=
add chain=tcp protocol=tcp dst-port=137-139 action=drop comment="deny NBT" disabled=no
add chain=tcp protocol=tcp dst-port=445 action=drop comment="deny cifs" disabled=no
add chain=tcp protocol=tcp dst-port=2049 action=drop comment="deny NFS" disabled=no
add chain=tcp protocol=tcp dst-port=12345-12346 action=drop comment="deny NetBus" disabled=
add chain=tcp protocol=tcp dst-port=20034 action=drop comment="deny NetBus" disabled=no
add chain=tcp protocol=tcp dst-port=3133 action=drop comment="deny BackOriffice" disabled=n
add chain=tcp protocol=tcp dst-port=67-68 action=drop comment="deny DHCP" disabled=no
add chain=udp protocol=udp dst-port=69 action=drop comment="deny TFTP" disabled=no
add chain=udp protocol=udp dst-port=111 action=drop comment="deny PRC portmapper" disabled=
add chain=udp protocol=udp dst-port=135 action=drop comment="deny PRC portmapper" disabled=
add chain=udp protocol=udp dst-port=137-139 action=drop comment="deny NBT" disabled=no
add chain=udp protocol=udp dst-port=2049 action=drop comment="deny NFS" disabled=no
add chain=udp protocol=udp dst-port=3133 action=drop comment="deny BackOriffice" disabled=n
add chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list address-list="por
add chain=input protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-addre
add chain=input protocol=tcp tcp-flags=fin,syn action=add-src-to-address-list address-list=
add chain=input protocol=tcp tcp-flags=syn,rst action=add-src-to-address-list address-list=
add chain=input protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack action=add-src-to-address
add chain=input protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg action=add-src-to-address-li
add chain=input protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-addr
add chain=input src-address-list="port scanners" action=drop comment="dropping port scanner
add chain=icmp protocol=icmp icmp-options=0:0 action=accept comment="drop invalid connectio
add chain=icmp protocol=icmp icmp-options=3:0 action=accept comment="allow established conn
add chain=icmp protocol=icmp icmp-options=3:1 action=accept comment="allow already establis
add chain=icmp protocol=icmp icmp-options=4:0 action=accept comment="allow source quench" d
add chain=icmp protocol=icmp icmp-options=8:0 action=accept comment="allow echo request" di
add chain=icmp protocol=icmp icmp-options=11:0 action=accept comment="allow time exceed" di
add chain=icmp protocol=icmp icmp-options=12:0 action=accept comment="allow parameter bad"
add chain=icmp action=drop comment="deny all other types" disabled=no
add chain=tcp protocol=tcp dst-port=25 action=reject reject-with=icmp-network-unreachable c
add chain=tcp protocol=udp dst-port=25 action=reject reject-with=icmp-network-unreachable c
add chain=tcp protocol=tcp dst-port=110 action=reject reject-with=icmp-network-unreachable
add chain=tcp protocol=udp dst-port=110 action=reject reject-with=icmp-network-unreachable
add chain=tcp protocol=udp dst-port=110 action=reject reject-with=icmp-network-unreachable

You might also like