Вы находитесь на странице: 1из 3

Verifica esto si te funciona modificalo a tu gusto...

/ip firewall mangle


add action=change-mss chain=forward comment=MSS in-interface=bridge1 new-mss=1300 protocol=tcp
tcp-flags=syn tcp-mss=\
1300-65535
add action=change-mss chain=forward new-mss=1300 out-interface=bridge1 protocol=tcp tcp-flags=syn
tcp-mss=1300-65535

add action=mark-connection chain=prerouting comment=ICMP_CONNECTION new-connection-


mark=ICMP_CONNECTION protocol=icmp
add action=mark-packet chain=prerouting connection-mark=ICMP_CONNECTION new-packet-
mark=ICMP_PACKET passthrough=no protocol=\
icmp
add action=mark-connection chain=prerouting comment=CONN-DOWNLOAD connection-bytes=1000000-0
dst-port=80 \
new-connection-mark=conn-download protocol=tcp
add action=mark-packet chain=prerouting connection-mark=conn-download new-packet-mark=download-
packet passthrough=no
add action=mark-connection chain=prerouting comment=CONN-BROWSING connection-bytes=0-1000000
dst-port=80 \
new-connection-mark=conn-browsing protocol=tcp
add action=mark-packet chain=prerouting connection-mark=conn-browsing new-packet-mark=browsing-
packet passthrough=no
add action=mark-connection chain=prerouting comment=Youtube content=youtube new-connection-
mark=youtube_in
add action=mark-connection chain=prerouting comment=Vevo content=vevo new-connection-
mark=vevo_in
add action=mark-packet chain=prerouting connection-mark=vevo_in new-packet-mark=vevo_in
passthrough=no
add action=mark-connection chain=prerouting comment=Netflix content=netflix new-connection-
mark=netflix_in
add action=mark-packet chain=prerouting connection-mark=netflix_in new-packet-mark=netflix_in
passthrough=no
add action=mark-connection chain=prerouting comment=Hulu content=hulu new-connection-mark=hulu_in
add action=mark-packet chain=prerouting connection-mark=hulu_in new-packet-mark=hulu_in
passthrough=no
add action=mark-connection chain=prerouting comment="Otros Videos" content=video new-connection-
mark=video_in
add action=mark-packet chain=prerouting connection-mark=video_in new-packet-mark=video_in
passthrough=no
add action=mark-connection chain=prerouting comment="ICMP (Ping)" new-connection-mark=icmp_conn
protocol=icmp
add action=mark-packet chain=prerouting connection-mark=icmp_conn new-packet-mark=icmp
passthrough=no
add action=mark-connection chain=prerouting comment=DNS dst-port=53 new-connection-mark=dns_conn
protocol=udp
add action=mark-packet chain=prerouting connection-mark=dns_conn new-packet-mark=dns
passthrough=no
add action=mark-connection chain=prerouting comment=Https dst-port=443 new-connection-
mark=https_conn protocol=tcp
add action=mark-packet chain=prerouting connection-mark=https_conn new-packet-mark=https
passthrough=no
add action=mark-connection chain=prerouting comment=WoW dst-port=3724,6112-6114,6881-6999 new-
connection-mark=wow_conn \
protocol=tcp
add action=mark-packet chain=prerouting connection-mark=wow_conn new-packet-mark=wow
passthrough=no
add action=mark-connection chain=prerouting dst-port=3724 new-connection-mark=wow_udp_conn
protocol=udp
add action=mark-packet chain=prerouting connection-mark=wow_udp_conn new-packet-mark=wow_udp
passthrough=no
add action=mark-connection chain=prerouting comment=MSN dst-port=1863 new-connection-
mark=msn_conn protocol=tcp
add action=mark-packet chain=prerouting connection-mark=msn_conn new-packet-mark=msn
passthrough=no
add action=mark-connection chain=prerouting comment=Winbox dst-port=8291 new-connection-
mark=winbox_conn protocol=tcp
add action=mark-packet chain=prerouting connection-mark=winbox_conn new-packet-mark=winbox
passthrough=no
add action=mark-connection chain=prerouting comment=Otros new-connection-mark=otras_conn
add action=mark-packet chain=prerouting connection-mark=otras_conn new-packet-mark=other
passthrough=no
add action=mark-connection chain=postrouting comment="Cache webproxy" dscp=4 new-connection-
mark=cache_pkt
add action=mark-packet chain=postrouting dscp=4 new-packet-mark=cache_pkt passthrough=no

/queue tree
add name=QoS_down parent=LAN priority=1 queue=default
add name=3QoS_down_Web parent=QoS_down priority=5 queue=default
add name="2QoS_down_Games and Video" parent=QoS_down priority=2 queue=default
add name=1QoS_down_VoIP parent=QoS_down priority=1 queue=default
add name=WinBox packet-mark=winbox parent=1QoS_down_VoIP priority=2 queue=default
add name=MSN packet-mark=msn parent=3QoS_down_Web priority=5 queue=default
add name=DNS packet-mark=dns parent=3QoS_down_Web priority=5 queue=default
add name=WoW packet-mark=wow parent="2QoS_down_Games and Video" priority=2 queue=default
add name=WoW_udp packet-mark=wow_udp parent="2QoS_down_Games and Video" priority=2
queue=default
add name=Otros packet-mark=other parent=3QoS_down_Web priority=7 queue=default
add name=QoS_up parent=WAN priority=1 queue=default
add name=1QoS_up_VoIP parent=QoS_up priority=1 queue=default
add name="2QoS_up_Games and Video" parent=QoS_up priority=2 queue=default
add name=3QoS_up_Web parent=QoS_up priority=5 queue=default
add name=DNS_up packet-mark=dns parent=3QoS_up_Web priority=5 queue=default
add name=Otros_up packet-mark=other parent=3QoS_up_Web priority=6 queue=default
add name=WinBox_up packet-mark=winbox parent=1QoS_up_VoIP priority=2 queue=default
add name=MSN_up packet-mark=msn parent=3QoS_up_Web priority=5 queue=default
add name=WoW_up packet-mark=wow parent="2QoS_up_Games and Video" priority=2 queue=default
add name=WoW_udp_up packet-mark=wow_udp parent="2QoS_up_Games and Video" priority=2
queue=default
add name=Youtube_Down packet-mark=youtube_in parent="2QoS_down_Games and Video" priority=2
queue=default
add name=Vevo_Down packet-mark=vevo_in parent="2QoS_down_Games and Video" priority=2
queue=default
add name=Netflix_Down packet-mark=netflix_in parent="2QoS_down_Games and Video" priority=2
queue=default
add name=Hulu_Down packet-mark=hulu_in parent="2QoS_down_Games and Video" priority=2
queue=default
add name="Otros Videos" packet-mark=video_in parent="2QoS_down_Games and Video" priority=2
queue=default
add name="\"==PING_CONDITION==\"" packet-mark=ICMP_PACKET parent=1QoS_down_VoIP priority=1
queue=default
add name="Paket Browsing" packet-mark=browsing-packet parent=3QoS_down_Web queue=default
add name="Paket Download" packet-mark=download-packet parent=3QoS_down_Web queue=default
add name="\"==PING_CONDITION Up==\"" packet-mark=ICMP_PACKET parent=1QoS_up_VoIP priority=1
queue=default
add name=Hulu_up packet-mark=hulu_in parent="2QoS_up_Games and Video" priority=2 queue=default
add name=Vevo_up packet-mark=vevo_in parent="2QoS_up_Games and Video" priority=2 queue=default
add name=Youtube_up packet-mark=youtube_in parent="2QoS_up_Games and Video" priority=2
queue=default
add name="Paket Browsing up" packet-mark=browsing-packet parent=3QoS_up_Web queue=default
add name="Paket Download up" packet-mark=download-packet parent=3QoS_up_Web queue=default
add name=Netflix_up packet-mark=netflix_in parent="2QoS_up_Games and Video" priority=2
queue=default
add name="Otros Videos up" packet-mark=video_in parent="2QoS_up_Games and Video" priority=2
queue=default
add name="WebProxy Down" packet-mark=cache_pkt parent=1QoS_down_VoIP priority=1 queue=default
add name="WebProxy up" packet-mark=cache_pkt parent=1QoS_up_VoIP priority=1 queue=default
add name="Https Down" packet-mark=https parent=3QoS_down_Web queue=default
add name="Https up" packet-mark=https parent=3QoS_up_Web queue=default
/ip firewall layer7-protocol
add name=facebook regexp="^.*(facebook).*\$"
add name=fbcdn regexp="^.*(fbcdn).*\$"
add name=googlevideo regexp="^.*(googlevideo).*\$"
add name=steamcontent regexp="^.*(steamcontent).*\$"
add name=steampowered regexp="^.*(steampowered).*\$"

/ip firewall filter


add action=drop chain=forward comment="BLOQUEAR YOUTUBE HTTPS EN TODOS LOS
BROWSER DST." disabled=no dst-address=0.0.0.0/0 \
dst-port=443 layer7-protocol=www.youtube.com protocol=tcp
add action=drop chain=forward comment="BLOQUEAR YOUTUBE HTTPS EN TODOS LOS
BROWSER SRC." disabled=no layer7-protocol=\
www.youtube.com protocol=tcp src-address=0.0.0.0/0 src-port=443
add action=drop chain=forward comment="BLOQUEAR YOUTUBE HTTP EN TODOS LOS
BROWSER DST." disabled=no dst-address=0.0.0.0/0 \
dst-port=80 layer7-protocol=www.youtube.com protocol=tcp
add action=drop chain=forward comment="BLOQUEAR YOUTUBE HTTP EN TODOS LOS
BROWSER SRC." disabled=no layer7-protocol=\
www.youtube.com protocol=tcp src-address=0.0.0.0/0 src-port=80

Вам также может понравиться