Вы находитесь на странице: 1из 2

/system scheduler

add comment= " disabled=no interval=1d name=Conficker-daily on-event= /system script


run daily-conficker-list start-date=jan/01/1970 start-time=00:00:01

ad chain=input connection-state=established action=accept comment= Aceptar conexio


nes establecidas disabled=no
ad chain=input connection-state=related action=accept comment= Aceptar related con
exiones disabled=no
ad chain=input connection-state=invalid action=drop comment= Rechazar conexiones i
nválidas disabled=no
add chain=input src-address=!10.10.17.0/24 src-address-list= Intentos SSH \
action=drop comment= Bloquear Lista SSH disabled=no
add chain=input src-address=!10.10.17.0/24 src-address-list= Lista Telnet \
action=drop comment= Bloquea Lista Telnet disabled=no
add chain=input src-address=!10.10.17.0/24 src-address-list= Bloqueo de \
Invalidos router action=drop comment= Bloqueo Lista de Invalidos \
disabled=no
add chain=input src-address=!10.10.17.0/24 src-address-list= Entradas por FTP \
action=drop comment= Bloquear Lista FTP disabled=no
add chain=input protocol=tcp dst-port=21 action=add-src-to-address-list \
address-list= Entradas por FTP address-list-timeout=0s comment= Crea \
Lista de IPs que entran al FTP disabled=no
add chain=input protocol=tcp dst-port=21 action=accept comment= Aceptar \
Conexiones FTP disabled=no
add chain=input protocol=tcp dst-port=80 action=add-src-to-address-list \
address-list= Accesos Via Web address-list-timeout=0s comment= Crea Lista \
de IPs que ven WebBox disabled=no
add chain=input protocol=tcp dst-port=80 action=accept comment= Acepta WebBox \
disabled=no
add chain=input protocol=udp action=accept comment= UDP disabled=no
add chain=input protocol=icmp limit=50/5s,2 action=accept comment= Aceptar \
pings limitados disabled=no
add chain=input protocol=icmp action=drop comment= Rechazar pings execibos \
disabled=no
add chain=input protocol=tcp dst-port=23 action=add-src-to-address-list \
address-list= Lista Telnet address-list-timeout=0s comment= Lista Telnet \
disabled=no
add chain=input protocol=tcp dst-port=23 action=accept comment= Acepta Telnet \
disabled=no
add chain=input protocol=tcp dst-port=22 action=add-src-to-address-list \
address-list= Intentos SSH address-list-timeout=0s comment= Crea Lista de \
Entradas SSH disabled=no
add chain=input protocol=tcp dst-port=22 action=accept comment= SSH \
disabled=no
add chain=input src-address=10.10.17.0/24 action=accept comment= Conexiones \
desde la red Local disabled=no
add chain=input protocol=tcp dst-port=8291 action=add-src-to-address-list \
address-list=Winbox address-list-timeout=0s comment= Agrega IPs Que entran \
por Winbox disabled=no
add chain=input protocol=tcp dst-port=8291 action=log log-prefix= Entrada por \
Winbox comment= Log entradas por Winbox disabled=no
add chain=input protocol=tcp dst-port=8291 action=accept comment= Winbox \
disabled=no
add chain=input protocol=tcp dst-port=23 action=accept comment= Aceptar \
Conexiones Telnet disabled=no
add chain=input action=add-src-to-address-list address-list= Bloqueo de \
Invalidos router address-list-timeout=0s comment= Lista de IP por \
acciones fuera de reglas disabled=no
add chain=input action=drop comment= Rechazar todo lo demás disabled=no

Вам также может понравиться