Hirdetés

Új hozzászólás Aktív témák

  • szuszinho

    őstag

    Sziasztok,

    Mi lehet a hiba, ha egyes oldalak nem jönnek be (pl.: yahoo) a böngészőben, de pingre jön válasz.
    Akármit állítok DNS-nek, 1.1.1.1, 8.8.8.8, nem oldja meg.

    /ip firewall filter
    add action=accept chain=input comment="VPN access" dst-port=13231 protocol=udp
    add action=accept chain=forward dst-address=192.168.200.0/24 src-address=\
        192.168.100.0/24
    add action=accept chain=forward dst-address=192.168.100.0/24 src-address=\
        192.168.200.0/24
    add action=accept chain=input comment="Allow to LAN not from LTE1" \
        in-interface=!lte1 src-address=192.0.0.0/8
    add action=drop chain=input comment="Drop invalid packets" connection-state=\
        invalid in-interface=lte1
    add action=accept chain=input comment="Allow est. rel. packets" \
        connection-state=established,related in-interface=lte1
    add action=drop chain=input comment="drop blacklist" src-address-list=blacklist
    add action=drop chain=forward src-address-list=blacklist
    add action=drop chain=input comment="Drop russian belarus IPs" \
        src-address-list=CountryIPBlocks
    add action=drop chain=output dst-address-list=CountryIPBlocks
    add action=add-src-to-address-list address-list=blacklist address-list-timeout=\
        1w7h chain=input comment="ports to blacklist" dst-port=\
        20-1023,8000,8080,8291 protocol=tcp src-address-list=!home
    add action=add-src-to-address-list address-list=blacklist address-list-timeout=\
        1w7h chain=input dst-port=20-1023,8000,8080,8291 protocol=udp \
        src-address-list=!home
    add action=drop chain=input comment="port scanners" protocol=tcp psd=21,3s,3,1

Új hozzászólás Aktív témák