以下是引用片段:
/ip firewall filter add chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list address-list="port scanners" address-list-timeout=14d comment="Port scanners to list " disabled=no
/ip firewall filter add chain=input protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list address-list="port scanners" address-list-timeout=14d comment="NMAP FIN Stealth scan"
/ip firewall filter add chain=input protocol=tcp tcp-flags=fin,syn action=add-src-to-address-list address-list="port scanners" address-list-timeout=14d comment="SYN/FIN scan"
/ip firewall filter add chain=input protocol=tcp tcp-flags=syn,rst action=add-src-to-address-list address-list="port scanners" address-list-timeout=14d comment="SYN/RST scan"
/ip firewall filter add chain=input protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack action=add-src-to-address-list address-list="port scanners" address-list-timeout=14d comment="FIN/PSH/URG scan"
/ip firewall filter add chain=input protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg action=add-src-to-address-list address-list="port scanners" address-list-timeout=14d comment="ALL/ALL scan"
/ip firewall filter add chain=input protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list address-list="port scanners" address-list-timeout=14d comment="NMAP NULL scan"
/ip firewall filter add chain=input src-address-list="port scanners" action=drop comment="dropping port scanners" disabled=no
斩断扫描你的RouterOS的黑手几个小规则
来源:网管联盟
作者:κ.ì.sSロ觜
点击:loading...
时间:2007-06-28
Tag:
0
以下只显示最新 20 条评论 查看所有评论
top
发表评论
相关文章
热点关注
- ADSL两线负载均衡设置详细
- winbox中文版使用说明
- 电信网通路由表-网通官方
- routeros电信+网通双线策
- RouterOS限速脚本+ 限线程
- 配置RouterOS VPN-L2TP服
- RouterOS的防火墙,中文注
- routeros限速更高层次运用
- m0n0wall安装教程
- RouterOS菜鸟篇教你一步一
- ros映射FTP外网不能访问
- 1000gwall安装与1U硬件防
- 从网络安装m0n0,VMWARE安
- 斩断扫描你的RouterOS的黑
- 流控精灵管理、修整数据流
- RouterOS双线负载均衡
- RouterOS2.9系列所支持的
- RouterOS基础知识普及贴关
- routeros在网通电信双线路
- 几个常用软路由的主页汇聚
