防止別人掃描你的routeros

/ip firewall filter add chain=input protocol=tcp psd=21,3s,3,1  action=add-src-to-address-list address-list="port scanners"  address-list-timeout=14d comment="Port scanners to list " disabled=no

/ip firewall filter add chain=input protocol=tcp  tcp-flags=fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list  address-list="port scanners" address-list-timeout=14d comment="NMAP FIN  Stealth scan"

/ip firewall filter add chain=input protocol=tcp tcp-flags=fin,syn  action=add-src-to-address-list address-list="port scanners"  address-list-timeout=14d comment="SYN/FIN scan"

/ip firewall filter add chain=input protocol=tcp tcp-flags=syn,rst  action=add-src-to-address-list address-list="port scanners"  address-list-timeout=14d comment="SYN/RST scan"

/ip firewall filter add chain=input protocol=tcp  tcp-flags=fin,psh,urg,!syn,!rst,!ack action=add-src-to-address-list  address-list="port scanners" address-list-timeout=14d  comment="FIN/PSH/URG scan"

/ip firewall filter add chain=input protocol=tcp  tcp-flags=fin,syn,rst,psh,ack,urg action=add-src-to-address-list  address-list="port scanners" address-list-timeout=14d comment="ALL/ALL  scan"

/ip firewall filter add chain=input protocol=tcp  tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list  address-list="port scanners" address-list-timeout=14d comment="NMAP NULL  scan"

/ip firewall filter add chain=input src-address-list="port scanners" action=drop comment="dropping port scanners" disabled=no

發佈留言

發佈留言必須填寫的電子郵件地址不會公開。

這個網站採用 Akismet 服務減少垃圾留言。進一步瞭解 Akismet 如何處理網站訪客的留言資料

分類
BlogUpp!