/ip firewall filter
/ip firewall filter
接受已经建立的连接
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
连接状态是invalid丢弃
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
除非是上面允许的数据,非本地数据丢弃
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
fasttrack作标记,上面的规则都通过,让他走快速通道
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
连接状态非法的丢弃
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
未经nat数据丢弃
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
© 允许规范转载