Portál AbcLinuxu, 12. května 2025 18:16
/ip firewall filter add chain=input comment="Povolen PING" limit=50/5s,2 protocol=icmp add action=drop chain=input protocol=icmp add action=drop chain=forward comment="filter NetBios" dst-port=135-139 protocol=udp add action=drop chain=forward dst-port=135-139 protocol=tcp add action=drop chain=forward protocol=udp src-port=135-139 add action=drop chain=forward protocol=tcp src-port=135-139 add action=drop chain=forward protocol=tcp src-port=445 add action=drop chain=forward protocol=udp src-port=445 add action=drop chain=forward comment="Omezeni P2P" p2p=all-p2p protocol=tcp add action=drop chain=input p2p=all-p2p protocol=tcp add action=drop chain=output p2p=all-p2p protocol=tcp add chain=input comment=Input connection-state=established add chain=input connection-state=new in-interface=LAN1 add chain=input connection-state=related add chain=input disabled=yes dst-port=443 in-interface=WAN protocol=tcp add chain=input disabled=yes dst-port=80 in-interface=WAN protocol=tcp add chain=input disabled=yes dst-port=22 in-interface=WAN protocol=tcp add action=drop chain=input in-interface=WAN protocol=tcp add action=drop chain=input connection-state=invalid add chain=forward comment=Forward connection-state=established add chain=forward connection-state=new add chain=forward connection-state=related add action=drop chain=forward connection-state=invalid add chain=output comment=Output connection-state=established add chain=output connection-state=new add chain=output connection-state=related add action=drop chain=output connection-state=invalid /ip firewall nat add action=masquerade chain=srcnat comment="Internet" out-interface=WAN src-address=10.0.0.0/8 add action=masquerade chain=srcnat comment=Maskarada src-address=192.168.1.0/24 add action=dst-nat chain=dstnat comment="Port forwarding" dst-port=22 in-interface=WAN protocol=tcp to-addresses=10.0.0.50 to-ports=22 add action=dst-nat chain=dstnat dst-port=8082 in-interface=WAN protocol=tcp to-addresses=10.0.2.12 to-ports=22 add action=dst-nat chain=dstnat dst-port=8081 in-interface=WAN protocol=tcp to-addresses=10.0.3.254 to-ports=22 Edit, mikrotik se pingne jak na 10.0.2.12 tak 10.0.3.254
Řešení dotazu:
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.