Mikrotik RouterOS系统缺省防火墙规则

简介

如果你的Mikrotik 的 RouterBoard 硬件产品或者x86/CHR,没有默认的防火墙规则或者你不小心删除了防火墙的

规则,那么这里专门整理出来一份留档记录分享给有需要的人,你可以重新进行导入。

 

防火墙规则

Interface List,根据自己情况适当修改

/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface list member
add interface=bridge list=LAN
add interface=ether1 list=WAN
add interface=pppoe-out1 list=WAN

IPv4 防火墙规则

/ip firewall filter
add action=accept chain=input comment="accept ping" protocol=icmp
add action=accept chain=input comment="accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="drop invalid" connection-state=invalid
add action=drop chain=input comment="drop all from WAN" in-interface-list=WAN
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
add action=accept chain=forward comment="accept established,related, untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="drop invalid" connection-state=invalid
add action=drop chain=forward comment="drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN

IPv6 防火墙规则,需要启用 IPv6 package 后再导入

/ipv6 firewall address-list
add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
add address=::1/128 comment="defconf: lo" list=bad_ipv6
add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
add address=100::/64 comment="defconf: discard only " list=bad_ipv6
add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6
add address=::224.0.0.0/100 comment="defconf: other" list=bad_ipv6
add address=::127.0.0.0/104 comment="defconf: other" list=bad_ipv6
add address=::/104 comment="defconf: other" list=bad_ipv6
add address=::255.0.0.0/104 comment="defconf: other" list=bad_ipv6
/ipv6 firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMPv6" protocol=icmpv6
add action=accept chain=input comment="defconf: accept UDP traceroute" port=33434-33534 protocol=udp
add action=accept chain=input comment="defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=udp src-address=fe80::/16
add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
add action=accept chain=input comment="defconf: accept ipsec AH" protocol=ipsec-ah
add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=ipsec-esp
add action=accept chain=input comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=input comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" hop-limit=equal:1 protocol=icmpv6
add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=icmpv6
add action=accept chain=forward comment="defconf: accept HIP" protocol=139
add action=accept chain=forward comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=ipsec-ah
add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=ipsec-esp
add action=accept chain=forward comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=forward comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN
上一篇 OpenWrt TF卡/SD卡 完美扩容Overlay 真扩容 小白也能掌握的新方法
下一篇 教你删除Windows中多余的网络连接

投稿邮箱:
ivpsr888@gmail.com (投稿详情)

TG订阅频道:
t.me/ivpsr_news 网站最新内容推送

TG交流群:
(点击加入) 用户交流

文章列表
1
raksmart开年大吉,低至$0.99/月起,香港、美国、日本机房可选,不限流量,全场7折优惠
raksmart开年大吉,低至$0.99/月起,香港、美国、日本机房可选,不限流量,全场7折优惠
2
Layer.ae:特惠仅$4.99/月,荷兰VPS,AMD Ryzen 9950X/2GB内存/50GB NVMe存储/3T流量/10Gbps带宽
Layer.ae:特惠仅$4.99/月,荷兰VPS,AMD Ryzen 9950X/2GB内存/50GB NVMe存储/3T流量/10Gbps带宽
3
野草云2026促销香港VPS,年付99元起,独立服务器199元/月起,国际/优质/精品多网络可选
野草云2026促销香港VPS,年付99元起,独立服务器199元/月起,国际/优质/精品多网络可选
4
DediPath:2021秋季持续特卖,全场VPS和混合服务器降价至4折,至强 E3-1230v3独立服务器低至$39/月
DediPath:2021秋季持续特卖,全场VPS和混合服务器降价至4折,至强 E3-1230v3独立服务器低至$39/月
5
inetWS法国巴黎VPS测评,原生IP 7.5折$3/月起,解锁TikTok/ Netflix/ChatGPT等多平台
inetWS法国巴黎VPS测评,原生IP 7.5折$3/月起,解锁TikTok/ Netflix/ChatGPT等多平台
6
RAKsmart德国站群服务器最高32个C段/1012个独立IP,大陆优化网络$289/月起
RAKsmart德国站群服务器最高32个C段/1012个独立IP,大陆优化网络$289/月起
7
教你如何从ADNI数据集的下载教程
教你如何从ADNI数据集的下载教程
8
cloudcone:美国VPS优惠活动,低至21美元/年,1G内存/2核/30gSSD/1T流量/1Gbps带宽
cloudcone:美国VPS优惠活动,低至21美元/年,1G内存/2核/30gSSD/1T流量/1Gbps带宽
9
下载神器IDM v6.40.11 绿色版便携版
下载神器IDM v6.40.11 绿色版便携版
10
TikTok运营播放量低怎么解决
TikTok运营播放量低怎么解决