## Filter 规则 10 条 + 虚拟规则 1 条 ## NAT 规则 3 条 ## Mangle 规则 1 条 + 虚拟规则 3 条 ## Raw 规则 34 条 + 虚拟规则 1 条 ## Address-list 规则 20 条 /ip firewall address-list add address=172.16.1.0/24 comment="defconf: local LAN IPv4 subnet" list=local_subnet_ipv4 add address=0.0.0.0/8 comment="defconf: RFC6890 - this network" list=no_forward_ipv4 add address=169.254.0.0/16 comment="defconf: RFC6890 - link local" list=no_forward_ipv4 add address=224.0.0.0/4 comment="defconf: RFC5771 - multicast" list=no_forward_ipv4 add address=255.255.255.255/32 comment="defconf: RFC6890 - limited broadcast" list=no_forward_ipv4 add address=127.0.0.0/8 comment="defconf: RFC6890 - Loopback" list=bad_ipv4 add address=192.0.0.0/24 comment="defconf: RFC6890 - reserved" list=bad_ipv4 add address=192.0.2.0/24 comment="defconf: RFC6890 - TEST-NET-1" list=bad_ipv4 add address=198.51.100.0/24 comment="defconf: RFC6890 - TEST-NET-2" list=bad_ipv4 add address=203.0.113.0/24 comment="defconf: RFC6890 - TEST-NET-3" list=bad_ipv4 add address=240.0.0.0/4 comment="defconf: RFC6890 - reserved" list=bad_ipv4 add address=0.0.0.0/8 comment="defconf: RFC6890 - this network" list=not_global_ipv4 add address=100.64.0.0/10 comment="defconf: RFC6890 - shared address" list=not_global_ipv4 add address=169.254.0.0/16 comment="defconf: RFC6890 - link local" list=not_global_ipv4 add address=192.0.0.0/29 comment="defconf: RFC6890 - DS-Lite" list=not_global_ipv4 add address=198.18.0.0/15 comment="defconf: RFC6890 - benchmarking" list=not_global_ipv4 add address=255.255.255.255/32 comment="defconf: RFC6890 - limited broadcast" list=not_global_ipv4 add address=224.0.0.0/4 comment="defconf: RFC5771 - multicast" list=bad_src_ipv4 add address=255.255.255.255/32 comment="defconf: RFC6890 - limited broadcast" list=bad_src_ipv4 add address=0.0.0.0/8 comment="defconf: RFC6890 - this network" list=bad_dst_ipv4 /ip firewall filter add action=accept chain=input comment="defconf: accept ICMP after RAW" protocol=icmp add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid add action=drop chain=input comment="defconf: drop all not from LAN" in-interface-list=!LAN add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related add action=accept chain=forward comment="defconf: accept established,related,untracked" connection-state=established,related,untracked add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat in-interface-list=WAN log=yes log-prefix="[wan-not-dnat]" add action=drop chain=forward comment="defconf: drop bad forward IPs" src-address-list=no_forward_ipv4 add action=drop chain=forward comment="defconf: drop bad forward IPs" dst-address-list=no_forward_ipv4 /ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade IPv4" out-interface-list=WAN add action=redirect chain=dstnat comment="lanconf: redirect DNS query (UDP)" dst-port=53 in-interface-list=LAN protocol=udp to-ports=53 add action=redirect chain=dstnat comment="lanconf: redirect DNS query (TCP)" dst-port=53 in-interface-list=LAN protocol=tcp to-ports=53 /ip firewall mangle add action=change-mss chain=forward comment="defconf: fix IPv4 mss for WAN" new-mss=clamp-to-pmtu passthrough=yes protocol=tcp tcp-flags=syn /ip firewall raw add action=accept chain=prerouting comment="defconf: enable for transparent firewall" disabled=yes add action=accept chain=prerouting comment="defconf: accept local Loopback" in-interface=lo add action=accept chain=prerouting comment="defconf: accept DHCPv4 discover" dst-address=255.255.255.255 dst-port=67 in-interface-list=LAN protocol=udp src-address=0.0.0.0 src-port=68 add action=drop chain=prerouting comment="defconf: drop bogon IPs" src-address-list=bad_ipv4 add action=drop chain=prerouting comment="defconf: drop bogon IPs" dst-address-list=bad_ipv4 add action=drop chain=prerouting comment="defconf: drop bad SRC IPv4" src-address-list=bad_src_ipv4 add action=drop chain=prerouting comment="defconf: drop bad DST IPv4" dst-address-list=bad_dst_ipv4 add action=drop chain=prerouting comment="defconf: drop non global from WAN" in-interface-list=WAN src-address-list=not_global_ipv4 add action=drop chain=prerouting comment="defconf: drop forward to local LAN from WAN" in-interface-list=WAN dst-address-list=local_subnet_ipv4 log=yes log-prefix="[wan-to-lan]" add action=drop chain=prerouting comment="defconf: drop if not from default IPv4 range" in-interface-list=LAN src-address-list=!local_subnet_ipv4 add action=drop chain=prerouting comment="defconf: drop UDP port 0" port=0 protocol=udp log=yes log-prefix="[udp-port-0]" add action=jump chain=prerouting comment="defconf: jump to TCP chain" jump-target=bad-tcp protocol=tcp add action=jump chain=prerouting comment="defconf: jump to ICMP chain" jump-target=icmp4 protocol=icmp add action=accept chain=prerouting comment="defconf: accept everything else from LAN" in-interface-list=LAN add action=accept chain=prerouting comment="defconf: accept everything else from WAN" in-interface-list=WAN add action=accept chain=prerouting comment="defconf: accept inter-interface router traffic" src-address-type=local add action=drop chain=prerouting comment="defconf: drop the rest" add action=drop chain=bad-tcp comment="defconf: drop TCP port 0" port=0 protocol=tcp log=yes log-prefix="[tcp-port-0]" add action=drop chain=bad-tcp comment="defconf: TCP flag filter" protocol=tcp tcp-flags=!fin,!syn,!rst,!ack add action=drop chain=bad-tcp comment="defconf: drop flags fin,syn" protocol=tcp tcp-flags=fin,syn add action=drop chain=bad-tcp comment="defconf: drop flags fin,rst" protocol=tcp tcp-flags=fin,rst add action=drop chain=bad-tcp comment="defconf: drop flags fin,!ack" protocol=tcp tcp-flags=fin,!ack add action=drop chain=bad-tcp comment="defconf: drop flags fin,urg" protocol=tcp tcp-flags=fin,urg add action=drop chain=bad-tcp comment="defconf: drop flags syn,rst" protocol=tcp tcp-flags=syn,rst add action=drop chain=bad-tcp comment="defconf: drop flags rst,urg" protocol=tcp tcp-flags=rst,urg add action=accept chain=icmp4 comment="defconf: rfc4884 echo reply" icmp-options=0:0 protocol=icmp add action=accept chain=icmp4 comment="defconf: rfc4884 host unreachable" icmp-options=3:1 protocol=icmp add action=accept chain=icmp4 comment="defconf: rfc4884 port unreachable" icmp-options=3:3 protocol=icmp add action=accept chain=icmp4 comment="defconf: rfc4884 fragmentation needed" icmp-options=3:4 protocol=icmp add action=accept chain=icmp4 comment="defconf: rfc4884 echo request" icmp-options=8:0 protocol=icmp add action=accept chain=icmp4 comment="defconf: rfc4884 time exceeded" icmp-options=11:0-255 protocol=icmp add action=accept chain=icmp4 comment="defconf: rfc4884 net unreachable only LAN" icmp-options=3:0 in-interface-list=LAN protocol=icmp add action=accept chain=icmp4 comment="defconf: rfc4884 protocol unreachable only LAN" icmp-options=3:2 in-interface-list=LAN protocol=icmp add action=drop chain=icmp4 comment="defconf: drop all other ICMP" protocol=icmp /ip firewall connection tracking set tcp-syn-sent-timeout=120s set tcp-syn-received-timeout=60s set tcp-established-timeout=7440s set tcp-fin-wait-timeout=120s set tcp-close-wait-timeout=60s set tcp-last-ack-timeout=30s set tcp-time-wait-timeout=120s set tcp-close-timeout=10s set tcp-max-retrans-timeout=300s set tcp-unacked-timeout=300s set udp-timeout=30s set udp-stream-timeout=120s set icmp-timeout=30s set generic-timeout=600s