Professional Documents
Culture Documents
disabled=yes
add chain=forward action=accept comment="" disabled=yes
add chain=forward protocol=tcp tcp-flags=syn,rst tcp-mss=1400-1536 \
action=accept comment="Disminuye MMS MTU menos cabeceras IP y TCP" \
disabled=yes
add chain=forward action=jump jump-target=drop-p2p comment="Drop P2P " \
disabled=no
add chain=input action=jump jump-target=drop comment="Dropping IP no \
permitidas " disabled=no
add chain=forward action=jump jump-target=drop comment="Dropping NetBios" \
disabled=no
add chain=forward action=jump jump-target=virus comment="jump y drop to VIRUS \
chain" disabled=no
add chain=forward in-interface=Local out-interface=Local action=accept \
comment="Allow traffic between wired and wireless networks" disabled=no
add chain=forward action=jump jump-target=drop comment="Dropping IP no \
permitidas por DML" disabled=no
add chain=forward action=jump jump-target=Limit-Conn comment="Limito \
conexiones TCP" disabled=no
add chain=forward action=jump jump-target=sanity-check comment="Sanity Check" \
disabled=no
add chain=forward protocol=tcp action=jump jump-target=restrict-tcp \
comment="-------- Restric TCP" disabled=no
add chain=forward protocol=udp action=jump jump-target=restrict-udp \
comment="-------- Restric UDP" disabled=no
add chain=forward action=jump jump-target=restrict-ip comment="" disabled=no
add chain=restrict-tcp connection-mark=auth action=reject \
reject-with=icmp-network-unreachable comment="" disabled=no
add chain=restrict-tcp connection-mark=smtp action=jump \
jump-target=smtp-first-reject comment="anti-spam policy" disabled=no
add chain=smtp-first-drop src-address-list=first-smtp \
action=add-src-to-address-list address-list=approved-smtp \
address-list-timeout=0s comment="" disabled=no
add chain=smtp-first-drop src-address-list=approved-smtp action=return \
comment="" disabled=no
add chain=smtp-first-drop action=add-src-to-address-list \
address-list=first-smtp address-list-timeout=0s comment="" disabled=no
add chain=smtp-first-drop action=reject reject-with=icmp-network-unreachable \
comment="" disabled=no
add chain=restrict-tcp connection-mark=other-tcp action=jump jump-target=drop \
comment="" disabled=no
add chain=restrict-udp connection-mark=other-udp action=jump jump-target=drop \
comment="" disabled=no
add chain=restrict-ip connection-mark=other action=jump jump-target=drop \
comment="" disabled=no
add chain=input action=jump jump-target=drop comment="Dropping NetBios" \
disabled=no
add chain=input action=jump jump-target=Limit-Conn comment="Limito conexiones \
TCP" disabled=no
add chain=input action=jump jump-target=drop-p2p comment="Drop P2P " \
disabled=no
add chain=input src-address-type=local dst-address-type=local action=accept \
comment="Allow local traffic \(between router applications\)" disabled=no
add chain=input in-interface=Local protocol=udp src-port=68 dst-port=67 \
action=jump jump-target=dhcp comment="DHCP protocol would not pass sanity \