• RouterOS软路由防火墙禁止公网端口扫描


    https://www.ros9.com/866.html

    https://www.ros9.com/index.php/soft-routing/ros-course

    /ip firewall filter

    add action=add-src-to-address-list address-list="port scanners" \

    address-list-timeout=2w chain=input comment="port scanners to list " \

    protocol=tcp psd=21,3s,3,1

    add action=add-src-to-address-list address-list="port scanners" \

    address-list-timeout=2w chain=input comment="NMAP FIN Stealth scan" \

    protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg

    add action=add-src-to-address-list address-list="port scanners" \

    address-list-timeout=2w chain=input comment="SYN/FIN scan" protocol=tcp \

    tcp-flags=fin,syn

    add action=add-src-to-address-list address-list="port scanners" \

    address-list-timeout=2w chain=input comment="SYN/RST scan" protocol=tcp \

    tcp-flags=syn,rst

    add action=add-src-to-address-list address-list="port scanners" \

    address-list-timeout=2w chain=input comment="FIN/PSH/URG scan" protocol=\

    tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack

    add action=add-src-to-address-list address-list="port scanners" \

    address-list-timeout=2w chain=input comment="ALL/ALL scan" protocol=tcp \

    tcp-flags=fin,syn,rst,psh,ack,urg

    add action=add-src-to-address-list address-list="port scanners" \

    address-list-timeout=2w chain=input comment="NMAP NULL scan" protocol=tcp \

    tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg

    add action=drop chain=input comment="dropping port scanners" \

    src-address-list="port scanners"

  • 相关阅读:
    ASP.NET Web API 记录请求响应数据到日志的一个方法
    EF删除集中方法对比
    CSS 的优先级机制[总结]
    sql备份命令
    sql两张表关联更新字段
    VSCode隐藏node_modules目录
    C# RSACryptoServiceProvider加密解密签名验签和DESCryptoServic
    模拟退火(转)
    HNOI2006-鬼谷子的钱袋
    HNOI2006-公路修建问题(二分答案+并查集)
  • 原文地址:https://www.cnblogs.com/walkersss/p/16803412.html
Copyright © 2020-2023  润新知