Сравнение Firewall
Добавлено: 06 дек 2017, 04:08
Есть два фаервола: первый - рабочий безпроблемный, второй - явно с уязвимостью по 53 порту. Помогите разобраться что во втором фильтре не так?
первый:
/ip firewall filter
add action=accept chain=input dst-port=8291 in-interface=tap1-wan protocol=\
tcp
add action=accept chain=forward
add action=accept chain=input protocol=icmp
add action=accept chain=input connection-state=established,related
add action=drop chain=input in-interface=tap1-wan
add action=fasttrack-connection chain=forward connection-state=\
established,related
add action=accept chain=forward connection-state=established,related
add action=drop chain=forward connection-state=invalid
add action=drop chain=forward connection-nat-state=!dstnat connection-state=\
new in-interface=tap1-wan
add action=drop chain=input in-interface=tap1-wan
второй:
/ip firewall filter
add action=accept chain=input protocol=icmp
add action=accept chain=forward protocol=icmp
add action=accept chain=input connection-state=established
add action=accept chain=forward connection-state=established
add action=accept chain=input connection-state=related
add action=accept chain=forward connection-state=related
add action=accept chain=input in-interface=!eth1-wan src-address=\
192.168.88.0/24
add chain=forward action=accept protocol=tcp in-interface=!eth1-wan dst-port=5900
add action=accept chain=input dst-port=8291 in-interface=tap1-wan protocol=\
tcp
add action=drop chain=input connection-state=invalid
add action=drop chain=forward connection-state=invalid
add action=drop chain=input in-interface=eth1-wan
add action=accept chain=forward comment="\E4\EE\F1\F2\F3\EF \E2 \E8\ED\F2\E5\
\F0\ED\E5\F2 \E8\E7 \EB\EE\EA\E0\EB\FC\ED\EE\E9 \F1\E5\F2\E8" \
dst-address=10.30.10.102 in-interface=!tap1-wan \
out-interface=tap1-wan protocol=tcp
add action=accept chain=forward comment="\E4\EE\F1\F2\F3\EF \EA ftp" \
dst-address=10.30.10.98 dst-port=21 in-interface=!tap1-wan \
out-interface=tap1-wan protocol=tcp
add action=accept chain=forward comment="\E4\EE\F1\F2\F3\EF \EA ofd.ru" \
dst-address=10.30.10.18 in-interface=!tap1-wan out-interface=tap1-wan \
protocol=tcp
add action=accept chain=forward comment="\E4\EE\F1\F2\F3\EF \EA Royal Bank" \
dst-address=10.30.10.119 in-interface=!tap1-wan out-interface=tap1-wan \
protocol=tcp
add action=accept chain=forward comment="\E4\EE\F1\F2\F3\EF \EA Royal Bank" \
dst-address=10.30.10.120 in-interface=!tap1-wan out-interface=tap1-wan \
protocol=tcp
add action=drop chain=forward
первый:
/ip firewall filter
add action=accept chain=input dst-port=8291 in-interface=tap1-wan protocol=\
tcp
add action=accept chain=forward
add action=accept chain=input protocol=icmp
add action=accept chain=input connection-state=established,related
add action=drop chain=input in-interface=tap1-wan
add action=fasttrack-connection chain=forward connection-state=\
established,related
add action=accept chain=forward connection-state=established,related
add action=drop chain=forward connection-state=invalid
add action=drop chain=forward connection-nat-state=!dstnat connection-state=\
new in-interface=tap1-wan
add action=drop chain=input in-interface=tap1-wan
второй:
/ip firewall filter
add action=accept chain=input protocol=icmp
add action=accept chain=forward protocol=icmp
add action=accept chain=input connection-state=established
add action=accept chain=forward connection-state=established
add action=accept chain=input connection-state=related
add action=accept chain=forward connection-state=related
add action=accept chain=input in-interface=!eth1-wan src-address=\
192.168.88.0/24
add chain=forward action=accept protocol=tcp in-interface=!eth1-wan dst-port=5900
add action=accept chain=input dst-port=8291 in-interface=tap1-wan protocol=\
tcp
add action=drop chain=input connection-state=invalid
add action=drop chain=forward connection-state=invalid
add action=drop chain=input in-interface=eth1-wan
add action=accept chain=forward comment="\E4\EE\F1\F2\F3\EF \E2 \E8\ED\F2\E5\
\F0\ED\E5\F2 \E8\E7 \EB\EE\EA\E0\EB\FC\ED\EE\E9 \F1\E5\F2\E8" \
dst-address=10.30.10.102 in-interface=!tap1-wan \
out-interface=tap1-wan protocol=tcp
add action=accept chain=forward comment="\E4\EE\F1\F2\F3\EF \EA ftp" \
dst-address=10.30.10.98 dst-port=21 in-interface=!tap1-wan \
out-interface=tap1-wan protocol=tcp
add action=accept chain=forward comment="\E4\EE\F1\F2\F3\EF \EA ofd.ru" \
dst-address=10.30.10.18 in-interface=!tap1-wan out-interface=tap1-wan \
protocol=tcp
add action=accept chain=forward comment="\E4\EE\F1\F2\F3\EF \EA Royal Bank" \
dst-address=10.30.10.119 in-interface=!tap1-wan out-interface=tap1-wan \
protocol=tcp
add action=accept chain=forward comment="\E4\EE\F1\F2\F3\EF \EA Royal Bank" \
dst-address=10.30.10.120 in-interface=!tap1-wan out-interface=tap1-wan \
protocol=tcp
add action=drop chain=forward