balance
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revision | |||
balance [2024/06/01 08:38] – protocol | balance [2024/06/01 09:49] (current) – protocol | ||
---|---|---|---|
Line 16: | Line 16: | ||
/ip firewall filter | /ip firewall filter | ||
- | add action=drop | + | add chain=input connection-state=invalid action=drop |
- | add action=drop chain=forward connection-state=invalid | + | add chain=forward connection-state=invalid |
- | add action=fasttrack-connection | + | add chain=forward connection-state=established, |
- | add action=accept | + | add chain=forward connection-state=established, |
- | add action=drop chain=output connection-state=invalid | + | add chain=output connection-state=invalid |
/ip firewall nat | /ip firewall nat | ||
- | add action=masquerade | + | add chain=srcnat src-address-list=private dst-address=!private out-interface-list=wan |
/ip firewall mangle | /ip firewall mangle | ||
- | add action=mark-connection | + | add chain=prerouting in-interface=ether1 connection-mark=no-mark new-connection-mark=mark-connection-ether1 action=mark-connection |
- | add action=mark-connection chain=prerouting in-interface=ether2 connection-mark=no-mark new-connection-mark=mark-connection-ether2 passthrough=yes | + | add chain=prerouting in-interface=ether2 connection-mark=no-mark new-connection-mark=mark-connection-ether2 |
- | add action=mark-connection | + | add chain=prerouting connection-mark=no-mark new-connection-mark=mark-connection-ether1 passthrough=yes src-address-list=force-ether1 action=mark-connection |
- | add action=mark-connection chain=prerouting connection-mark=no-mark dst-address-list=force-ether1 new-connection-mark=mark-connection-ether1 passthrough=yes | + | add chain=prerouting connection-mark=no-mark dst-address-list=force-ether1 new-connection-mark=mark-connection-ether1 passthrough=yes action=mark-connection |
- | add action=mark-connection chain=prerouting connection-mark=no-mark new-connection-mark=mark-connection-ether2 passthrough=yes src-address-list=force-ether2 | + | add chain=prerouting connection-mark=no-mark new-connection-mark=mark-connection-ether2 passthrough=yes src-address-list=force-ether2 action=mark-connection |
- | add action=mark-connection chain=prerouting connection-mark=no-mark dst-address-list=force-ether2 new-connection-mark=mark-connection-ether2 passthrough=yes | + | add chain=prerouting connection-mark=no-mark dst-address-list=force-ether2 new-connection-mark=mark-connection-ether2 passthrough=yes |
- | add action=mark-connection | + | add chain=prerouting comment=PCC connection-mark=no-mark src-address-list=private dst-address-list=!private dst-address-type=!local in-interface-list=lan new-connection-mark=mark-connection-ether1 passthrough=yes per-connection-classifier=src-address: |
- | add action=mark-connection chain=prerouting comment=PCC connection-mark=no-mark src-address-list=private dst-address-list=!private dst-address-type=!local in-interface-list=lan new-connection-mark=mark-connection-ether2 passthrough=yes per-connection-classifier=src-address: | + | add chain=prerouting comment=PCC connection-mark=no-mark src-address-list=private dst-address-list=!private dst-address-type=!local in-interface-list=lan new-connection-mark=mark-connection-ether2 passthrough=yes per-connection-classifier=src-address: |
- | add action=mark-routing | + | add chain=prerouting connection-mark=mark-connection-ether1 in-interface-list=lan new-routing-mark=mark-routing-ether1 passthrough=yes action=mark-routing |
- | add action=mark-routing chain=prerouting connection-mark=mark-connection-ether2 in-interface-list=lan new-routing-mark=mark-routing-ether2 passthrough=yes | + | add chain=prerouting connection-mark=mark-connection-ether2 in-interface-list=lan new-routing-mark=mark-routing-ether2 passthrough=yes |
- | add action=mark-routing | + | add chain=output connection-mark=mark-connection-ether1 new-routing-mark=mark-routing-ether1 action=mark-routing |
- | add action=mark-routing chain=output connection-mark=mark-connection-ether2 new-routing-mark=mark-routing-ether2 passthrough=yes | + | add chain=output connection-mark=mark-connection-ether2 new-routing-mark=mark-routing-ether2 |
/ip firewall raw | /ip firewall raw | ||
- | add action=drop | + | add chain=prerouting in-interface-list=!wan protocol=tcp action=drop |
- | add action=drop chain=prerouting | + | add chain=prerouting in-interface-list=wan |
- | add action=drop | + | add chain=prerouting in-interface-list=wan |
</ | </ |
balance.1717241937.txt.gz · Last modified: 2024/06/01 08:38 by protocol