





--
ABCDE五版已完結.規則多次修正確認.這樣就能穩穩用.遠離那紛紛擾擾.



--
7-28更正:猴仔很開心解決了!
| /ip firewall mangle add action=change-mss chain=forward comment="Change MSS" \ new-mss=clamp-to-pmtu passthrough=yes protocol=tcp tcp-flags=syn add action=change-mss chain=output new-mss=clamp-to-pmtu \ passthrough=yes protocol=tcp tcp-flags=syn /ip firewall address-list add address=192.168.88.2-192.168.88.254 list=LAN /ip firewall nat add action=dst-nat chain=dstnat comment="NAT to LAN" \ dst-address=0.0.0.0/0 in-interface=pppoe-out1 \ to-addresses=192.168.88.0/24 /ip firewall nat add action=redirect chain=dstnat comment=\ "Block DNS Hijacking for Local area Network" \ dst-address-type=!local dst-port=53 \ protocol=udp src-address-type=!local /ip firewall nat add action=dst-nat chain=dstnat comment=\ "Force Users to Router for DNS - TCP" dst-port=53 \ protocol=tcp to-addresses=192.168.88.1 to-ports=53 add action=dst-nat chain=dstnat comment=\ "Force Users to Router for DNS - UDP" dst-port=53 \ protocol=udp to-addresses=192.168.88.1 to-ports=53 /ip firewall nat add action=masquerade chain=srcnat comment=\ "IP Masquerading from WAN" out-interface=pppoe-out1 /ip firewall nat add action=masquerade chain=srcnat comment=\ "IP Masquerading for Local area Network" \ src-address=192.168.88.0/24 /ip firewall nat add action=masquerade chain=srcnat comment=\ "IP Masquerading for Local area Network from WAN" \ out-interface=pppoe-out1 src-address=192.168.88.0/24 /ip firewall filter add chain=input comment=\ "Accept all connections from local network" \ src-address-list=LAN /ip firewall filter add chain=input comment=\ "Accept all connections from local network" \ in-interface=!pppoe-out1 src-address=192.168.88.0/24 /ip firewall filter add action=drop chain=input comment="Drop Rule - Input Chain" \ log=yes log-prefix="Drop All" /ip firewall filter add action=jump chain=input comment="Jump for icmp input flow" \ jump-target=icmp protocol=icmp add action=jump chain=forward comment="Jump for icmp forward flow" \ jump-target=icmp protocol=icmp add action=accept chain=icmp comment="Allow Echo Reply" \ icmp-options=0:0 protocol=icmp add action=accept chain=icmp comment="Allow Destination \\ Unreachable(Net Unreachable)" icmp-options=3:0 \ protocol=icmp add action=accept chain=icmp comment="Allow Destination \\ Unreachable(Host Unreachable)" icmp-options=3:1 \ protocol=icmp add action=accept chain=icmp comment="Allow Destination \\ Unreachable(Fragmentation Needed and Don't Fragment was Set)" \ icmp-options=3:4 protocol=icmp add action=accept chain=icmp comment="Allow Echo Request" \ icmp-options=8:0 protocol=icmp add action=accept chain=icmp comment="Allow Time Exceeded" \ icmp-options=11:0 protocol=icmp add action=accept chain=icmp comment="Allow Parameter Bad" \ icmp-options=12:0 protocol=icmp add action=drop chain=icmp comment="Deny icmp Types" log=yes \ log-prefix="Drop Other Types" add action=jump chain=output comment="Jump for icmp output flow" \ jump-target=icmp protocol=icmp /ip firewall filter add action=jump chain=forward comment=\ "DDoS Detection and Blocking" \ connection-state=new jump-target=detect-ddos add action=return chain=detect-ddos dst-limit=\ 32,32,src-and-dst-addresses/10s add action=return chain=detect-ddos \ src-address=192.168.88.1 add action=add-dst-to-address-list address-list=\ ddosed address-list-timeout=10m chain=detect-ddos add action=add-src-to-address-list address-list=\ ddoser address-list-timeout=10m chain=detect-ddos add action=drop chain=forward connection-state=\ new src-address-list=ddoser dst-address-list=ddosed /ip firewall filter add action=jump chain=forward comment="Make jumps to Virus \\ ports chain" jump-target=virus add action=drop chain=virus comment=DeepThroat.Trojan-1 \ dst-port=41 protocol=tcp add action=drop chain=virus comment=Worm.NetSky.Y@mm \ dst-port=82 protocol=tcp add action=drop chain=virus comment=W32.Korgo.A/B/C/D/E/F-1 \ dst-port=113 protocol=tcp add action=drop chain=virus comment=W33.Korgo.A/B/C/D/E/F-2 \ dst-port=2041 protocol=tcp add action=drop chain=virus comment=DeepThroat.Trojan-2 \ dst-port=3150 protocol=tcp add action=drop chain=virus comment=W32.Korgo.A/B/C/D/E/F-3 \ dst-port=3067 protocol=tcp add action=drop chain=virus comment=Backdoor.IRC.Aladdinz.R-1 \ dst-port=3422 protocol=tcp add action=drop chain=virus comment=W32.Korgo.A/B/C/D/E/F-4 \ dst-port=6667 protocol=tcp add action=drop chain=virus comment=Worm.NetSky.S/T/U@mm \ dst-port=6789 protocol=tcp add action=drop chain=virus comment=Back.Orifice.2000.Trojan-1 \ dst-port=8787 protocol=tcp add action=drop chain=virus comment=Back.Orifice.2000.Trojan-2 \ dst-port=8879 protocol=tcp add action=drop chain=virus comment=W32.Dabber.A/B-2 \ dst-port=8967 protocol=tcp add action=drop chain=virus comment=W32.Dabber.A/B-3 \ dst-port=9999 protocol=tcp add action=drop chain=virus comment=Block.NetBus.Trojan-2 \ dst-port=20034 protocol=tcp add action=drop chain=virus comment=GirlFriend.Trojan-1 \ dst-port=21554 protocol=tcp add action=drop chain=virus comment=Back.Orifice.2000.Trojan-3 \ dst-port=31666 protocol=tcp add action=drop chain=virus comment=Backdoor.IRC.Aladdinz.R-2 \ dst-port=43958 protocol=tcp add action=drop chain=virus comment=DeepThroat.Trojan-3 \ dst-port=999 protocol=tcp add action=drop chain=virus comment=DeepThroat.Trojan-4 \ dst-port=6670 protocol=tcp add action=drop chain=virus comment=DeepThroat.Trojan-5 \ dst-port=6771 protocol=tcp add action=drop chain=virus comment=DeepThroat.Trojan-6 \ dst-port=60000 protocol=tcp add action=drop chain=virus comment=DeepThroat.Trojan-7 \ dst-port=2140 protocol=tcp add action=drop chain=virus comment=Portal.of.Doom.Trojan-1 \ dst-port=10067 protocol=tcp add action=drop chain=virus comment=Portal.of.Doom.Trojan-2 \ dst-port=10167 protocol=tcp add action=drop chain=virus comment=Portal.of.Doom.Trojan-3 \ dst-port=3700 protocol=tcp add action=drop chain=virus comment=Portal.of.Doom.Trojan-4 \ dst-port=9872-9875 protocol=tcp add action=drop chain=virus comment=Delta.Source.Trojan-1 \ dst-port=6883 protocol=tcp add action=drop chain=virus comment=Delta.Source.Trojan-2 \ dst-port=26274 protocol=tcp add action=drop chain=virus comment=Delta.Source.Trojan-3 \ dst-port=4444 protocol=tcp add action=drop chain=virus comment=Delta.Source.Trojan-4 \ dst-port=47262 protocol=tcp add action=drop chain=virus comment=Eclypse.Trojan-1 \ dst-port=3791 protocol=tcp add action=drop chain=virus comment=Eclypse.Trojan-2 \ dst-port=3801 protocol=tcp add action=drop chain=virus comment=Eclypse.Trojan-3 \ dst-port=65390 protocol=tcp add action=drop chain=virus comment=Y3K.RAT.Trojan-1 \ dst-port=5880-5882 protocol=tcp add action=drop chain=virus comment=Y3K.RAT.Trojan-2 \ dst-port=5888-5889 protocol=tcp add action=drop chain=virus comment=NetSphere.Trojan-1 \ dst-port=30100-30103 protocol=tcp add action=drop chain=virus comment=NetSphere.Trojan-2 \ dst-port=30133 protocol=tcp add action=drop chain=virus comment=NetMonitor.Trojan-1 \ dst-port=7300-7301 protocol=tcp add action=drop chain=virus comment=NetMonitor.Trojan-2 \ dst-port=7306-7308 protocol=tcp add action=drop chain=virus comment=FireHotcker.Trojan-1 \ dst-port=79 protocol=tcp add action=drop chain=virus comment=FireHotcker.Trojan-2 \ dst-port=5031 protocol=tcp add action=drop chain=virus comment=FireHotcker.Trojan-3 \ dst-port=5321 protocol=tcp add action=drop chain=virus comment=TheThing.Trojan-1 \ dst-port=6400 protocol=tcp add action=drop chain=virus comment=TheThing.Trojan-2 \ dst-port=7777 protocol=tcp add action=drop chain=virus comment=GateCrasher.Trojan-1 \ dst-port=1047 protocol=tcp add action=drop chain=virus comment=GateCrasher.Trojan-2 \ dst-port=6969-6970 protocol=tcp add action=drop chain=virus comment=SubSeven-1 \ dst-port=2774 protocol=tcp add action=drop chain=virus comment=SubSeven-2 \ dst-port=27374 protocol=tcp add action=drop chain=virus comment=SubSeven-3 \ dst-port=1243 protocol=tcp add action=drop chain=virus comment=SubSeven-4 \ dst-port=1234 protocol=tcp add action=drop chain=virus comment=SubSeven-5 \ dst-port=6711-6713 protocol=tcp add action=drop chain=virus comment=SubSeven-7 \ dst-port=16959 protocol=tcp add action=drop chain=virus comment=Moonpie.Trojan-1 \ dst-port=25685-25686 protocol=tcp add action=drop chain=virus comment=Moonpie.Trojan-2 \ dst-port=25982 protocol=tcp add action=drop chain=virus comment=NetSpy.Trojan-3 \ dst-port=31337-31339 protocol=tcp add action=drop chain=virus comment=Trojan \ dst-port=8102 protocol=tcp add action=drop chain=virus comment=WAY.Trojan \ dst-port=8011 protocol=tcp add action=drop chain=virus comment=Trojan.BingHe \ dst-port=7626 protocol=tcp add action=add-dst-to-address-list address-list=Trojan.NianSeHoYian \ address-list-timeout=1d chain=virus comment=Trojan.NianSeHoYian \ dst-port=19191 protocol=tcp add action=drop chain=virus comment=Trojan.NianSeHoYian \ dst-port=19191 protocol=tcp add action=drop chain=virus comment=NetBull.Trojan \ dst-port=23444-23445 protocol=tcp add action=drop chain=virus comment=WinCrash.Trojan-1 \ dst-port=2583 protocol=tcp add action=drop chain=virus comment=WinCrash.Trojan-2 \ dst-port=3024 protocol=tcp add action=drop chain=virus comment=WinCrash.Trojan-3 \ dst-port=4092 protocol=tcp add action=drop chain=virus comment=WinCrash.Trojan-4 \ dst-port=5714 protocol=tcp add action=drop chain=virus comment=Doly1.0/1.35/1.5trojan-1 \ dst-port=1010-1012 protocol=tcp add action=drop chain=virus comment=Doly1.0/1.35/1.5trojan-2 \ dst-port=1015 protocol=tcp add action=drop chain=virus comment=TransScout.Trojan-1 \ dst-port=2004-2005 protocol=tcp add action=drop chain=virus comment=TransScout.Trojan-2 \ dst-port=9878 protocol=tcp add action=drop chain=virus comment=Backdoor.YAI..Trojan-1 \ dst-port=2773 protocol=tcp add action=drop chain=virus comment=Backdoor.YAI.Trojan-2 \ dst-port=7215 protocol=tcp add action=drop chain=virus comment=Backdoor.YAI.Trojan-3 \ dst-port=54283 protocol=tcp add action=drop chain=virus comment=BackDoorTrojan-1 \ dst-port=1003 protocol=tcp add action=drop chain=virus comment=BackDoorTrojan-2 \ dst-port=5598 protocol=tcp add action=drop chain=virus comment=BackDoorTrojan-3 \ dst-port=5698 protocol=tcp add action=drop chain=virus comment=SchainwindlerTrojan-2 \ dst-port=31554 protocol=tcp add action=drop chain=virus comment=Shaft.DDoS.Trojan-1 \ dst-port=18753 protocol=tcp add action=drop chain=virus comment=Shaft.DDoS.Trojan-2 \ dst-port=20432 protocol=tcp add action=drop chain=virus comment=Devil.DDoS.Trojan \ dst-port=65000 protocol=tcp add action=drop chain=virus comment=LatinusTrojan-1 \ dst-port=11831 protocol=tcp add action=drop chain=virus comment=LatinusTrojan-2 \ dst-port=29559 protocol=tcp add action=drop chain=virus comment=Snid.X2Trojan-1 \ dst-port=1784 protocol=tcp add action=drop chain=virus comment=Snid.X2Trojan-2 \ dst-port=3586 protocol=tcp add action=drop chain=virus comment=Snid.X2Trojan-3 \ dst-port=7609 protocol=tcp add action=drop chain=virus comment=BionetTrojan-1 \ dst-port=12348-12349 protocol=tcp add action=drop chain=virus comment=BionetTrojan-2 \ dst-port=12478 protocol=tcp add action=drop chain=virus comment=BionetTrojan-3 \ dst-port=57922 protocol=tcp add action=drop chain=virus comment=Worm.Novarg.a.Mydoom.a1. \ dst-port=3127 protocol=tcp add action=drop chain=virus comment=Worm.BBeagle.a.Bagle.a. \ dst-port=6777 protocol=tcp add action=drop chain=virus comment=Worm.BBeagle.b \ dst-port=8866 protocol=tcp add action=drop chain=virus comment=Worm.BBeagle.c-g/j-l \ dst-port=2745 protocol=tcp add action=drop chain=virus comment=Worm.BBeagle.p/q/r/n \ dst-port=2556 protocol=tcp add action=drop chain=virus comment=Worm.BBEagle.m-2 \ dst-port=20742 protocol=tcp add action=drop chain=virus comment=Worm.BBeagle.s/t/u/v \ dst-port=4751 protocol=tcp add action=drop chain=virus comment=Worm.BBeagle.aa/ab/w/x-z-2 \ dst-port=2535 protocol=tcp add action=drop chain=virus comment=Worm.LovGate.r.RpcExploit \ dst-port=5238 protocol=tcp add action=drop chain=virus comment=Worm.Sasser.a \ dst-port=1068 protocol=tcp add action=drop chain=virus comment=Worm.Sasser.b/c/f \ dst-port=5554 protocol=tcp add action=drop chain=virus comment=Worm.Sasser.b/c/f \ dst-port=9996 protocol=tcp add action=drop chain=virus comment=Worm.Sasser.d \ dst-port=9995 protocol=tcp add action=drop chain=virus comment=Worm.Lovgate.a/b/c/d \ dst-port=10168 protocol=tcp add action=drop chain=virus comment=Worm.Lovgate.v.QQ \ dst-port=20808 protocol=tcp add action=drop chain=virus comment=Worm.Lovgate.f/g \ dst-port=1092 protocol=tcp add action=drop chain=virus comment=Worm.Lovgate.f/g \ dst-port=20168 protocol=tcp add action=drop chain=virus comment=ndm.requester \ dst-port=1363-1364 protocol=tcp add action=drop chain=virus comment=screen.cast \ dst-port=1368 protocol=tcp add action=drop chain=virus comment=hromgrafx \ dst-port=1373 protocol=tcp add action=drop chain=virus comment=cichainlid \ dst-port=1377 protocol=tcp add action=drop chain=virus comment=Backdoor.Optixprotocol \ dst-port=3410 protocol=tcp add action=add-dst-to-address-list address-list=Worm.BBeagle.b \ address-list-timeout=1d chain=virus comment=Worm.BBeagle.b \ dst-port=8888 protocol=tcp add action=drop chain=virus comment=Worm.BBeagle.b \ dst-port=8888 protocol=tcp add action=drop chain=virus comment=Delta.Source.Trojan-7 \ dst-port=44444 protocol=udp add action=drop chain=virus comment=Worm.Sobig.f-3 \ dst-port=8998 protocol=udp add action=drop chain=virus comment=Worm.Novarg.a.Mydoom.a2. \ dst-port=3198 protocol=tcp add action=drop chain=virus comment="Drop Blaster Worm" \ dst-port=135-139 protocol=tcp add action=drop chain=virus comment="Drop Messenger Worm" \ dst-port=135-139 protocol=udp add action=drop chain=virus comment="Drop Blaster Worm" \ dst-port=445 protocol=tcp add action=drop chain=virus comment="Drop Blaster Worm" \ dst-port=445 protocol=udp add action=drop chain=virus comment="Drop 593" \ dst-port=593 protocol=tcp add action=drop chain=virus comment="Drop 1024-1030" \ dst-port=1024-1030 protocol=tcp add action=drop chain=virus comment="Drop MyDoom" \ dst-port=1080 protocol=tcp add action=drop chain=virus comment="Drop 1214" \ dst-port=1214 protocol=tcp add action=drop chain=virus comment="Drop ndm requester" \ dst-port=1363 protocol=tcp add action=drop chain=virus comment="Drop ndm server" \ dst-port=1364 protocol=tcp add action=drop chain=virus comment="Drop screen cast" \ dst-port=1368 protocol=tcp add action=drop chain=virus comment="Drop hromgrafx" \ dst-port=1373 protocol=tcp add action=drop chain=virus comment="Drop cichlid" \ dst-port=1377 protocol=tcp add action=drop chain=virus comment="Drop Worm" \ dst-port=1433-1434 protocol=tcp add action=drop chain=virus comment="Drop NFS" \ dst-port=2049 protocol=tcp add action=drop chain=virus comment="Drop NFS" \ dst-port=2049 protocol=udp add action=drop chain=virus comment="Drop Bagle Virus" \ dst-port=2745 protocol=tcp add action=drop chain=virus comment="Drop Dumaru.Y" \ dst-port=2283 protocol=tcp add action=drop chain=virus comment="Drop Beagle" \ dst-port=2535 protocol=tcp add action=drop chain=virus comment="Drop Beagle.C-K" \ dst-port=2745 protocol=tcp add action=drop chain=virus comment="Drop MyDoom" \ dst-port=3127-3128 protocol=tcp add action=drop chain=virus comment="Drop BackOriffice" \ dst-port=3133 protocol=tcp add action=drop chain=virus comment="Drop BackOriffice" \ dst-port=3133 protocol=udp add action=drop chain=virus comment="Drop Backdoor OptixPro" \ dst-port=3410 protocol=tcp add action=drop chain=virus comment="Drop Worm" \ dst-port=4444 protocol=tcp add action=drop chain=virus comment="Drop Worm" \ dst-port=4444 protocol=udp add action=drop chain=virus comment="Drop beagle worm" \ dst-port=4751 protocol=tcp add action=drop chain=virus comment="Drop Sasser" \ dst-port=5554 protocol=tcp add action=drop chain=virus comment="Drop Beagle.B" \ dst-port=8866 protocol=tcp add action=drop chain=virus comment="Drop adws(TCP)" \ dst-port=9389 protocol=tcp add action=drop chain=virus comment="Drop adws(UDP)" \ dst-port=9389 protocol=udp add action=drop chain=virus comment="Drop Dabber.A-B" \ dst-port=9898 protocol=tcp add action=drop chain=virus comment="Drop Dumaru.Y" \ dst-port=10000 protocol=tcp add action=drop chain=virus comment="Drop MyDoom.B" \ dst-port=10080 protocol=tcp add action=drop chain=virus comment="Drop NetBus" \ dst-port=12345-12346,20034 protocol=tcp add action=drop chain=virus comment="Drop Kuang2" \ dst-port=17300 protocol=tcp add action=drop chain=virus comment="Drop SubSeven" \ dst-port=27374 protocol=tcp add action=drop chain=virus comment="Drop PhatBot, Agobot, Gaobot" \ dst-port=65506 protocol=tcp add action=drop chain=virus comment="Drop TFTP" \ dst-port=69 protocol=tcp add action=drop chain=virus comment="Drop TFTP" \ dst-port=69 protocol=udp add action=drop chain=virus comment="Drop RPC portmapper" \ dst-port=111 protocol=tcp add action=drop chain=virus comment="Drop RPC portmapper" \ dst-port=111 protocol=udp add action=drop chain=virus comment="Drop NFS" \ dst-port=2049 protocol=tcp add action=drop chain=virus comment="Drop NFS" \ dst-port=2049 protocol=udp add action=drop chain=virus comment="Drop BackOriffice" \ dst-port=3133 protocol=tcp add action=drop chain=virus comment="Drop BackOriffice" \ dst-port=3133 protocol=udp add action=drop chain=virus comment="Drop NetBus" \ dst-port=20034 protocol=tcp add action=drop chain=virus comment="Drop NetBus" \ dst-port=12345-12346 protocol=tcp |


Ludacris - Vitamin D ft. Ty Dolla Sign






























































































