2100準~ABCDEF六版要調整.依照11/21號版本做修改.改完就定版.--/ip settingsset rp-filter=noset tcp-syncookies=no/ip firewall natadd action=dst-nat chain=dstnat dst-port=53 \protocol=tcp to-addresses=192.168.88.1 to-ports=53 \comment="Force Users to Router for DNS - TCP"add action=dst-nat chain=dstnat dst-port=53 \protocol=udp to-addresses=192.168.88.1 to-ports=53 \comment="Force Users to Router for DNS - UDP"/ip firewall filteradd action=add-src-to-address-list chain=input protocol=tcp \connection-limit=100,32 address-list=blocked-addr \address-list-timeout=1d comment="SYN Flood protect"add action=tarpit chain=input protocol=tcp \src-address-list=blocked-addr connection-limit=3,32add action=jump chain=forward protocol=tcp tcp-flags=syn \connection-state=new jump-target=SYN-Protect \comment="SYN Flood protect"add chain=SYN-Protect protocol=tcp tcp-flags=syn \limit=400,5 connection-state=newadd action=drop chain=SYN-Protect protocol=tcp \tcp-flags=syn connection-state=newadd action=jump chain=forward connection-state=new \jump-target=detect-ddos comment="DDoS Detection and Blocking"add action=return chain=detect-ddos dst-limit=\32,32,src-and-dst-addresses/10sadd action=return chain=detect-ddos \src-address=192.168.88.1add action=add-dst-to-address-list address-list=\ddosed address-list-timeout=10m chain=detect-ddosadd action=add-src-to-address-list address-list=\ddoser address-list-timeout=10m chain=detect-ddosadd action=drop chain=forward connection-state=\new src-address-list=ddoser dst-address-list=ddosed--改這樣就好.這是猴仔致上禮貌的讓步.就看國家機器怎麼玩!2120請準備.--Massive Attack feat. Mos Def - I Against I
2155準~--說好的「中國網軍」呢? 從PTT「除垢」到楊蕙如「被訴」…滿城盡是「民進黨網軍」!【平論無雙】完整版 2019.12.02 平秀琳 蔡正元 鄭麗文 于美人 劉宥彤 李明賢 郭正亮