2200準~ABCDEF六版要新增下面飢渴.噢~不!是新增下面即可.--/ip firewall filteradd chain=input comment=\"Accept established and related packets" \connection-state=established,related--/ip firewall filteradd action=drop chain=input connection-state=invalid \comment="Drop invalid"add chain=input connection-state=established \comment="Accept established"add chain=forward protocol=tcp tcp-flags=!syn,ack comment=\"Accept packets where tcp-flags does not have syn,but has ack flags"add chain=forward connection-state=!new,related comment=\"Accept all connections which state is not new or related packets"add action=drop chain=forward connection-state=invalid \comment="Drop invalid packets"add chain=forward connection-state=established \comment="Accept established packets"add chain=forward connection-state=related \comment="Accept related packets"/ip firewall filteradd action=jump chain=forward jump-target=tcp protocol=tcp \comment="Make jumps to new TCP chains"add action=jump chain=forward jump-target=udp protocol=udp \comment="Make jumps to new UDP chains"add action=drop chain=tcp dst-port=69 protocol=tcp \comment="Deny TFTP"add action=drop chain=tcp dst-port=111 protocol=tcp \comment="Ddeny RPC portmapper"add action=drop chain=tcp dst-port=135 protocol=tcp \comment="Deny RPC portmapper"add action=drop chain=tcp dst-port=137-139 protocol=tcp \comment="Deny NBT"add action=drop chain=tcp dst-port=445 protocol=tcp \comment="Deny cifs"add action=drop chain=tcp dst-port=2049 protocol=tcp \comment="Deny NFS"add action=drop chain=tcp dst-port=12345-12346 protocol=tcp \comment="Deny NetBus"add action=drop chain=tcp dst-port=20034 protocol=tcp \comment="Deny NetBus"add action=drop chain=tcp dst-port=3133 protocol=tcp \comment="Deny BackOriffice"add action=drop chain=tcp dst-port=67-68 protocol=tcp \comment="Deny DHCP"add action=drop chain=udp dst-port=69 protocol=udp \comment="Deny TFTP"add action=drop chain=udp dst-port=111 protocol=udp \comment="Deny PRC portmapper"add action=drop chain=udp dst-port=135 protocol=udp \comment="Deny PRC portmapper"add action=drop chain=udp dst-port=137-139 protocol=udp \comment="Deny NBT"add action=drop chain=udp dst-port=2049 protocol=udp \comment="Deny NFS"add action=drop chain=udp dst-port=3133 protocol=udp \comment="Deny BackOriffice"--20191205中天新聞 【氣象】南方雲系北抬影響 天氣濕涼穿保暖