Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #drop_ftp
- /ip firewall filter
- add chain=output comment="Drop FTP Brute Forcers" content=\
- "530 Login incorrect" dst-limit=1/1m,9,dst-address/1m protocol=tcp
- add action=add-dst-to-address-list address-list=FTP_BlackList \
- address-list-timeout=1d chain=output content="530 Login incorrect" \
- protocol=tcp
- add action=drop chain=input dst-port=21 protocol=tcp src-address-list=\
- FTP_BlackList
- #drop_ssh_telnet
- /ip firewall filter
- add action=add-src-to-address-list address-list=SSH_BlackList_1 \
- address-list-timeout=1m chain=input comment=\
- "Drop SSH&TELNET Brute Forcers" connection-state=new dst-port=22-23 \
- protocol=tcp
- add action=add-src-to-address-list address-list=SSH_BlackList_2 \
- address-list-timeout=1m chain=input connection-state=new dst-port=\
- 22-23 protocol=tcp src-address-list=SSH_BlackList_1
- add action=add-src-to-address-list address-list=SSH_BlackList_3 \
- address-list-timeout=1m chain=input connection-state=new dst-port=\
- 22-23 protocol=tcp src-address-list=SSH_BlackList_2
- add action=add-src-to-address-list address-list=IP_BlackList \
- address-list-timeout=1d chain=input connection-state=new dst-port=\
- 22-23 protocol=tcp src-address-list=SSH_BlackList_3
- add action=drop chain=input dst-port=22-23 protocol=tcp \
- src-address-list=IP_BlackList
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement