Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Assume you want to block torrent & p2p traffic on 192.168.10.0/24
- Local/Lan address is 192.168.10.0/24 (Change setting according to your network)
- /ip firewall layer7-protocol
- add name=torrentsites regexp="^.*(get|GET).+(torrent|thepiratebay|isohunt|entertane|demonoid|btjunkie|mininova|flixflux|torrentz|vertor|h33t|btscene|bitunity|bittoxic|thunderbytes|entertane|zoozle|vcdq|bitnova|bitsoup|meganova|fulldls|btbot|flixflux|seedpeer|fenopy|gpirate|commonbits).*\$"
- /ip firewall filter
- add chain=forward src-address=192.168.10.0/24 layer7-protocol=torrentsites action=drop comment=torrentsites
- add chain=forward src-address=192.168.10.0/24 protocol=17 dst-port=53 layer7-protocol=torrentsites action=drop comment=dropDNS
- add chain=forward src-address=192.168.10.0/24 content=torrent action=drop comment=keyword_drop
- add chain=forward src-address=192.168.10.0/24 content=tracker action=drop comment=trackers_drop
- add chain=forward src-address=192.168.10.0/24 content=getpeers action=drop comment=get_peers_drop
- add chain=forward src-address=192.168.10.0/24 content=info_hash action=drop comment=info_hash_drop
- add chain=forward src-address=192.168.10.0/24 content=announce_peers action=drop comment=announce_peers_drop
- add chain=forward src-address=192.168.10.0/24 p2p=all-p2p action=drop comment=p2p_drop
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement