<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title>Mikrotik.moscow [тема: Брандмауэр.]</title>
		<link>http://mikrotik.moscow</link>
		<description>Новое в теме Брандмауэр. форума RouterOS на сайте Mikrotik.moscow [mikrotik.moscow]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Mon, 10 Aug 2026 17:13:58 -0400</pubDate>
		<item>
			<title>Брандмауэр.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239076">Брандмауэр.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Привет, вот интересно, почему мой провайдер не отключает какие-то протоколы. Хотелось бы и мне так сделать для своих клиентов. Как вообще работает мой провайдер? Может, у тебя есть какие-нибудь идеи? <br />
			<i>16.01.2006 18:06:00, maxfava.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239076</link>
			<guid>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239076</guid>
			<pubDate>Mon, 16 Jan 2006 18:06:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Брандмауэр.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239075">Брандмауэр.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Эмм… а почему бы просто заблокировать всё и разрешить только те сервисы, которые нужны? Заблокировать ВСЁ входящее, разрешить ВСЁ исходящее. А потом добавить правила для нужных сервисов, и ты защищён от всей вирусни. Ну если ты провайдер, то здесь очевидные проблемы. Я просто блокирую основные сервисы, вроде NetBIOS и определённые порты для SMTP и других сервисов, которые не хочу, чтобы клиенты запускали в сети. А потом говорю клиентам, что им самим надо заниматься файрволом и стоит вложиться в аппаратный/программный файрвол. #firewall #security #cybersecurity <br />
			<i>10.10.2005 16:37:00, wildbill442.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239075</link>
			<guid>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239075</guid>
			<pubDate>Mon, 10 Oct 2005 16:37:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Брандмауэр.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239074">Брандмауэр.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			demo2.mt.lv логин: demo <br />
			<i>10.10.2005 07:30:00, yancho.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239074</link>
			<guid>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239074</guid>
			<pubDate>Mon, 10 Oct 2005 07:30:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Брандмауэр.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239073">Брандмауэр.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Как мне снова получить доступ к тестовому серверу MT? Я потерял URL. <br />
			<i>10.10.2005 07:21:00, maroon.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239073</link>
			<guid>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239073</guid>
			<pubDate>Mon, 10 Oct 2005 07:21:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Брандмауэр.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239072">Брандмауэр.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Не знаю. Если заглянуть на тестовый сервер MK, возможно, найдёшь ещё что-то. Но объяснений всё равно не так много. <br />
			<i>10.10.2005 07:04:00, gianluca.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239072</link>
			<guid>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239072</guid>
			<pubDate>Mon, 10 Oct 2005 07:04:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Брандмауэр.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239071">Брандмауэр.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Да, пожалуйста, вставьте окончательный код брандмауэра для защиты от вирусов и сделайте его закрепленным. На этом форуме есть довольно много разных кодов для версии 2.9, но я не знаю, кому можно доверять, потому что кто-нибудь всегда комментирует, насколько это правильно. Последний, который я видел:<br />/ip firewall filter add chain=virus comment="Reglas Antivirus"<br />/ip firewall filter add chain=forward connection-state=invalid action=drop comment="Drop invalid connections" disabled=no<br />/ip firewall filter add chain=forward connection-state=established action=accept comment="Established Connections" disabled=no<br />/ip firewall filter add chain=forward connection-state=related action=accept comment="Related connections" disabled=no<br />/ip firewall filter add chain=forward action=jump jump-target=virus comment="!!! Check for well-known viruses !!!" disabled=no<br />/ip firewall filter add chain=forward protocol=udp action=accept comment="UDP" disabled=no<br />/ip firewall filter add chain=forward protocol=icmp limit=50/5,2 action=accept comment="Allow limited Pings" disabled=no<br />/ip firewall filter add chain=forward protocol=icmp action=drop comment="Drop excess pings" disabled=no<br />/ip firewall filter add chain=input connection-state=invalid action=drop comment="Drop invalid connections" disabled=no<br />/ip firewall filter add chain=input tcp-flags=!syn connection-state=established action=accept comment="Accept established connections" disabled=no<br />/ip firewall filter add chain=input connection-state=related action=accept comment="Accept related connections" disabled=no<br />/ip firewall filter add chain=input action=jump jump-target=virus comment="!!! Check for well-known viruses !!!" disabled=no<br />/ip firewall filter add chain=input protocol=udp action=accept comment="UDP" disabled=no<br />/ip firewall filter add chain=input protocol=icmp limit=50/5,2 action=accept comment="Allow limited pings" disabled=no<br />/ip firewall filter add chain=input protocol=icmp action=drop comment="Drop excess pings" disabled=no<br />/ip firewall filter add chain=input dst-port=22 protocol=tcp action=accept comment="SSH for demo purposes" disabled=no<br />/ip firewall filter add chain=input dst-port=23 protocol=tcp action=accept comment="Telnet for demo purposes" disabled=no<br />/ip firewall filter add chain=input dst-port=80 protocol=tcp action=accept comment="http for demo purposes" disabled=no<br />/ip firewall filter add chain=input dst-port=3987 protocol=tcp action=accept comment="winbox for demo purposes" disabled=no<br />/ip firewall filter add chain=input action=accept log=yes comment="Log and drop everything else" disabled=no<br />/ip firewall filter add chain=virus dst-port=135-139 protocol=tcp action=drop comment="Drop Blaster Worm" disabled=no<br />/ip firewall filter add chain=virus dst-port=135-139 protocol=udp action=drop comment="Drop Messenger Worm" disabled=no<br />/ip firewall filter add chain=virus dst-port=445 protocol=tcp action=drop comment="Drop Blaster Worm" disabled=no<br />/ip firewall filter add chain=virus dst-port=445 protocol=udp action=drop comment="Drop Blaster Worm" disabled=no<br />/ip firewall filter add chain=virus dst-port=593 protocol=tcp action=drop comment=“ " disabled=no<br />/ip firewall filter add chain=virus dst-port=1024-1030 protocol=tcp action=drop comment=" ” disabled=no<br />/ip firewall filter add chain=virus dst-port=1080 protocol=tcp action=drop comment="Drop MyDoom" disabled=no<br />/ip firewall filter add chain=virus dst-port=1214 protocol=tcp action=drop comment=“________” disabled=no<br />/ip firewall filter add chain=virus dst-port=1363 protocol=tcp action=drop comment=“ndm requester” disabled=no<br />/ip firewall filter add chain=virus dst-port=1364 protocol=tcp action=drop comment=“ndm server” disabled=no<br />/ip firewall filter add chain=virus dst-port=1368 protocol=tcp action=drop comment=“screen cast” disabled=no<br />/ip firewall filter add chain=virus dst-port=1373 protocol=tcp action=drop comment=“hromgrafx” disabled=no<br />/ip firewall filter add chain=virus dst-port=1377 protocol=tcp action=drop comment=“cichlid” disabled=no<br />/ip firewall filter add chain=virus dst-port=1433-1434 protocol=tcp action=drop comment=“Worm” disabled=no<br />/ip firewall filter add chain=virus dst-port=2745 protocol=tcp action=drop comment=“Bagle Virus” disabled=no<br />/ip firewall filter add chain=virus dst-port=2283 protocol=tcp action=drop comment=“Drop Dumaru.Y” disabled=no<br />/ip firewall filter add chain=virus dst-port=2535 protocol=tcp action=drop comment=“Drop Beagle” disabled=no<br />/ip firewall filter add chain=virus dst-port=2745 protocol=tcp action=drop comment=“Drop Beagle.C-K” disabled=no<br />/ip firewall filter add chain=virus dst-port=3127-3128 protocol=tcp action=drop comment=“Drop MyDoom” disabled=no<br />/ip firewall filter add chain=virus dst-port=3410 protocol=tcp action=drop comment=“Drop Backdoor OptixPro” disabled=no<br />/ip firewall filter add chain=virus dst-port=4444 protocol=tcp action=drop comment=“Worm” disabled=no<br />/ip firewall filter add chain=virus dst-port=4444 protocol=udp action=drop comment=“Worm” disabled=no<br />/ip firewall filter add chain=virus dst-port=5554 protocol=tcp action=drop comment=“Drop Sasser” disabled=no<br />/ip firewall filter add chain=virus dst-port=8866 protocol=tcp action=drop comment=“Drop Beagle.B” disabled=no<br />/ip firewall filter add chain=virus dst-port=9898 protocol=tcp action=drop comment=“Drop Dabber.A-B” disabled=no<br />/ip firewall filter add chain=virus dst-port=10000 protocol=tcp action=drop comment=“Drop Dumaru.Y” disabled=no<br />/ip firewall filter add chain=virus dst-port=10080 protocol=tcp action=drop comment=“Drop MyDoom.B” disabled=no<br />/ip firewall filter add chain=virus dst-port=12345 protocol=tcp action=drop comment=“Drop NetBus” disabled=no<br />/ip firewall filter add chain=virus dst-port=17300 protocol=tcp action=drop comment=“Drop Kuang2” disabled=no<br />/ip firewall filter add chain=virus dst-port=27374 protocol=tcp action=drop comment=“Drop SubSeven” disabled=no<br />/ip firewall filter add chain=virus dst-port=65506 protocol=tcp action=drop comment=“Drop PhatBot, Agobot, Gaobot” disabled=no<br />Как вы считаете, насколько это правильно?? <br />
			<i>06.10.2005 06:55:00, Snowy.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239071</link>
			<guid>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239071</guid>
			<pubDate>Thu, 06 Oct 2005 06:55:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Брандмауэр.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239070">Брандмауэр.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Было бы полезно иметь примеры корректных правил для файрвола на пограничном роутере, чтобы избежать атак, вирусов и т.д. Я знаю, что на форуме есть темы про цепочки заражения вирусами… но было бы здорово записать всё, о чём нужно подумать, чтобы защитить сеть. Спасибо, Gianluca. <br />
			<i>25.09.2005 15:11:00, gianluca.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239070</link>
			<guid>http://mikrotik.moscow/forum/forum57/62343-brandmauer./message239070</guid>
			<pubDate>Sun, 25 Sep 2005 15:11:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
	</channel>
</rss>
