pctine wrote:
採用何種 VPN type 還是要
SSTP,L2TP,PPTP這三種VPN,我都設定完成,且都能正常連線,所以用何種都可以,穩定即可,效能差一點也沒關係(當然不能差太多)
我設定VPN通道,大多是小檔案存取
再請教如果24小時連線風險高不高 ?
tsaisj55 wrote:
SSTP,L2TP,...(恕刪)
/ip firewall filter
add action=drop chain=input comment="\\AB\\CA\\C2\\EA\\A5~\\BA\\F4Ping \\A6^\\C0\\B3" in-interface=all-ppp protocol=icmp
add action=drop chain=input comment="\\A5\\E1\\B1\\F3\\ABD\\A5\\BB\\BE\\F7\\AA\\BA\\AB\\CA\\A5]" dst-address-type=!local
add action=drop chain=input comment="\\A5\\E1\\B1\\F3\\B5L\\AE\\C4\\AA\\BA\\AB\\CA\\A5]" connection-state=invalid
add action=drop chain=input comment="\\A8\\BE\\A4\\EE\\B3Q\\B1\\BD\\BA\\CB Port" protocol=tcp src-address-list="port scanners"
add action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w chain=input protocol=tcp psd=21,3s,3,1
add action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w chain=input protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg
add action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w chain=input protocol=tcp tcp-flags=fin,syn
add action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w chain=input protocol=tcp tcp-flags=syn,rst
add action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w chain=input protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack
add action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w chain=input protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg
add action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w chain=input protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg
add action=drop chain=input comment="\\A5\\E1\\B1\\F3\\A6h\\BC\\BD\\AA\\BA\\AB\\CA\\A5]" src-address-type=!unicast
add action=drop chain=input comment="DoS\\A9\\DA\\B5\\B4\\AAA\\B0\\C8\\A7\\F0\\C0\\BB" connection-limit=10,32 protocol=tcp
add action=drop chain=input comment="\\AB\\CA\\C2\\EA\\A5~\\A4H\\B5n\\A4JWinBox" src-address-list=login_winbox
add action=add-src-to-address-list address-list=login_winbox address-list-timeout=1d chain=input dst-port=8291 in-interface=all-ppp protocol=tcp
add action=drop chain=input comment="\\AB\\CA\\C2\\EA\\A5~\\A4H\\A8\\CF\\A5\\CEweb-proxy" src-address-list=web-proxy
add action=add-src-to-address-list address-list=web-proxy address-list-timeout=1d chain=input dst-port=88 in-interface=all-ppp protocol=tcp
add action=drop chain=input comment="ROS SSH/Telnet\\A8\\BE\\A4\\F5\\C0\\F0(\\B5n\\A4J3\\A6\\B8\\BF\\F9\\BB~\\A7Y\\AB\\CA\\C2\\EA)" src-address-list=login_blacklist
add action=add-src-to-address-list address-list=login_blacklist address-list-timeout=1d chain=input connection-state=new dst-port=22,23 protocol=tcp \
src-address-list=login_stage3
add action=add-src-to-address-list address-list=login_stage3 address-list-timeout=1m chain=input connection-state=new dst-port=22,23 protocol=tcp \
src-address-list=login_stage2
add action=add-src-to-address-list address-list=login_stage2 address-list-timeout=1m chain=input connection-state=new dst-port=22,23 protocol=tcp \
src-address-list=login_stage1
add action=add-src-to-address-list address-list=login_stage1 address-list-timeout=1m chain=input connection-state=new dst-address-type=local dst-port=22,23 \
protocol=tcp
add action=drop chain=forward comment="\\AB\\CA\\C2\\EAbittorrent-DHT" layer7-protocol="bittorrent_dht " packet-size=95-190
pctine wrote:
被你考倒了, "ipsec int