/ip firewall address-list add address=192.168.88.2-192.168.88.254 list=LAN /ip firewall nat add action=masquerade chain=srcnat comment="IP Masquerading" \ src-address=192.168.88.0/24 /ip firewall filter add action=accept chain=input comment=\ "Accept all(Input) packetsconnections from local network" \ src-address-list=LAN add chain=icmp protocol=icmp comment="Drop ICMP(Type8) packets" \ icmp-options=!8:0 action-accept add action=drop chain=forward comment="Drop LAN -> UDP(53,433)" \ dst-port=53,443 log-prefix="Drop LAN -> UDP(53,433)" \ protocol=udp src-address-list=LAN /ip settings set rp-filter=no tcp-syncookies=no /system script add name=Blocklister_download_Ads owner=admin policy=\ ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="/\\ tool fetch url=\\"https://blocklister.gefoo.org/ads\" dst-path=\ ads.rsc; /import file-name=ads.rsc;" add name=Blocklister_download_Spyware owner=admin policy=\ ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="/\\ tool fetch url=\\"https://blocklister.gefoo.org/spyware\" dst-path=spywar\ e.rsc; /import file-name=spyware.rsc;" add name=Blocklister_download_Malwaredomainlist owner=admin policy=\ ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="/\\ tool fetch url=\\"https://blocklister.gefoo.org/malwaredomainlist\" dst-pat\ h=malwaredomainlist.rsc; /import file-name=malwaredomainlist.rsc;" add name=Blocklister_download_Blocklistde_apache owner=admin policy=\ ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="/\\ tool fetch url=\\"https://blocklister.gefoo.org/blocklistde_apache\" dst-pa\ th=blocklistde_apache.rsc; /import file-name=blocklistde_apache.rsc;" |