Ahoj,
prosim nasel by se nekdo tak ochotny a zkontroloval mi pravidla na firewallu? Nastavoval jsem si to sam a tak mam strach, jestli jsem neco nevynechal?
Za verejnou IP je jen mikrotik 751G-2HnD a na nem je povesena lokalni sit, ve ktere je linux server s LAMP a XMPP serverem. Chtel bych tedy dovnitr propoustet jenom HTTP/HTTPS, XMPP a VOIP a mit moznost se do vnitrni site (na verejnou IP mikrotiku) pripojovat pres L2TP VPNku, kde mi miktorik dela server.
Vsechno mi funguje, ale nejsem si jisty, jestli mam spravne definovana drop pravidla a zda je vsechno ostatni zablokovane.
Jak je to s aktualizaci firmware? Mam tam hooodne stary FW. Rikal jsem si, ze je kdyz to funguje, nebudu do toho hrabat, ale asi bych mel pravidelne aktualizovat na novejsi verze, kvuli zaplatam?
# jul/11/2014 13:49:05 by RouterOS 5.16
# software id = VJ2A-C7VY
#
/ip firewall address-list
/ip firewall connection tracking
set enabled=yes generic-timeout=10m icmp-timeout=10s tcp-close-timeout=10s \
tcp-close-wait-timeout=10s tcp-established-timeout=1d \
tcp-fin-wait-timeout=10s tcp-last-ack-timeout=10s \
tcp-syn-received-timeout=5s tcp-syn-sent-timeout=5s tcp-syncookie=no \
tcp-time-wait-timeout=10s udp-stream-timeout=3m udp-timeout=10s
/ip firewall filter
add action=accept chain=input comment="default configuration" disabled=no \
protocol=icmp
add action=accept chain=input comment="default configuration" \
connection-state=established disabled=no
add action=accept chain=input comment="default configuration" \
connection-state=related disabled=no
add action=accept chain=input comment="== tik www admin ==" disabled=no \
dst-port=8080 protocol=tcp
add action=accept chain=input disabled=yes dst-port=80 protocol=tcp
add action=accept chain=input comment="== VPN ==" disabled=no dst-port=500 \
protocol=udp
add action=accept chain=input disabled=no dst-port=1701 protocol=udp
add action=accept chain=input disabled=no dst-port=4500 protocol=udp
add action=accept chain=input disabled=no protocol=ipsec-esp
add action=drop chain=input comment="default configuration" disabled=no \
in-interface=ether1-gateway
/ip firewall nat
add action=masquerade chain=srcnat comment="default configuration" disabled=\
no out-interface=ether1-gateway to-addresses=0.0.0.0
add action=dst-nat chain=dstnat comment="APACHE HTTP+HTTPS na server." \
disabled=no dst-port=80 in-interface=ether1-gateway protocol=tcp \
to-addresses=192.168.10.21 to-ports=80
add action=dst-nat chain=dstnat disabled=no dst-port=443 in-interface=\
ether1-gateway protocol=tcp to-addresses=192.168.10.21 to-ports=443
add action=dst-nat chain=dstnat comment="JABBER XMPP na server." disabled=no \
dst-port=5269 in-interface=ether1-gateway protocol=tcp to-addresses=\
192.168.10.21 to-ports=5269
add action=dst-nat chain=dstnat disabled=no dst-port=5222 in-interface=\
ether1-gateway protocol=tcp to-addresses=192.168.10.21 to-ports=5222
/ip firewall service-port
set ftp disabled=no ports=21
set tftp disabled=no ports=69
set irc disabled=no ports=6667
set h323 disabled=no
set sip disabled=no ports=5060,5061 sip-direct-media=yes
set pptp disabled=no