pgb Jasně, ale moc těch pravidel nemám tak proto mě to tak zarazilo že je to takový rozdíl, předtím jsem to nepoznal protože jsem měl pouze 100M linku.....
/ip firewall filter
add action=accept chain=input comment="Navazane spojeni OK" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="Moje IPv4 (src)" src-address-list=moje_ip
add action=accept chain=input comment="defconf: accept ICMP after RAW" protocol=icmp
add action=accept chain=input comment="VPN: allow IKE" dst-port=500 protocol=udp
add action=accept chain=input comment="VPN: allow L2TP" dst-port=1701 protocol=udp
add action=accept chain=input comment="VPN: allow IPsec NAT-T" dst-port=4500 protocol=udp
add action=accept chain=input protocol=ipsec-esp
add action=accept chain=input protocol=ipsec-ah
add action=accept chain=input comment="Pristup z internetu pres IPv4 k routeru limit 1/minutu" connection-state=new dst-limit=\
1/1m,1,src-address/1m40s dst-port=8585,801 protocol=tcp
add action=drop chain=input comment="Nen\ED z LAN" in-interface-list=!LAN
add action=drop chain=forward comment="Disable internet IP 192.168.1.99" out-interface-list=WAN src-address=192.168.1.99
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
add action=accept chain=forward comment="Navazane spojeni OK" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop bad forward IPs" src-address-list=no_forward_ipv4
add action=drop chain=forward comment="defconf: drop bad forward IPs" dst-address-list=no_forward_ipv4
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=forward comment="Moje IPv4 (src)" src-address-list=moje_ip
add action=accept chain=forward comment="Tv headend" dst-port=9981 protocol=tcp
add action=accept chain=forward comment="ssh (ssh, nas, htpc) limit 1/min" connection-state=new dst-limit=1/1m,1,src-and-dst-addresses/1m40s \
dst-port=22,806,812 protocol=tcp
add action=accept chain=forward comment="Voip telefon" connection-state=new disabled=yes dst-port=8586 protocol=tcp
add action=accept chain=forward comment="rsync nas" disabled=yes dst-port=873 protocol=tcp
add action=accept chain=forward comment=Wol dst-port=9 protocol=udp
add action=drop chain=forward comment="Nen\ED z LAN" in-interface-list=!LAN
/ip firewall raw
add action=accept chain=prerouting comment="Povolenim vypnete firewall" disabled=yes
add action=drop chain=prerouting comment="defconf: drop non global from WAN" in-interface-list=WAN src-address-list=not_global_ipv4
add action=drop chain=prerouting comment="defconf: drop forward to local lan from WAN" dst-address=192.168.1.0/24 in-interface-list=WAN
add action=drop chain=prerouting comment="defconf: drop local if not from default IP range" in-interface-list=LAN src-address=!192.168.0.0/16
add action=drop chain=prerouting comment="defconf: drop bad UDP" port=0 protocol=udp
add action=jump chain=prerouting comment="defconf: jump to ICMP chain" jump-target=icmp4 protocol=icmp
add action=jump chain=prerouting comment="defconf: jump to TCP chain" jump-target=bad_tcp protocol=tcp
add action=drop chain=bad_tcp comment="defconf: TCP flag filter" protocol=tcp tcp-flags=!fin,!syn,!rst,!ack
add action=drop chain=bad_tcp comment=defconf protocol=tcp tcp-flags=fin,syn
add action=drop chain=bad_tcp comment=defconf protocol=tcp tcp-flags=fin,rst
add action=drop chain=bad_tcp comment=defconf protocol=tcp tcp-flags=fin,!ack
add action=drop chain=bad_tcp comment=defconf protocol=tcp tcp-flags=fin,urg
add action=drop chain=bad_tcp comment=defconf protocol=tcp tcp-flags=syn,rst
add action=drop chain=bad_tcp comment=defconf protocol=tcp tcp-flags=rst,urg
add action=drop chain=bad_tcp comment="defconf: TCP port 0 drop" port=0 protocol=tcp
add action=accept chain=icmp4 comment="defconf: echo reply" icmp-options=0:0 limit=5,10:packet protocol=icmp
add action=accept chain=icmp4 comment="defconf: net unreachable" icmp-options=3:0 protocol=icmp
add action=accept chain=icmp4 comment="defconf: host unreachable" icmp-options=3:1 protocol=icmp
add action=accept chain=icmp4 comment="defconf: protocol unreachable" icmp-options=3:2 protocol=icmp
add action=accept chain=icmp4 comment="defconf: port unreachable" icmp-options=3:3 protocol=icmp
add action=accept chain=icmp4 comment="defconf: fragmentation needed" icmp-options=3:4 protocol=icmp
add action=accept chain=icmp4 comment="defconf: echo" icmp-options=8:0 limit=5,10:packet protocol=icmp
add action=accept chain=icmp4 comment="defconf: time exceeded " icmp-options=11:0-255 protocol=icmp
add action=drop chain=icmp4 comment="Zakaze ostatni icmp ktere nejsou z LAN" in-interface-list=!LAN protocol=icmp