Bagi kamu yang
sudah menggunakan mikrotik, berikut adalah settingan firewall pada
mikrotik untuk menangkal netcut dan drop beberapa virus.
Langsung saja buka winbox atau pake putty. Pada winbox, klik "New Terminal" dan silahkan copy-paste script di bawah ini:
Kemudian reboot mikrotik/ip firewall filteradd action=accept chain=input \disabled=no dst-port=8291 protocol=tcpadd action=drop chain=forward \connection-state=invalid disabled=noadd action=drop chain=virus disabled=no \dst-port=135-139 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=1433-1434 protocol=tcpadd action=drop chain=virus \disabled=no dst-port=445 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=445 protocol=udpadd action=drop chain=virus disabled=no \dst-port=593 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=1024-1030 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=1080 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=1214 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=1363 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=1364 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=1368 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=1373 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=1377 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=2745 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=2283 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=2535 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=2745 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=3127 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=3410 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=4444 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=4444 protocol=udpadd action=drop chain=virus disabled=no \dst-port=5554 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=8866 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=9898 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=10080 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=12345 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=17300 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=27374 protocol=tcpadd action=drop chain=virus disabled=no \dst-port=65506 protocol=tcpadd action=jump chain=forward \disabled=no jump-target=virusadd action=drop chain=input \connection-state=invalid disabled=noadd action=accept chain=input \disabled=no protocol=udpadd action=accept chain=input \disabled=no limit=50/5s,2 protocol=icmpadd action=drop chain=input \disabled=no protocol=icmpadd action=accept chain=input \disabled=no dst-port=21 protocol=tcpadd action=accept chain=input \disabled=no dst-port=22 protocol=tcpadd action=accept chain=input \disabled=no dst-port=23 protocol=tcpadd action=accept chain=input \disabled=no dst-port=80 protocol=tcpadd action=accept chain=input \disabled=no dst-port=8291 protocol=tcpadd action=accept chain=input \disabled=no dst-port=1723 protocol=tcpadd action=accept chain=input \disabled=no dst-port=23 protocol=tcpadd action=accept chain=input \disabled=no dst-port=80 protocol=tcpadd action=accept chain=input disabled=no \dst-port=1723 protocol=tcpadd action=add-src-to-address-list \address-list=DDOS address-list-timeout=15s \chain=input disabled=no dst-port=1337 protocol=tcpadd action=add-src-to-address-list \address-list=DDOS address-list-timeout=15m \chain=input disabled=no dst-port=7331 \protocol=tcp src-address-list=knockadd action=add-src-to-address-list \address-list="port-scanners" \address-list-timeout=2w chain=input \comment="port-scanner" \disabled=no protocol=tcp psd=21,3s,3,1add action=add-src-to-address-list \address-list="port-scanners" \address-list-timeout=2w chain=input \comment="SYN/FIN" disabled=no \protocol=tcp tcp-flags=fin,synadd action=add-src-to-address-list \address-list="port-scanners" \address-list-timeout=2w chain=input \comment="SYN/RST" disabled=no \protocol=tcp tcp-flags=syn,rstadd action=add-src-to-address-list \address-list="port-scanners" \address-list-timeout=2w chain=input \comment="FIN/PSH/URG" disabled=\no protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ackadd action=add-src-to-address-list \address-list="port-scanners" \address-list-timeout=2w chain=input \comment="ALL/ALL scan" disabled=no \protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urgadd action=add-src-to-address-list \address-list="port-scanners" \address-list-timeout=2w chain=input \comment="NMAP" disabled=no \protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urgadd action=accept chain=input \comment="ANTI-NETCUT" disabled=no dst-port=\0-65535 protocol=tcp \src-address=61.213.183.1-61.213.183.254add action=accept chain=input \comment="ANTI-NETCUT" disabled=no \dst-port=0-65535 protocol=tcp \src-address=67.195.134.1-67.195.134.254add action=accept chain=input \comment="ANTI-NETCUT" disabled=no \dst-port=0-65535 protocol=tcp \src-address=68.142.233.1-68.142.233.254add action=accept chain=input \comment="ANTI-NETCUT" disabled=no dst-port=\0-65535 protocol=tcp \src-address=68.180.217.1-68.180.217.254add action=accept chain=input \comment="ANTI-NETCUT" disabled=no \dst-port=0-65535 protocol=tcp \src-address=203.84.204.1-203.84.204.254add action=accept chain=input \comment="ANTI-NETCUT" disabled=no \dst-port=0-65535 protocol=tcp \src-address=69.63.176.1-69.63.176.254add action=accept chain=input \comment="ANTI-NETCUT" \disabled=no dst-port=0-65535 protocol=tcp \src-address=69.63.181.1-69.63.181.254add action=accept chain=input \comment="ANTI-NETCUT" \disabled=no dst-port=0-65535 protocol=tcp \src-address=63.245.209.1-63.245.209.254add action=accept chain=input \comment="ANTI-NETCUT" disabled=no dst-port=\0-65535 protocol=tcp \src-address=63.245.213.1-63.245.213.254
/system reboot
0 komentar:
Post a Comment