Respostas

  • VLW Eberty...

    Eberty Jackson Rodrigues disse:

    A porta do FTP é a 21

    /ip firewall filter
    add action=drop chain=input comment=\
    "BLOQUEIA FTP BRUTE FORCERS - MENOS DO IP 172.31.255.2" disabled=no \
    dst-port=21 protocol=tcp src-address=!172.31.255.2 src-address-list=\
    ftp_blacklist
    add action=add-src-to-address-list address-list=ftp_blacklist \
    address-list-timeout=10w3d chain=input connection-state=new disabled=no \
    dst-port=21 protocol=tcp src-address-list=ftp_stage3
    add action=add-src-to-address-list address-list=ftp_stage3 \
    address-list-timeout=1m chain=input connection-state=new disabled=no \
    dst-port=21 protocol=tcp src-address-list=ftp_stage2
    add action=add-src-to-address-list address-list=ftp_stage2 \
    address-list-timeout=1m chain=input connection-state=new disabled=no \
    dst-port=21 protocol=tcp src-address-list=ftp_stage1
    add action=add-src-to-address-list address-list=ftp_stage1 \
    address-list-timeout=1m chain=input connection-state=new disabled=no \
    dst-port=21 protocol=tcp src-address=!172.31.255.2

    Só colocar essa regra ai.

  • Funciono 100% valeus chefe....



    Eberty Jackson Rodrigues disse:

    Amigo, usa a mesma regra do SSH.

    /ip firewall filter
    add action=drop chain=input comment=\
    "BLOQUEIA SSH BRUTE FORCERS - MENOS DO IP 172.31.255.2" disabled=no \
    dst-port=22 protocol=tcp src-address=!172.31.255.2 src-address-list=\
    ssh_blacklist
    add action=add-src-to-address-list address-list=ssh_blacklist \
    address-list-timeout=10w3d chain=input connection-state=new disabled=no \
    dst-port=22 protocol=tcp src-address-list=ssh_stage3
    add action=add-src-to-address-list address-list=ssh_stage3 \
    address-list-timeout=1m chain=input connection-state=new disabled=no \
    dst-port=22 protocol=tcp src-address-list=ssh_stage2
    add action=add-src-to-address-list address-list=ssh_stage2 \
    address-list-timeout=1m chain=input connection-state=new disabled=no \
    dst-port=22 protocol=tcp src-address-list=ssh_stage1
    add action=add-src-to-address-list address-list=ssh_stage1 \
    address-list-timeout=1m chain=input connection-state=new disabled=no \
    dst-port=22 protocol=tcp src-address=!172.31.255.2

    Substitui as portas.

  • A porta do FTP é a 21

    /ip firewall filter
    add action=drop chain=input comment=\
    "BLOQUEIA FTP BRUTE FORCERS - MENOS DO IP 172.31.255.2" disabled=no \
    dst-port=21 protocol=tcp src-address=!172.31.255.2 src-address-list=\
    ftp_blacklist
    add action=add-src-to-address-list address-list=ftp_blacklist \
    address-list-timeout=10w3d chain=input connection-state=new disabled=no \
    dst-port=21 protocol=tcp src-address-list=ftp_stage3
    add action=add-src-to-address-list address-list=ftp_stage3 \
    address-list-timeout=1m chain=input connection-state=new disabled=no \
    dst-port=21 protocol=tcp src-address-list=ftp_stage2
    add action=add-src-to-address-list address-list=ftp_stage2 \
    address-list-timeout=1m chain=input connection-state=new disabled=no \
    dst-port=21 protocol=tcp src-address-list=ftp_stage1
    add action=add-src-to-address-list address-list=ftp_stage1 \
    address-list-timeout=1m chain=input connection-state=new disabled=no \
    dst-port=21 protocol=tcp src-address=!172.31.255.2

    Só colocar essa regra ai.

  • Aqui em nossa cidade a oí esta pessima... todo mundo reclamando da operadora não tem concorrente!!!!

  • se vc não usa a porta 22 desabilita ela em "services"

    Willian Douglas dos Santos disse:

    so muda as portas correto?

  • so muda as portas correto?

  • Amigo, usa a mesma regra do SSH.

    /ip firewall filter
    add action=drop chain=input comment=\
    "BLOQUEIA SSH BRUTE FORCERS - MENOS DO IP 172.31.255.2" disabled=no \
    dst-port=22 protocol=tcp src-address=!172.31.255.2 src-address-list=\
    ssh_blacklist
    add action=add-src-to-address-list address-list=ssh_blacklist \
    address-list-timeout=10w3d chain=input connection-state=new disabled=no \
    dst-port=22 protocol=tcp src-address-list=ssh_stage3
    add action=add-src-to-address-list address-list=ssh_stage3 \
    address-list-timeout=1m chain=input connection-state=new disabled=no \
    dst-port=22 protocol=tcp src-address-list=ssh_stage2
    add action=add-src-to-address-list address-list=ssh_stage2 \
    address-list-timeout=1m chain=input connection-state=new disabled=no \
    dst-port=22 protocol=tcp src-address-list=ssh_stage1
    add action=add-src-to-address-list address-list=ssh_stage1 \
    address-list-timeout=1m chain=input connection-state=new disabled=no \
    dst-port=22 protocol=tcp src-address=!172.31.255.2

    Substitui as portas.

This reply was deleted.