otaviorossetto
(usa Nenhuma)
Enviado em 02/06/2017 - 19:08h
Consegui dessa forma:
[admin@MikroTik] > ip
[admin@MikroTik] /ip> firewall
[admin@MikroTik] /ip firewall> filter
[admin@MikroTik] /ip firewall filter> export
# jun/02/2017 22:08:48 by RouterOS 6.38.5
# software id = B8NS-NEUC
#
/ip firewall filter
add action=accept chain=forward comment="======Libera Consulta Editora Supervisor======" disabled=yes layer7-protocol=\
Consulta_Editora protocol=tcp src-address-list=Faixa_Supervisor
add action=accept chain=forward comment="======Libera Assina Ja Supervisor======" disabled=yes layer7-protocol=\
Site_AssinaJa protocol=tcp src-address-list=Faixa_Supervisor
add action=accept chain=forward comment="======Libera Site Portal Bradesco Supervisor======" disabled=yes \
layer7-protocol=Site_Portal_BradescoDental protocol=tcp src-address-list=Faixa_Supervisor
add action=accept chain=forward comment="======Libera Site Vivo Supervisor======" disabled=yes layer7-protocol=Site_Vivo2 \
protocol=tcp src-address-list=Faixa_Supervisor
add action=accept chain=forward comment="======Libera Site Vivo Web Vendas GVT Supervisor======" disabled=yes \
layer7-protocol=Site_Vivo protocol=tcp src-address-list=Faixa_Supervisor
add action=accept chain=forward comment="======Libera Site Bradesco Supervisor======" disabled=yes layer7-protocol=\
Site_Bradesco protocol=tcp src-address-list=Faixa_Supervisor
add action=accept chain=forward comment="======Libera Site Bradesco Promotora Supervisor======" disabled=yes \
layer7-protocol=Site_BradescoPromotor protocol=tcp src-address-list=Faixa_Supervisor
add action=accept chain=forward comment="=======Libera Site Correios Supervisor======" disabled=yes layer7-protocol=\
Site_Correios protocol=tcp src-address-list=Faixa_Supervisor
add action=accept chain=forward comment="======Libera Webmail Supervisor======" disabled=yes layer7-protocol=\
Site_WebmailSeguro protocol=tcp src-address-list=Faixa_Supervisor
add action=accept chain=forward comment="======Libera Receita Federal Supervisor======" disabled=yes layer7-protocol=\
Site_Receita protocol=tcp src-address-list=Faixa_Supervisor
add action=accept chain=forward comment="======Libera Congonhas Supervisor======" disabled=yes layer7-protocol=\
Site_Congonhas protocol=tcp src-address-list=Faixa_Supervisor
add action=accept chain=forward comment="======Libera Google Supervisor======" disabled=yes layer7-protocol=Site_Google \
protocol=tcp src-address-list=Faixa_Supervisor
add action=accept chain=forward comment="======Libera Assina Ja======" layer7-protocol=Site_AssinaJa protocol=tcp \
src-address-list=Faixa_Operacao
add action=accept chain=forward comment="======Libera Libera Services Make======" layer7-protocol=Site_ServicesMakesystem \
protocol=tcp src-address-list=Faixa_Operacao
add action=accept chain=forward comment="======Libera Site MakeSystem======" layer7-protocol=Site_MakeSystem protocol=tcp \
src-address-list=Faixa_Operacao
add action=accept chain=forward comment="======Libera Site Portal Bradesco======" layer7-protocol=\
Site_Portal_BradescoDental protocol=tcp src-address-list=Faixa_Operacao
add action=accept chain=forward comment="======Libera Site Vivo======" layer7-protocol=Site_Vivo2 protocol=tcp \
src-address-list=Faixa_Operacao
add action=accept chain=forward comment="======Libera Site Vivo Web Vendas GVT======" layer7-protocol=Site_Vivo protocol=\
tcp src-address-list=Faixa_Operacao
add action=accept chain=forward comment="======Libera Site Bradesco======" layer7-protocol=Site_Bradesco protocol=tcp \
src-address-list=Faixa_Operacao
add action=accept chain=forward comment="======Libera Site Bradesco Promotora======" layer7-protocol=\
Site_BradescoPromotor protocol=tcp src-address-list=Faixa_Operacao
add action=accept chain=forward comment="=======Libera Site Correios======" layer7-protocol=Site_Correios protocol=tcp \
src-address-list=Faixa_Operacao
add action=accept chain=forward comment="======Libera Consulta Editora======" layer7-protocol=Consulta_Editora protocol=\
tcp src-address-list=Faixa_Operacao
add action=accept chain=forward comment="========LIbera Telefine dos sonhos Operacao========" layer7-protocol=\
Site_TelefonedosSonhos protocol=tcp src-address-list=Faixa_Operacao
add action=accept chain=forward comment="======Libera WebService Correios ======" disabled=yes layer7-protocol=\
Site_Webservice_correios protocol=tcp src-address-list=Faixa_Operacao
add action=accept chain=forward comment="======WebService Correios II ======" disabled=yes layer7-protocol=\
Web_service_correios protocol=tcp src-address-list=Faixa_Operacao
add action=reject chain=forward comment="========Bloqueio Geral Operacao========" layer7-protocol=Bloqueio_Operacao \
protocol=tcp reject-with=tcp-reset src-address-list=Faixa_Operacao
add action=reject chain=forward comment="======Bloqueio Geral Supervisor======" disabled=yes layer7-protocol=\
Bloqueio_Supervisor protocol=tcp reject-with=tcp-reset src-address-list=Faixa_Supervisor
add action=accept chain=input comment="Bloqueio Internet" disabled=yes dst-port=8080 protocol=tcp src-address-list=OP
add action=accept chain=input comment="Acesso Remoto MK" dst-port=8088 protocol=tcp src-address=0.0.0.0/0
add action=accept chain=input dst-port=8291 protocol=tcp src-address=0.0.0.0/0
add action=log chain=input comment="Regras Gerais" log-prefix=Firewall
add action=log chain=input dst-port=8088 log-prefix=Firewall protocol=tcp src-address=0.0.0.0/0
add action=log chain=forward log-prefix=Firewall
add action=accept chain=input in-interface=bridge1 src-address=192.168.1.0/24
add action=accept chain=forward in-interface=bridge1 src-address=192.168.1.0/24
add action=accept chain=input dst-port=53 protocol=udp src-address=192.168.1.0/24
add action=accept chain=forward dst-port=53 protocol=udp src-address=192.168.1.0/24
add action=accept chain=forward dst-port=53 protocol=udp src-address=192.168.1.0/24
add action=accept chain=forward src-address=192.168.1.0/24
add action=accept chain=input src-address=192.168.1.0/24
add action=accept chain=input connection-state=established
add action=accept chain=input connection-state=related
add action=accept chain=input protocol=icmp
add action=drop chain=input dst-port=3128 in-interface=vivo protocol=tcp src-address=!192.168.1.0/24
add action=drop chain=input connection-state=invalid in-interface=vivo src-address=!192.168.1.0/24
add action=accept chain=forward comment="Liberando Google" disabled=yes in-interface=vivo layer7-protocol=*1 src-address=\
!192.168.1.0/24
add action=drop chain=forward comment="Libera\E7\E3o facebook" disabled=yes in-interface=vivo layer7-protocol=*2 \
src-address=!192.168.1.0/24
add action=drop chain=forward comment="Bloqueio Facebook" disabled=yes in-interface=vivo layer7-protocol=*2 src-address=\
!192.168.1.0/24
add action=drop chain=forward comment="Bloqueio Youtube" disabled=yes in-interface=vivo layer7-protocol=*3 src-address=\
!192.168.1.0/24
[admin@MikroTik] /ip firewall filter> export firewall filter
[admin@MikroTik] > ip
[admin@MikroTik] /ip> firewall
[admin@MikroTik] /ip firewall> mangle
[admin@MikroTik] /ip firewall mangle> export
# jun/02/2017 22:12:49 by RouterOS 6.38.5
# software id = B8NS-NEUC
#
[admin@MikroTik] /ip firewall mangle>