rad bych pozadal o radu s nastavenim FW pravidel na RB532.
Situace:
Mam NAS Synology, pripojeny do LAN (ETH3) na ktery vidim, kdyz pouziji prohlizec, zadam IP NAS serveru (192.168.20.4) z PC (192.168.10.20) - ETH2, NTB/Mobilu (WLAN1).
Kazdy Interface ma vlastni DHCP.
Jde mi to, pripojit si share na NASu jako disk na PC/NTB (WIN7). Zkousel jsem zadat jak nazev serveru, tak IP, a bez uspechu. Kdyz jsem zkousel pouzit Synology Assistent, tak take NAS nenasel.
nastaveni FW
Kód: Vybrat vše
/ip firewall connection tracking
set enabled=yes generic-timeout=10m icmp-timeout=10s tcp-close-timeout=10s tcp-close-wait-timeout=10s tcp-established-timeout=1d \
tcp-fin-wait-timeout=10s tcp-last-ack-timeout=10s tcp-syn-received-timeout=5s tcp-syn-sent-timeout=5s tcp-syncookie=no tcp-time-wait-timeout=\
10s udp-stream-timeout=3m udp-timeout=10s
/ip firewall filter
add action=accept chain=input comment="Povoleni pristupu z vnitrni site" disabled=no src-address=192.168.10.0/24
add action=accept chain=input disabled=no src-address=192.168.20.0/24
add action=accept chain=input disabled=no src-address=192.168.30.0/24
add action=jump chain=forward comment="kontrola VIRY" disabled=no jump-target=virus
add action=drop chain=virus disabled=no dst-port=69 protocol=tcp
add action=drop chain=virus disabled=no dst-port=111 protocol=tcp
add action=drop chain=virus disabled=no dst-port=111 protocol=udp
add action=drop chain=virus disabled=no dst-port=135-139 protocol=tcp
add action=drop chain=virus disabled=no dst-port=135-139 protocol=udp
add action=drop chain=virus disabled=no dst-port=444-445 protocol=tcp
add action=drop chain=virus disabled=no dst-port=444-445 protocol=udp
add action=drop chain=virus disabled=no dst-port=593 protocol=tcp
add action=drop chain=virus disabled=no dst-port=1024-1030 protocol=tcp
add action=drop chain=virus disabled=no dst-port=1080 protocol=tcp
add action=drop chain=virus disabled=no dst-port=1214 protocol=tcp
add action=drop chain=virus disabled=no dst-port=1363-1364 protocol=tcp
add action=drop chain=virus disabled=no dst-port=1368 protocol=tcp
add action=drop chain=virus disabled=no dst-port=1373 protocol=tcp
add action=drop chain=virus disabled=no dst-port=1377 protocol=tcp
add action=drop chain=virus disabled=no dst-port=1433-1434 protocol=tcp
add action=drop chain=virus disabled=no dst-port=2045 protocol=tcp
add action=drop chain=virus disabled=no dst-port=2045 protocol=udp
add action=drop chain=virus disabled=no dst-port=2283 protocol=tcp
add action=drop chain=virus disabled=no dst-port=2535 protocol=tcp
add action=drop chain=virus disabled=no dst-port=2745 protocol=tcp
add action=drop chain=virus disabled=no dst-port=2745 protocol=udp
add action=drop chain=virus disabled=no dst-port=3127-3128 protocol=tcp
add action=drop chain=virus disabled=no dst-port=3133 protocol=tcp
add action=drop chain=virus disabled=no dst-port=3133 protocol=udp
add action=drop chain=virus disabled=no dst-port=3410 protocol=tcp
add action=drop chain=virus disabled=no dst-port=4444 protocol=udp
add action=drop chain=virus disabled=no dst-port=4444 protocol=tcp
add action=drop chain=virus disabled=no dst-port=5554 protocol=tcp
add action=drop chain=virus disabled=no dst-port=8866 protocol=tcp
add action=drop chain=virus disabled=no dst-port=9898 protocol=tcp
add action=drop chain=virus disabled=no dst-port=10000 protocol=tcp
add action=drop chain=virus disabled=no dst-port=10080 protocol=tcp
add action=drop chain=virus disabled=no dst-port=12345-12346 protocol=tcp
add action=drop chain=virus disabled=no dst-port=17300 protocol=tcp
add action=drop chain=virus disabled=no dst-port=17940 protocol=tcp
add action=drop chain=virus disabled=no dst-port=20034 protocol=tcp
add action=drop chain=virus disabled=no dst-port=27374 protocol=tcp
add action=drop chain=virus disabled=no dst-port=33322 protocol=tcp
add action=drop chain=virus disabled=no dst-port=65506 protocol=tcp
add action=accept chain=input comment=UDP disabled=no protocol=udp
add action=accept chain=input comment="Allow limited pings" disabled=no limit=50/5s,2 protocol=icmp
add action=drop chain=input comment="Drop excess pings" disabled=no protocol=icmp
add action=accept chain=input comment="SSH for secure shell" disabled=no dst-port=22 protocol=tcp
add action=accept chain=input comment=winbox disabled=no dst-port=8291 protocol=tcp
add action=accept chain=input comment=VOIP disabled=no dst-port=10000-20000 protocol=udp src-port=10000-20000
add action=drop chain=input comment="Zahazovani Invalid Packets" connection-state=invalid disabled=no
add action=accept chain=input comment="Accept established packet" connection-state=established disabled=no
add action=accept chain=input comment="Accept related packet" connection-state=related disabled=no
add action=add-src-to-address-list address-list=port_scan address-list-timeout=5d chain=input comment="Port Scan Filter" disabled=no protocol=tcp \
src-address-list=!port_scan
add action=drop chain=input comment="Drop enything else" disabled=no in-interface=ether1
add action=accept chain=forward comment="Established Connection Accept" connection-state=established disabled=no in-interface=ether1
add action=log chain=forward comment="Log everything else" disabled=no in-interface=ether1 log-prefix="DROP INPUT"
add action=drop chain=forward disabled=no in-interface=ether1
/ip firewall mangle
add action=mark-connection chain=forward disabled=no new-connection-mark=p2p_conn p2p=all-p2p passthrough=yes
add action=mark-packet chain=forward connection-mark=p2p_conn disabled=no new-packet-mark=p2p passthrough=yes
add action=mark-packet chain=forward connection-mark=!p2p_conn disabled=no new-packet-mark=other passthrough=yes
/ip firewall nat
add action=masquerade chain=srcnat disabled=no out-interface=ether1 src-address=192.168.10.0/24
add action=masquerade chain=srcnat disabled=no out-interface=ether1 src-address=192.168.20.0/24
add action=masquerade chain=srcnat disabled=no out-interface=ether1 src-address=192.168.30.0/24
Dale bych poprosil o radu s pravidlem, aby se me na NAS nikdo nedostal z venku. Pripadne zakazat, aby se sam vykecaval do Internetu (ETH1)
Budu velmi rad za rady, pripadne napady co mam zmenit v konfiguraci, tak abych NAS mohl pripojit jako disk ve WIN7.
Diky moc
Mike