[randy@Angola Hotspot Router] > /ip firewall export
# jul/19/2011 16:51:19 by RouterOS 5.4
# software id = P42A-955A
#
/ip firewall address-list
add address=192.168.10.0/27 disabled=no list="Hotel Staff"
add address=1.0.0.0/8 disabled=no list=Bogons
add address=2.0.0.0/8 disabled=no list=Bogons
add address=5.0.0.0/8 disabled=no list=Bogons
add address=7.0.0.0/8 disabled=no list=Bogons
add address=10.0.0.0/8 disabled=no list=Bogons
add address=23.0.0.0/8 disabled=no list=Bogons
add address=27.0.0.0/8 disabled=no list=Bogons
add address=31.0.0.0/8 disabled=no list=Bogons
add address=36.0.0.0/8 disabled=no list=Bogons
add address=37.0.0.0/8 disabled=no list=Bogons
add address=39.0.0.0/8 disabled=no list=Bogons
add address=42.0.0.0/8 disabled=no list=Bogons
add address=49.0.0.0/8 disabled=no list=Bogons
add address=50.0.0.0/8 disabled=no list=Bogons
add address=77.0.0.0/8 disabled=no list=Bogons
add address=78.0.0.0/8 disabled=no list=Bogons
add address=79.0.0.0/8 disabled=no list=Bogons
add address=92.0.0.0/8 disabled=no list=Bogons
add address=93.0.0.0/8 disabled=no list=Bogons
add address=94.0.0.0/8 disabled=no list=Bogons
add address=95.0.0.0/8 disabled=no list=Bogons
add address=96.0.0.0/8 disabled=no list=Bogons
add address=97.0.0.0/8 disabled=no list=Bogons
add address=98.0.0.0/8 disabled=no list=Bogons
add address=99.0.0.0/8 disabled=no list=Bogons
add address=100.0.0.0/8 disabled=no list=Bogons
add address=101.0.0.0/8 disabled=no list=Bogons
add address=102.0.0.0/8 disabled=no list=Bogons
add address=103.0.0.0/8 disabled=no list=Bogons
add address=104.0.0.0/8 disabled=no list=Bogons
add address=105.0.0.0/8 disabled=no list=Bogons
add address=106.0.0.0/8 disabled=no list=Bogons
add address=107.0.0.0/8 disabled=no list=Bogons
add address=108.0.0.0/8 disabled=no list=Bogons
add address=109.0.0.0/8 disabled=no list=Bogons
add address=110.0.0.0/8 disabled=no list=Bogons
add address=111.0.0.0/8 disabled=no list=Bogons
add address=112.0.0.0/8 disabled=no list=Bogons
add address=113.0.0.0/8 disabled=no list=Bogons
add address=114.0.0.0/8 disabled=no list=Bogons
add address=115.0.0.0/8 disabled=no list=Bogons
add address=116.0.0.0/8 disabled=no list=Bogons
add address=117.0.0.0/8 disabled=no list=Bogons
add address=118.0.0.0/8 disabled=no list=Bogons
add address=119.0.0.0/8 disabled=no list=Bogons
add address=120.0.0.0/8 disabled=no list=Bogons
add address=121.0.0.0/8 disabled=no list=Bogons
add address=122.0.0.0/8 disabled=no list=Bogons
add address=123.0.0.0/8 disabled=no list=Bogons
add address=169.254.0.0/16 disabled=no list=Bogons
add address=172.16.0.0/12 disabled=no list=Bogons
add address=174.0.0.0/8 disabled=no list=Bogons
add address=175.0.0.0/8 disabled=no list=Bogons
add address=176.0.0.0/8 disabled=no list=Bogons
add address=177.0.0.0/8 disabled=no list=Bogons
add address=178.0.0.0/8 disabled=no list=Bogons
add address=179.0.0.0/8 disabled=no list=Bogons
add address=180.0.0.0/8 disabled=no list=Bogons
add address=181.0.0.0/8 disabled=no list=Bogons
add address=182.0.0.0/8 disabled=no list=Bogons
add address=183.0.0.0/8 disabled=no list=Bogons
add address=184.0.0.0/8 disabled=no list=Bogons
add address=185.0.0.0/8 disabled=no list=Bogons
add address=186.0.0.0/8 disabled=no list=Bogons
add address=187.0.0.0/8 disabled=no list=Bogons
add address=192.0.2.0/24 disabled=no list=Bogons
add address=192.168.0.0/16 disabled=yes list=Bogons
add address=197.0.0.0/8 disabled=no list=Bogons
add address=198.18.0.0/15 disabled=no list=Bogons
add address=223.0.0.0/8 disabled=no list=Bogons
add address=192.168.10.20 disabled=no list=Black-List
add address=192.168.10.21 disabled=no list=Black-List
add address=192.168.10.22 disabled=no list=Black-List
add address=192.168.10.23 disabled=no list=Black-List
add address=192.168.10.24 disabled=no list=Black-List
add address=192.168.10.25 disabled=no list=Black-List
/ip firewall connection tracking
set enabled=yes generic-timeout=10m icmp-timeout=10s tcp-close-timeout=10s tcp-close-wait-timeout=10s tcp-established-timeout=1d \
tcp-fin-wait-timeout=10s tcp-last-ack-timeout=10s tcp-syn-received-timeout=5s tcp-syn-sent-timeout=5s tcp-syncookie=yes \
tcp-time-wait-timeout=10s udp-stream-timeout=3m udp-timeout=10s
/ip firewall filter
add action=drop chain=forward comment="Block internet: POS" disabled=no protocol=tcp src-address=192.168.10.20
add action=drop chain=forward comment="Block internet: POS" disabled=no protocol=tcp src-address=192.168.10.21
add action=drop chain=forward comment="Block internet: POS" disabled=no protocol=tcp src-address=192.168.10.22
add action=drop chain=forward comment="Block internet: POS" disabled=no protocol=tcp src-address=192.168.10.23
add action=drop chain=forward comment="Block internet: POS" disabled=no protocol=tcp src-address=192.168.10.24
add action=drop chain=forward comment="Block internet: POS" disabled=no protocol=tcp src-address=192.168.10.25
add action=drop chain=input comment="Block internet: POS" disabled=no protocol=tcp src-address=192.168.10.20
add action=drop chain=input comment="Block internet: POS" disabled=no protocol=tcp src-address=192.168.10.21
add action=drop chain=input comment="Block internet: POS" disabled=no protocol=tcp src-address=192.168.10.22
add action=drop chain=input comment="Block internet: POS" disabled=no protocol=tcp src-address=192.168.10.23
add action=drop chain=input comment="Block internet: POS" disabled=no protocol=tcp src-address=192.168.10.24
add action=drop chain=input comment="Block internet: POS" disabled=no protocol=tcp src-address=192.168.10.25
add action=jump chain=input comment="Jump to Virus Chain" disabled=no jump-target=Virus
add action=passthrough chain=unused-hs-chain comment="place hotspot rules here" disabled=yes
add action=drop chain=input comment="Drop anyone in the Black-List" disabled=no src-address-list=Black-List
add action=drop chain=forward comment="Drop anyone in the Black-List" disabled=no src-address-list=Black-List
add action=drop chain=forward comment="Drop Bogons (Set LAN Interface)" disabled=no dst-address-type="" dst-limit=0,5,dst-address/1m40s \
fragment=no in-interface=ether2 limit=0,5 psd=21,3s,3,1 src-address-list=Bogons src-address-type="" time=\
0s-23h59m59s,sun,mon,tue,wed,thu,fri,sat
add action=add-src-to-address-list address-list=Black-List address-list-timeout=1d chain=input comment=\
"Transfer repeated attempts from SSH Stage 3 to Black-List" connection-state=new disabled=no dst-port=22 protocol=tcp src-address-list=\
ssh_stage3
add action=add-src-to-address-list address-list=ssh_stage3 address-list-timeout=1m chain=input comment=\
"Add succesive attempts to SSH Stage 3" connection-state=new disabled=no dst-port=22 protocol=tcp src-address-list=ssh_stage2
add action=add-src-to-address-list address-list=ssh_stage2 address-list-timeout=1m chain=input comment=\
"Add succesive attempts to SSH Stage 2" connection-state=new disabled=no dst-port=22 protocol=tcp src-address-list=ssh_stage1
add action=add-src-to-address-list address-list=ssh_stage1 address-list-timeout=1m chain=input comment=\
"Add intial attempt to SSH Stage 1 List" connection-state=new disabled=no dst-port=22 protocol=tcp
add action=add-src-to-address-list address-list=Black-List address-list-timeout=1d chain=input comment=\
"Transfer repeated attempts from Telnet Stage 3 to Black-List" connection-state=new disabled=no dst-port=23 protocol=tcp \
src-address-list=telnet_stage3
add action=add-src-to-address-list address-list=telnet_stage3 address-list-timeout=1m chain=input comment=\
"Add succesive attempts to Telnet Stage 3" connection-state=new disabled=no dst-port=23 protocol=tcp src-address-list=telnet_stage2
add action=add-src-to-address-list address-list=telnet_stage2 address-list-timeout=1m chain=input comment=\
"Add succesive attempts to Telnet Stage 2" connection-state=new disabled=no dst-port=23 protocol=tcp src-address-list=telnet_stage1
add action=add-src-to-address-list address-list=telnet_stage1 address-list-timeout=1m chain=input comment=\
"Add Intial attempt to Telnet Stage 1" connection-state=new disabled=no dst-port=23 protocol=tcp
add action=add-src-to-address-list address-list="Port Scanners" address-list-timeout=0s chain=forward comment=\
"Add TCP Port Scanners to Address List" disabled=yes protocol=tcp psd=40,3s,2,1
add action=drop chain=input comment="Drop [Port Scanners]" disabled=yes src-address-list="Port Scanners"
add action=drop chain=forward comment="Drop [Port Scanners]" disabled=yes src-address-list="Port Scanners"
add action=drop chain=input comment="Drop Invalid Connections" connection-state=invalid disabled=no
add action=drop chain=forward comment="Drop Invalid Connections" connection-state=invalid disabled=no
add action=passthrough chain=forward disabled=no src-address=192.167.18.0/24
add action=drop chain=Virus comment="Drop Blaster Worm" disabled=no dst-port=135-139 protocol=tcp
add action=drop chain=Virus comment="Drop Blaster Worm" disabled=no dst-port=445 protocol=tcp
add action=drop chain=Virus comment="Drop Blaster Worm" disabled=no dst-port=445 protocol=udp
add action=drop chain=Virus comment="Drop Messenger Worm" disabled=no dst-port=135-139 protocol=udp
add action=drop chain=Virus comment=Conficker disabled=no dst-port=593 protocol=tcp
add action=drop chain=Virus comment=Worm disabled=no dst-port=1024-1030 protocol=tcp
add action=drop chain=Virus comment="ndm requester" disabled=no dst-port=1363 protocol=tcp
add action=drop chain=Virus comment="ndm server" disabled=no dst-port=1364 protocol=tcp
add action=drop chain=Virus comment="screen cast" disabled=no dst-port=1368 protocol=tcp
add action=drop chain=Virus comment=hromgrafx disabled=no dst-port=1373 protocol=tcp
add action=drop chain=Virus comment="Drop MyDoom" disabled=no dst-port=1080 protocol=tcp
add action=drop chain=Virus comment=Worm disabled=no dst-port=1433-1434 protocol=tcp
add action=drop chain=Virus comment="Drop Dumaru.Y" disabled=no dst-port=2283 protocol=tcp
add action=drop chain=Virus comment="Drop Beagle" disabled=no dst-port=2535 protocol=tcp
add action=drop chain=Virus comment="Drop Beagle.C-K" disabled=no dst-port=2745 protocol=tcp
add action=drop chain=Virus comment="Drop MyDoom" disabled=no dst-port=3127-3128 protocol=tcp
add action=drop chain=Virus comment="Drop Backdoor OptixPro" disabled=no dst-port=3410 protocol=tcp
add action=drop chain=Virus comment="Drop Sasser" disabled=no dst-port=5554 protocol=tcp
add action=drop chain=Virus comment=Worm disabled=no dst-port=4444 protocol=tcp
add action=drop chain=Virus comment=Worm disabled=no dst-port=4444 protocol=udp
add action=drop chain=Virus comment="Drop Beagle.B" disabled=no dst-port=8866 protocol=tcp
add action=drop chain=Virus comment="Drop Dabber.A-B" disabled=no dst-port=9898 protocol=tcp
add action=drop chain=Virus comment="Drop Dumaru.Y" disabled=no dst-port=10000 protocol=tcp
add action=drop chain=Virus comment="Drop MyDoom.B" disabled=no dst-port=10080 protocol=tcp
add action=drop chain=Virus comment=cichlid disabled=no dst-port=1377 protocol=tcp
add action=drop chain=Virus comment="Drop NetBus" disabled=no dst-port=12345 protocol=tcp
add action=drop chain=Virus comment="Drop Kuang2" disabled=no dst-port=17300 protocol=tcp
add action=drop chain=Virus comment="Drop SubSeven" disabled=no dst-port=27374 protocol=tcp
add action=drop chain=Virus comment="Drop PhatBot, Agobot, Gaobot" disabled=no dst-port=65506 protocol=tcp
add action=drop chain=forward comment="Drop all P2P" disabled=yes p2p=all-p2p
add action=drop chain=forward comment="All 192.168.10.x addresses can not access any address starting with 192.167" disabled=no dst-address=\
192.167.0.0/16 src-address=192.168.10.0/24
/ip firewall mangle
add action=set-priority chain=prerouting comment="DSCP - 7 - Skype, HTTPS" disabled=no dst-port=443 new-priority=7 passthrough=yes protocol=\
tcp
add action=set-priority chain=prerouting comment="Priority - 7 - Skype, HTTPS" disabled=no dst-port=443 new-priority=7 passthrough=yes \
protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 7 - VOIP" disabled=no new-priority=7 passthrough=yes port=1167,1719,1720,8010 \
protocol=udp
add action=set-priority chain=prerouting comment="Priority - 7 - VOIP" disabled=no new-priority=7 passthrough=yes port=1719,1720,8008,8009 \
protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 7 - Ventrilo VOIP" disabled=no new-priority=7 passthrough=yes port=3784 \
protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 7 - Ventrilo VOIP" disabled=no new-priority=7 passthrough=yes port=3784,3785 \
protocol=udp
add action=set-priority chain=prerouting comment="Priority - 7 - Windows Live Messenger Voice" disabled=no new-priority=7 passthrough=yes \
port=6901 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 7 - Windows Live Messenger Voice" disabled=no new-priority=7 passthrough=yes \
port=6901 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 7 - SIP" disabled=no new-priority=7 passthrough=yes port=5060 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 7 - SIP" disabled=no new-priority=7 passthrough=yes port=5060 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 6 - SSH" disabled=no new-priority=6 passthrough=yes port=22 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 6 - Telnet" disabled=no new-priority=6 passthrough=yes port=23 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 6 - ICMP" disabled=no new-priority=6 passthrough=yes protocol=icmp
add action=set-priority chain=prerouting comment="Priority - 6 - TCP DNS Requests" disabled=no new-priority=6 passthrough=yes port=53 \
protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 6 - UDP DNS & mDNS Requests" disabled=no new-priority=6 passthrough=yes port=\
53,5353 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 6 - SSH" disabled=no new-priority=6 passthrough=yes port=22 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 6 - PPTP VPNs" disabled=no new-priority=6 passthrough=yes port=1723 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 6 - PPTP VPNs" disabled=no new-priority=6 passthrough=yes port=1723 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 5 - HTTP Requests" connection-bytes=0-5000000 disabled=no dst-port=80 \
new-priority=5 passthrough=yes protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 4 - Yahoo IM" disabled=no new-priority=4 passthrough=yes port=5050 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 4 - ICQ" disabled=no new-priority=4 passthrough=yes port=5190 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 4 - Time" disabled=no new-priority=4 passthrough=yes port=37 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 4 - Time" disabled=no new-priority=4 passthrough=yes port=37,123 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 4 - AOL, IRC" disabled=no new-priority=4 passthrough=yes port=\
531,5190,6660-6669,6679,6697 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 4 - AOL, IRC" disabled=no new-priority=4 passthrough=yes port=531 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - File Sharing" disabled=no new-priority=0 p2p=all-p2p passthrough=yes
add action=set-priority chain=prerouting comment="Priority - 0 - SFTP" disabled=no dst-port=22 new-priority=0 packet-size=1400-1500 \
passthrough=yes protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - FTP" disabled=no dst-port=20,21 new-priority=0 packet-size=1400-1500 \
passthrough=yes protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - HTTP Downloads" connection-bytes=5000000-0 disabled=no new-priority=0 \
passthrough=yes port=80 protocol=tcp
add action=accept chain=prerouting comment="Priority - 0 - Mail Services" disabled=no port=110,995,143,993,25,57,109,465,587 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - SNMP" disabled=no new-priority=0 passthrough=yes port=161,162 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - SNMP" disabled=no new-priority=0 passthrough=yes port=162 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - IMAP, IMAPS" disabled=no new-priority=0 passthrough=yes port=220,993 \
protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - IMAP" disabled=no new-priority=0 passthrough=yes port=220 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - Doom FPS" disabled=no new-priority=0 passthrough=yes port=666 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - America's Army MMO" disabled=no new-priority=0 passthrough=yes port=1716 \
protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - Civilization MMO" disabled=no new-priority=0 passthrough=yes port=2056 \
protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - Halo: Combat Evolved MMO" disabled=no new-priority=0 passthrough=yes port=\
2302 protocol=udp
add action=accept chain=prerouting comment="Priority - 0 - Dark Ages" disabled=no port=2610 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - Xbox Live" disabled=no new-priority=0 passthrough=yes port=3074 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - Xbox Live" disabled=no new-priority=0 passthrough=yes port=3074 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - Blizzard Games Online" disabled=no new-priority=0 passthrough=yes port=\
3723,6112 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - Blizzard Games Online" disabled=no new-priority=0 passthrough=yes port=3723 \
protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - WoW MMO" disabled=no new-priority=0 passthrough=yes port=3724 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - WoW MMO" disabled=no new-priority=0 passthrough=yes port=3724 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - Club Penguin Disney Online" disabled=no new-priority=0 passthrough=yes port=\
3724,6112,6113,9875 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - Diablo II" disabled=no new-priority=0 passthrough=yes port=4000 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - Diablo II" disabled=no new-priority=0 passthrough=yes port=4000 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - Microsoft Ants MMO" disabled=no new-priority=0 passthrough=yes port=4001 \
protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - Google Desktop" disabled=no new-priority=0 passthrough=yes port=4664 \
protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - BZFlag" disabled=no new-priority=0 passthrough=yes port=5154 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - BZFlag" disabled=no new-priority=0 passthrough=yes port=5154 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - Freeciv MMO" disabled=no new-priority=0 passthrough=yes port=5556 protocol=\
tcp
add action=set-priority chain=prerouting comment="Priority - 0 - Freeciv MMO" disabled=no new-priority=0 passthrough=yes port=5556 protocol=\
udp
add action=set-priority chain=prerouting comment="Priority - 0 - Windows Live Messenger File Transfer" disabled=no new-priority=4 \
passthrough=yes port=6891-6900 protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - Enemy Territory: Quake Wars" disabled=no new-priority=0 passthrough=yes \
port=7133 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - Teamspeak" disabled=no new-priority=0 passthrough=yes port=8767-8768 \
protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - Teamspeak" disabled=no new-priority=0 passthrough=yes port=9987 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - Earthland Relams 2" disabled=no new-priority=0 passthrough=yes port=\
8888-8889 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - Sony Playstation" disabled=no new-priority=0 passthrough=yes port=9293 \
protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - Battlefield 1942 MMO" disabled=no new-priority=0 passthrough=yes port=14567 \
protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - Battlefield Vietnam" disabled=no new-priority=0 passthrough=yes port=15567 \
protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - Battlefield 2" disabled=no new-priority=0 passthrough=yes port=16567 \
protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - Quake" disabled=no new-priority=0 passthrough=yes port=26000 protocol=tcp
add action=set-priority chain=prerouting comment="Priority - 0 - Quake" disabled=no new-priority=0 passthrough=yes port=26000,27901,27960 \
protocol=udp
add action=set-priority chain=prerouting comment="Priority - 0 - Call of Duty" disabled=no new-priority=0 passthrough=yes port=28960 \
protocol=udp
add action=mark-connection chain=prerouting disabled=no new-connection-mark="Hotel Room-Conn" passthrough=yes src-address=\
192.168.10.101-192.168.10.219
add action=mark-packet chain=prerouting connection-mark="Hotel Room-Conn" disabled=no new-packet-mark="Hotel Rooms" passthrough=no
/ip firewall nat
add action=passthrough chain=unused-hs-chain comment="place hotspot rules here" disabled=yes
add action=masquerade chain=srcnat comment="Masquerade Everything" disabled=no out-interface=ether1
add action=redirect chain=dstnat comment="Transparent Proxy Cache" disabled=no dst-port=80 protocol=tcp src-address=192.167.18.0/24 to-ports=\
8989
/ip firewall service-port
set ftp disabled=no ports=21
set tftp disabled=no ports=69
set irc disabled=no ports=6667
set h323 disabled=no
set sip disabled=no ports=5060,5061
set pptp disabled=no