Mon Aug 25, 2014 10:08 am
/ip firewall address-list
add address=1.1.1.0/24 list=limitted-group
src-address-list=limitted-group
/ip firewall filter
add action=drop chain=forward dst-port=5242 protocol=tcp src-address-list=\
limitted-group
add action=drop chain=forward dst-port=4244 protocol=tcp src-address-list=\
limitted-group
add action=drop chain=forward dst-port=5243 protocol=udp src-address-list=\
limitted-group
add action=drop chain=forward dst-port=9785 protocol=udp src-address-list=\
limitted-group
/ip firewall mangle
add action=mark-packet chain=forward dst-port=80,433 new-packet-mark=new-PM \
passthrough=no protocol=tcp src-address-list=limitted-group
add action=mark-connection chain=forward dst-port=80,344 new-connection-mark=\
MC packet-mark=new-PM protocol=tcp src-address-list=limitted-group