SlideShare a Scribd company logo
1 of 1
Reglas de Firewall: /ip firewall filter add action=add-src-to-address-list address-list=Block-
DDoS  address-list-timeout=none-dynamic chain=input comment=" Block DDoS"  connection-
limit=32,32 disabled=yes protocol=tcp add action=tarpit chain=input connection-limit=10,32
protocol=tcp  src-address-list=Block-DDoS comment="" disabled=yes add action=accept
chain=input comment="Acceso winbox desde trunk" dst-port= 8291 disabled=yes protocol=tcp
add action=drop chain=input dst-port=53 in-interface=ether4 log-prefix= DNS protocol=udp
disabled=yes comment=" Bloquea consultas DNS desde Internet" add action=accept
chain=input disabled=yes comment= " Permite sesiones TCP input establecidas" connection-
state=established add action=accept chain=input comment= " Permite sesiones TCP input
relacionadas" disabled=yes connection-state=related add action=accept chain=input
comment=" Acceso al DHCP server" disabled=yes dst-port=67-68  log-prefix="DHCP
REQUEST" protocol=udp add action=accept chain=input comment= " Permite utilizar el MK
como DNS Server" disabled=yes dst-port=53 protocol=udp add action=drop chain=input
comment=" No permite sesiones TCP input invalidas"  connection-state=invalid log-
prefix="DROP INPUT INVALIDAS" disabled=yes add action=drop chain=input comment="
DENIEGO TODO LO QUE ENTRE AL ROUTER Y NO  ESTC9 EXPLICITAMENTE
PERMITIDO" log-prefix="DROP INPUT" protocol=!icmp disabled=yes add action=accept
chain=forward comment=" Permite sesiones TCP establecidas"  connection-state=established
disabled=yes add action=accept chain=forward comment=" Permite sesiones TCP
relacionadas"  connection-state=related disabled=yes add action=accept chain=forward
comment=" Permite PING" log-prefix=PING  protocol=icmp disabled=yes add action=accept
chain=forward comment=" Permite HTTP" dst-port=80 protocol= tcp disabled=yes add
action=accept chain=forward comment=" Permite 587 Secure Mail" dst-port=587  protocol=tcp
disabled=yes add action=accept chain=forward comment=" Permite HTTPS" dst-port=443 
protocol=tcp disabled=yes add action=accept chain=forward comment=" Permite FTP" dst-
port=21 protocol= tcp disabled=yes add action=accept chain=forward comment=" Permite
SSH" dst-port=22 protocol= tcp disabled=yes add action=accept chain=forward comment="
Permite SSH 1122" dst-port=1122  protocol=tcp disabled=yes add action=accept
chain=forward comment=" Permite DNS" dst-port=53 protocol= udp disabled=yes add
action=accept chain=forward comment=" Permite SMTP" dst-port=25 protocol= tcp
disabled=yes add action=accept chain=forward comment=" Permite SMTP" dst-port=465
protocol= tcp disabled=yes add action=accept chain=forward comment=" Permite POP3" dst-
port=110 protocol= tcp disabled=yes add action=accept chain=forward comment=" Permite
POP3S" dst-port=995  protocol=tcp disabled=yes add action=accept chain=forward
comment=" Permite IMAP" dst-port=143 protocol= tcp disabled=yes add action=accept
chain=forward comment=" Permite IMAPS" dst-port=993  protocol=tcp disabled=yes add
action=accept chain=forward comment=" Permite RDP" dst-port=3389 protocol= tcp
disabled=yes add action=drop chain=forward comment=" DISABLED No permite sesiones
TCP invalidas"  connection-state=invalid disabled=yes log-prefix="DROP FORWARD
INVALIDAS" add action=drop chain=forward comment=" DENIEGO TODO LO QUE
ATRAVIESE EL ROUTER _Y NO ESTC9 EXPLICITAMENTE PERMITIDO" log=yes  log-
prefix="DROP FORWARD" disabled=yes

More Related Content

Similar to Reglas de Firewall.docx

Balance pcc para 3 links adsl com modem em bridge
Balance pcc para 3 links adsl com modem em bridgeBalance pcc para 3 links adsl com modem em bridge
Balance pcc para 3 links adsl com modem em bridgejoadsoNjo
 
Configure Mikrotik Khmer.pdf
Configure Mikrotik Khmer.pdfConfigure Mikrotik Khmer.pdf
Configure Mikrotik Khmer.pdfBT Digital
 
Net game 2 wan Mikrosik
Net game 2 wan MikrosikNet game 2 wan Mikrosik
Net game 2 wan MikrosikKhunut Thi-ai
 
Lightning fast with Varnish
Lightning fast with VarnishLightning fast with Varnish
Lightning fast with VarnishVarnish Software
 
Balanceo con 2 wan
Balanceo con 2 wanBalanceo con 2 wan
Balanceo con 2 wanrodolfin007
 
Balanceo con 2 wan
Balanceo con 2 wanBalanceo con 2 wan
Balanceo con 2 wanrodolfin007
 
Modul dhcp server menggunakan mikrotik os
Modul dhcp server menggunakan mikrotik osModul dhcp server menggunakan mikrotik os
Modul dhcp server menggunakan mikrotik osEen Pahlefi
 
3 queue firewall
3 queue firewall3 queue firewall
3 queue firewallmaster 82
 
Counting on God
Counting on GodCounting on God
Counting on GodJames Gray
 
Puppet Camp Charlotte 2015: Exporting Resources: There and Back Again
Puppet Camp Charlotte 2015: Exporting Resources: There and Back AgainPuppet Camp Charlotte 2015: Exporting Resources: There and Back Again
Puppet Camp Charlotte 2015: Exporting Resources: There and Back AgainPuppet
 
Limitar traff brdg-mkt
Limitar traff brdg-mktLimitar traff brdg-mkt
Limitar traff brdg-mktJose Sanchez
 
Http capturing
Http capturingHttp capturing
Http capturingEric Ahn
 
Mail server configuration
Mail server configurationMail server configuration
Mail server configurationchacheng oo
 
presentation_microtik y sus buenas practicas.pdf
presentation_microtik y sus buenas practicas.pdfpresentation_microtik y sus buenas practicas.pdf
presentation_microtik y sus buenas practicas.pdfYsraelSaucedoRojas
 
Debugging: Rules & Tools
Debugging: Rules & ToolsDebugging: Rules & Tools
Debugging: Rules & ToolsIan Barber
 
DJ-08-Forms-HTML.pptx
DJ-08-Forms-HTML.pptxDJ-08-Forms-HTML.pptx
DJ-08-Forms-HTML.pptxDamien Raczy
 

Similar to Reglas de Firewall.docx (20)

Balance pcc para 3 links adsl com modem em bridge
Balance pcc para 3 links adsl com modem em bridgeBalance pcc para 3 links adsl com modem em bridge
Balance pcc para 3 links adsl com modem em bridge
 
Fail2ban
Fail2banFail2ban
Fail2ban
 
Configure Mikrotik Khmer.pdf
Configure Mikrotik Khmer.pdfConfigure Mikrotik Khmer.pdf
Configure Mikrotik Khmer.pdf
 
Speedtest
SpeedtestSpeedtest
Speedtest
 
Net game 2 wan Mikrosik
Net game 2 wan MikrosikNet game 2 wan Mikrosik
Net game 2 wan Mikrosik
 
Lightning fast with Varnish
Lightning fast with VarnishLightning fast with Varnish
Lightning fast with Varnish
 
Balanceo con 2 wan
Balanceo con 2 wanBalanceo con 2 wan
Balanceo con 2 wan
 
Balanceo con 2 wan
Balanceo con 2 wanBalanceo con 2 wan
Balanceo con 2 wan
 
Modul dhcp server menggunakan mikrotik os
Modul dhcp server menggunakan mikrotik osModul dhcp server menggunakan mikrotik os
Modul dhcp server menggunakan mikrotik os
 
3 queue firewall
3 queue firewall3 queue firewall
3 queue firewall
 
Counting on God
Counting on GodCounting on God
Counting on God
 
Puppet Camp Charlotte 2015: Exporting Resources: There and Back Again
Puppet Camp Charlotte 2015: Exporting Resources: There and Back AgainPuppet Camp Charlotte 2015: Exporting Resources: There and Back Again
Puppet Camp Charlotte 2015: Exporting Resources: There and Back Again
 
Limitar traff brdg-mkt
Limitar traff brdg-mktLimitar traff brdg-mkt
Limitar traff brdg-mkt
 
Http capturing
Http capturingHttp capturing
Http capturing
 
Mail server configuration
Mail server configurationMail server configuration
Mail server configuration
 
presentation_microtik y sus buenas practicas.pdf
presentation_microtik y sus buenas practicas.pdfpresentation_microtik y sus buenas practicas.pdf
presentation_microtik y sus buenas practicas.pdf
 
Memcache as udp traffic reflector
Memcache as udp traffic reflectorMemcache as udp traffic reflector
Memcache as udp traffic reflector
 
Command
CommandCommand
Command
 
Debugging: Rules & Tools
Debugging: Rules & ToolsDebugging: Rules & Tools
Debugging: Rules & Tools
 
DJ-08-Forms-HTML.pptx
DJ-08-Forms-HTML.pptxDJ-08-Forms-HTML.pptx
DJ-08-Forms-HTML.pptx
 

Recently uploaded

VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kestopur 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Roomdivyansh0kumar0
 
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663Call Girls Mumbai
 
Denver Web Design brochure for public viewing
Denver Web Design brochure for public viewingDenver Web Design brochure for public viewing
Denver Web Design brochure for public viewingbigorange77
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024APNIC
 
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls KolkataLow Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on DeliveryCall Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Deliverybabeytanya
 
Challengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya Shirtrahman018755
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGAPNIC
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...APNIC
 
Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
VIP Kolkata Call Girl Alambazar 👉 8250192130 Available With Room
VIP Kolkata Call Girl Alambazar 👉 8250192130  Available With RoomVIP Kolkata Call Girl Alambazar 👉 8250192130  Available With Room
VIP Kolkata Call Girl Alambazar 👉 8250192130 Available With Roomdivyansh0kumar0
 
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls KolkataVIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
象限策略:Google Workspace 与 Microsoft 365 对业务的影响 .pdf
象限策略:Google Workspace 与 Microsoft 365 对业务的影响 .pdf象限策略:Google Workspace 与 Microsoft 365 对业务的影响 .pdf
象限策略:Google Workspace 与 Microsoft 365 对业务的影响 .pdfkeithzhangding
 
AlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsAlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsThierry TROUIN ☁
 
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Delhi Call girls
 

Recently uploaded (20)

VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kestopur 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
 
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
 
Denver Web Design brochure for public viewing
Denver Web Design brochure for public viewingDenver Web Design brochure for public viewing
Denver Web Design brochure for public viewing
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
 
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
 
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls KolkataLow Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on DeliveryCall Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
 
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
 
Challengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya Shirt
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOG
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
Vip Call Girls Aerocity ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Aerocity ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Aerocity ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Aerocity ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝
 
VIP Kolkata Call Girl Alambazar 👉 8250192130 Available With Room
VIP Kolkata Call Girl Alambazar 👉 8250192130  Available With RoomVIP Kolkata Call Girl Alambazar 👉 8250192130  Available With Room
VIP Kolkata Call Girl Alambazar 👉 8250192130 Available With Room
 
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls KolkataVIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
象限策略:Google Workspace 与 Microsoft 365 对业务的影响 .pdf
象限策略:Google Workspace 与 Microsoft 365 对业务的影响 .pdf象限策略:Google Workspace 与 Microsoft 365 对业务的影响 .pdf
象限策略:Google Workspace 与 Microsoft 365 对业务的影响 .pdf
 
AlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsAlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with Flows
 
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
 
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 

Reglas de Firewall.docx

  • 1. Reglas de Firewall: /ip firewall filter add action=add-src-to-address-list address-list=Block- DDoS address-list-timeout=none-dynamic chain=input comment=" Block DDoS" connection- limit=32,32 disabled=yes protocol=tcp add action=tarpit chain=input connection-limit=10,32 protocol=tcp src-address-list=Block-DDoS comment="" disabled=yes add action=accept chain=input comment="Acceso winbox desde trunk" dst-port= 8291 disabled=yes protocol=tcp add action=drop chain=input dst-port=53 in-interface=ether4 log-prefix= DNS protocol=udp disabled=yes comment=" Bloquea consultas DNS desde Internet" add action=accept chain=input disabled=yes comment= " Permite sesiones TCP input establecidas" connection- state=established add action=accept chain=input comment= " Permite sesiones TCP input relacionadas" disabled=yes connection-state=related add action=accept chain=input comment=" Acceso al DHCP server" disabled=yes dst-port=67-68 log-prefix="DHCP REQUEST" protocol=udp add action=accept chain=input comment= " Permite utilizar el MK como DNS Server" disabled=yes dst-port=53 protocol=udp add action=drop chain=input comment=" No permite sesiones TCP input invalidas" connection-state=invalid log- prefix="DROP INPUT INVALIDAS" disabled=yes add action=drop chain=input comment=" DENIEGO TODO LO QUE ENTRE AL ROUTER Y NO ESTC9 EXPLICITAMENTE PERMITIDO" log-prefix="DROP INPUT" protocol=!icmp disabled=yes add action=accept chain=forward comment=" Permite sesiones TCP establecidas" connection-state=established disabled=yes add action=accept chain=forward comment=" Permite sesiones TCP relacionadas" connection-state=related disabled=yes add action=accept chain=forward comment=" Permite PING" log-prefix=PING protocol=icmp disabled=yes add action=accept chain=forward comment=" Permite HTTP" dst-port=80 protocol= tcp disabled=yes add action=accept chain=forward comment=" Permite 587 Secure Mail" dst-port=587 protocol=tcp disabled=yes add action=accept chain=forward comment=" Permite HTTPS" dst-port=443 protocol=tcp disabled=yes add action=accept chain=forward comment=" Permite FTP" dst- port=21 protocol= tcp disabled=yes add action=accept chain=forward comment=" Permite SSH" dst-port=22 protocol= tcp disabled=yes add action=accept chain=forward comment=" Permite SSH 1122" dst-port=1122 protocol=tcp disabled=yes add action=accept chain=forward comment=" Permite DNS" dst-port=53 protocol= udp disabled=yes add action=accept chain=forward comment=" Permite SMTP" dst-port=25 protocol= tcp disabled=yes add action=accept chain=forward comment=" Permite SMTP" dst-port=465 protocol= tcp disabled=yes add action=accept chain=forward comment=" Permite POP3" dst- port=110 protocol= tcp disabled=yes add action=accept chain=forward comment=" Permite POP3S" dst-port=995 protocol=tcp disabled=yes add action=accept chain=forward comment=" Permite IMAP" dst-port=143 protocol= tcp disabled=yes add action=accept chain=forward comment=" Permite IMAPS" dst-port=993 protocol=tcp disabled=yes add action=accept chain=forward comment=" Permite RDP" dst-port=3389 protocol= tcp disabled=yes add action=drop chain=forward comment=" DISABLED No permite sesiones TCP invalidas" connection-state=invalid disabled=yes log-prefix="DROP FORWARD INVALIDAS" add action=drop chain=forward comment=" DENIEGO TODO LO QUE ATRAVIESE EL ROUTER _Y NO ESTC9 EXPLICITAMENTE PERMITIDO" log=yes log- prefix="DROP FORWARD" disabled=yes