mirror of
https://github.com/thatmattlove/hyperglass.git
synced 2026-02-07 17:58:24 +00:00
Update sample_directives_mikrotik.yaml
This commit is contained in:
parent
5d86d069c2
commit
55612c93fd
1 changed files with 159 additions and 1 deletions
|
|
@ -1 +1,159 @@
|
|||
|
||||
MikroTik_Traceroute:
|
||||
name: Traceroute
|
||||
rules:
|
||||
# REGRA DENY RFC 6598
|
||||
- condition: '100.64.0.0/10'
|
||||
ge: 10
|
||||
le: 32
|
||||
action: deny
|
||||
# REGRA DENY RFC 1918 CLASSE A
|
||||
- condition: '10.0.0.0/8'
|
||||
ge: 8
|
||||
le: 32
|
||||
action: deny
|
||||
# REGRA DENY RFC 1918 CLASSE B
|
||||
- condition: '172.16.0.0/12'
|
||||
ge: 12
|
||||
le: 32
|
||||
action: deny
|
||||
# REGRA DENY RFC 1918 CLASSE C
|
||||
- condition: '192.168.0.0/16'
|
||||
ge: 16
|
||||
le: 32
|
||||
action: deny
|
||||
# REGRA DENY LO
|
||||
- condition: '127.0.0.0/8'
|
||||
ge: 8
|
||||
le: 32
|
||||
action: deny
|
||||
# REGRA DENY ASN PREFIXO
|
||||
- condition: 'SEU_PREFIXO_IPv4_AGORA'
|
||||
ge: 22
|
||||
le: 32
|
||||
action: deny
|
||||
# REGRA DENY DEFAULT ROUTE
|
||||
- condition: '0.0.0.0/8'
|
||||
ge: 8
|
||||
le: 32
|
||||
action: deny
|
||||
- condition: '0.0.0.0/0'
|
||||
ge: 32
|
||||
le: 32
|
||||
action: permit
|
||||
command: 'tool traceroute src-address={source4} timeout=1 duration=5 count=1 {target}'
|
||||
# REGRA DENY SITE LOCAL DEPRECIADO RFC 3879
|
||||
- condition: 'fec0::/10'
|
||||
ge: 10
|
||||
le: 128
|
||||
action: deny
|
||||
# REGRA DENY ULA RFC 4193
|
||||
- condition: 'fc00::/7'
|
||||
ge: 7
|
||||
le: 128
|
||||
action: deny
|
||||
# REGRA DENY LINK LOCAL RFC 4291
|
||||
- condition: 'fe80::/10'
|
||||
ge: 10
|
||||
le: 128
|
||||
action: deny
|
||||
# REGRA DENY Unspecified RFC 4291
|
||||
- condition: '::/128'
|
||||
ge: 128
|
||||
le: 128
|
||||
action: deny
|
||||
# REGRA DENY LO RFC 4291
|
||||
- condition: '::1/128'
|
||||
ge: 128
|
||||
le: 128
|
||||
action: deny
|
||||
# REGRA DENY ASN PREFIXO
|
||||
- condition: 'SEU_PREFIXO_IPv6_AGORA'
|
||||
ge: 32
|
||||
le: 128
|
||||
action: deny
|
||||
- condition: '::/0'
|
||||
ge: 128
|
||||
le: 128
|
||||
action: permit
|
||||
command: 'tool traceroute src-address={source6} timeout=1 duration=5 count=1 {target}'
|
||||
field:
|
||||
description: IP Address, or Hostname
|
||||
MikroTik_Ping:
|
||||
name: Ping
|
||||
rules:
|
||||
# REGRA DENY RFC 6598
|
||||
- condition: '100.64.0.0/10'
|
||||
ge: 10
|
||||
le: 32
|
||||
action: deny
|
||||
# REGRA DENY RFC 1918 CLASSE A
|
||||
- condition: '10.0.0.0/8'
|
||||
ge: 8
|
||||
le: 32
|
||||
action: deny
|
||||
# REGRA DENY RFC 1918 CLASSE B
|
||||
- condition: '172.16.0.0/12'
|
||||
ge: 12
|
||||
le: 32
|
||||
action: deny
|
||||
# REGRA DENY RFC 1918 CLASSE C
|
||||
- condition: '192.168.0.0/16'
|
||||
ge: 16
|
||||
le: 32
|
||||
action: deny
|
||||
# REGRA DENY LO
|
||||
- condition: '127.0.0.0/8'
|
||||
ge: 8
|
||||
le: 32
|
||||
action: deny
|
||||
# REGRA DENY ASN PREFIXO
|
||||
- condition: 'SEU_PREFIXO_IPv4_AGORA'
|
||||
ge: 22
|
||||
le: 32
|
||||
action: deny
|
||||
# REGRA DENY DEFAULT ROUTE
|
||||
- condition: '0.0.0.0/8'
|
||||
ge: 8
|
||||
le: 32
|
||||
action: deny
|
||||
- condition: '0.0.0.0/0'
|
||||
ge: 32
|
||||
le: 32
|
||||
command: 'ping src-address={source4} count=5 {target}'
|
||||
# REGRA DENY SITE LOCAL DEPRECIADO RFC 3879
|
||||
- condition: 'fec0::/10'
|
||||
ge: 10
|
||||
le: 128
|
||||
action: deny
|
||||
# REGRA DENY ULA RFC 4193
|
||||
- condition: 'fc00::/7'
|
||||
ge: 7
|
||||
le: 128
|
||||
action: deny
|
||||
# REGRA DENY LINK LOCAL RFC 4291
|
||||
- condition: 'fe80::/10'
|
||||
ge: 10
|
||||
le: 128
|
||||
action: deny
|
||||
# REGRA DENY Unspecified RFC 4291
|
||||
- condition: '::/128'
|
||||
ge: 128
|
||||
le: 128
|
||||
action: deny
|
||||
# REGRA DENY LO RFC 4291
|
||||
- condition: '::1/128'
|
||||
ge: 128
|
||||
le: 128
|
||||
action: deny
|
||||
# REGRA DENY ASN PREFIXO
|
||||
- condition: 'SEU_PREFIXO_IPv6_AGORA'
|
||||
ge: 32
|
||||
le: 128
|
||||
action: deny
|
||||
- condition: '::/0'
|
||||
ge: 128
|
||||
le: 128
|
||||
action: permit
|
||||
command: 'ping src-address={source6} count=5 {target}'
|
||||
field:
|
||||
description: IP Address, or Hostname
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue