0 D chain=forward action=jump jump-target=hs-unauth hotspot=from-client,!auth
1 D chain=forward action=jump jump-target=hs-unauth-to hotspot=to-client,!auth
2 D chain=input action=jump jump-target=hs-input hotspot=from-client
3 D chain=input action=drop protocol=tcp hotspot=!from-client
dst-port=64872-64875
4 D chain=hs-input action=jump jump-target=pre-hs-input
5 D chain=hs-input action=accept protocol=udp dst-port=64872
6 D chain=hs-input action=accept protocol=tcp dst-port=64872-64875
7 D chain=hs-input action=jump jump-target=hs-unauth hotspot=!auth
8 D chain=hs-unauth action=reject reject-with=tcp-reset protocol=tcp
9 D chain=hs-unauth action=reject reject-with=icmp-net-prohibited
10 D chain=hs-unauth-to action=reject reject-with=icmp-host-prohibited
11 X ;;; place hotspot rules here
chain=unused-hs-chain action=passthrough
12 ;;; drop ssh brute forcers
chain=input action=drop protocol=tcp src-address-list=ssh_blacklist
dst-port=221 log=no log-prefix=""
13 chain=input action=add-src-to-address-list connection-state=new
protocol=tcp src-address-list=ssh_stage3 address-list=ssh_blacklist
address-list-timeout=1w3d dst-port=221 log=no log-prefix=""
14 chain=input action=add-src-to-address-list connection-state=new
protocol=tcp src-address-list=ssh_stage2 address-list=ssh_stage3
address-list-timeout=1m dst-port=221 log=no log-prefix=""
15 chain=input action=add-src-to-address-list connection-state=new
protocol=tcp src-address-list=ssh_stage1 address-list=ssh_stage2
address-list-timeout=1m dst-port=221 log=no log-prefix=""
16 chain=input action=add-src-to-address-list connection-state=new
protocol=tcp address-list=ssh_stage1 address-list-timeout=1h1m
dst-port=221 log=no log-prefix=""
17 X ;;; torrent /announce...
chain=forward action=drop protocol=tcp src-address=!
192.168.88.83 in-interface=bridge-lan dst-port=2710,80 content=info_hash= log=no
log-prefix=""
18 X ;;; torrent-DHT-Out-Magnet d1:ad2:id20:
chain=forward action=drop protocol=udp src-address=!
192.168.88.83 in-interface=bridge-lan dst-port=1025-65535 content=d1:ad2:id20:
packet-size=95-190 log=no log-prefix=""
19 chain=input action=drop protocol=tcp in-interface=pppoe-out1 dst-port=80
log=no log-prefix=""
20 chain=input action=accept protocol=tcp dst-address=
94.255.83.207 dst-port=8080 log=no log-prefix=""
21 ;;; VPN guard
chain=input action=drop protocol=udp src-address-list=!home dst-port=1701
log=yes log-prefix="PVN drop----"
22 ;;; VPN guard 500p
chain=input action=drop protocol=udp src-address-list=!home dst-port=500
log=yes log-prefix="PVN 500----"
23 ;;; Dostup Admina k seti
chain=forward action=accept src-address=
192.168.20.22 dst-address=
192.168.0.0/24 log=no log-prefix="YA-"
24 ;;; Dostup Admina k seti
chain=forward action=accept src-address=
192.168.88.33 dst-address=192.168.0.0/24 log=no log-prefix="YA-"
25 ;;; Dostup Admina k seti lenovo
chain=forward action=accept src-address=
192.168.88.60 dst-address=
192.168.0.0/24 log=yes log-prefix="YA-"
26 ;;; Dostup vova k seti
chain=forward action=accept src-address=
192.168.88.83 dst-address=192.168.0.0/24 log=no log-prefix=""
27 ;;; Dostup vova k seti
chain=forward action=accept src-address=
192.168.88.163 dst-address=
192.168.0.0/24 log=no log-prefix=""
28 ;;; Dostup vova k seti
chain=forward action=accept src-address=
192.168.88.75 dst-address=192.168.0.0/24 log=no log-prefix=""
29 ;;; Dostup vova k seti
chain=forward action=accept src-address=
192.168.20.83 dst-address=192.168.0.0/24 log=no log-prefix=""
30 ;;; Dostup Admina k seti lenovo
chain=forward action=accept src-address=
192.168.20.42 dst-address=192.168.0.0/24 log=yes log-prefix="YA-"