Доброго времени суток, нужен опытный совет, подходит ли дынный фаервол для защиты микротика:
0 D ;;; special dummy rule to show fasttrack counters
chain=forward action=passthrough
1 chain=forward action=fasttrack-connection connection-state=established,related log=no log-prefix=""
2 ;;; IPSec
chain=forward action=accept log=no log-prefix="" ipsec-policy=in,ipsec
3 chain=forward action=accept log=no log-prefix="" ipsec-policy=out,ipsec
4 ;;; Base-Exchange-Rules
chain=input action=accept connection-state=established log=no log-prefix=""
5 chain=forward action=accept connection-state=established log=no log-prefix=""
6 chain=forward action=accept src-address=
192.168.3.0/24 log=no log-prefix=""
7 chain=forward action=accept connection-state=related log=no log-prefix=""
8 chain=input action=accept connection-state=related log=no log-prefix=""
9 ;;; Forward-Access
chain=forward action=accept protocol=tcp in-interface=pppoe-out dst-port=8000 log=no log-prefix=""
10 ;;; Remote-Access
chain=input action=accept src-address-list=Remote-Access log=no log-prefix=""
11 ;;; ICMP
chain=input action=accept protocol=icmp log=no log-prefix=""
12 ;;; Drop-Invalid
chain=input action=drop connection-state=invalid log=no log-prefix=""
13 chain=forward action=drop connection-state=invalid log=no log-prefix=""
14 ;;; Drop-Other
chain=input action=drop in-interface=pppoe-out log=no log-prefix=""
15 chain=forward action=drop log=no log-prefix=""