He cambiado los Ap de casa (por fin) y he aprovechado para meter capsman, tengo 4 redes wifis, IoT, Invitados, niños y la principal.
El router es un Rb3011 y los caps son HapAc2.
Buenas noches!
Quitaríais/añadiríais algo?/ip firewall filter
add action=add-src-to-address-list address-list=LOGINS_FALLIDOS address-list-timeout=none-dynamic chain=input comment="REGISTRO DE LOGINS FALLIDOS" \
connection-state=new dst-port=8289 limit=!1/1m,3acket protocol=tcp
add action=add-src-to-address-list address-list=LOGINS_FALLIDOS_TELEGRAM address-list-timeout=none-dynamic chain=input connection-state=new dst-port=\
8289 limit=!1/1m,3acket protocol=tcp
add action=drop chain=forward comment="ACCESO A INTERNET BLOQUEDO POR EXCESO DE LOGINS" src-address-list=LOGINS_FALLIDOS
add action=drop chain=input comment="ACCESO A ROUTER BLOQUEDO POR EXCESO DE LOGINS" src-address-list=LOGINS_FALLIDOS
add action=drop chain=input comment="DROP INPUT INTERFACES INVITADOS -- IoT" in-interface-list="RED INVITADOS -- IoT"
add action=drop chain=input comment="DROP INPUT WIFI NI\D1OS" in-interface-list="RED NI\D1OS"
add action=drop chain=forward comment="DROP FORWARD WIFI INVITADOS -- IoT > LAN" in-interface-list="RED INVITADOS -- IoT" out-interface-list=LAN
add action=drop chain=forward comment="DROP FORWARD WIFI NI\D1OS -- IoT > LAN" in-interface-list="RED NI\D1OS" out-interface-list=LAN
add action=drop chain=forward comment="DROP FORWARD WIFI INVITADOS -- IoT > NI\D1OS" in-interface-list="RED INVITADOS -- IoT" out-interface-list=\
"RED NI\D1OS"
add action=drop chain=forward comment="DROP FORWARD WIFI INVITADOS --> IoT" in-interface=bridge-Invitados out-interface=bridge-IoT-WiFi
add action=accept chain=input comment="WIREGUARD ROAMING ACCEPT" dst-port=16880 in-interface-list=WAN-INTERNET log-prefix=\
"CONEXION WIREGUARD ROAMING ACEPTADA" protocol=udp
add action=accept chain=input comment="WIREGUARD PtP ACCEPT" dst-port=16881 in-interface-list=WAN-INTERNET log-prefix="CONEXION WIREGUARD PtP" protocol=\
udp
add action=accept chain=input comment="WINBOX WIREGUARD ROAMING" dst-port=8289 in-interface-list=WIREGUARD log-prefix="ACCESO POR WIREGUARD" protocol=\
tcp src-address-list=WIREGUARD-VPN
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related hw-offload=yes in-interface=CASA
add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=\
WAN-INTERNET
El router es un Rb3011 y los caps son HapAc2.
Buenas noches!