{"id":303140,"date":"2020-05-06T21:00:26","date_gmt":"2020-05-06T21:00:26","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=303140"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=303140","title":{"rendered":"Mikrotik firewall filter: \u0441\u043a\u0440\u0438\u043f\u0442 \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u043e\u0441\u043d\u043e\u0432\u0443 \u0434\u043b\u044f \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438"},"content":{"rendered":"\n<div class=\"post__text post__text-html post__text_v1\" id=\"post-content-body\" data-io-article-url=\"https:\/\/habr.com\/ru\/post\/500148\/\">\u041a\u0442\u043e \u0445\u043e\u0442\u044c \u0440\u0430\u0437 \u043f\u0438\u0441\u0430\u043b \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0443 \u0444\u0438\u043b\u044c\u0440\u0430\u0446\u0438\u0438 firewall \u0437\u043d\u0430\u0435\u0442, \u0447\u0442\u043e \u044d\u0442\u043e \u0434\u0435\u043b\u043e \u043d\u0435 \u043f\u0440\u043e\u0441\u0442\u043e\u0435 \u0438 \u0441\u043e\u043f\u0440\u044f\u0436\u0435\u043d\u043e \u0441 \u043a\u0443\u0447\u0435\u0439 \u043e\u0448\u0438\u0431\u043e\u043a, \u043a\u043e\u0433\u0434\u0430 \u043a\u043e\u043b\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0437\u043e\u043d \u0431\u043e\u043b\u044c\u0448\u0435 2-\u0445. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0443\u0442\u0430\u0446\u0438\u0438 \u0432\u0430\u043c \u043f\u043e\u043c\u043e\u0436\u0435\u0442 \u0441\u043a\u0440\u0438\u043f\u0442 \u0438\u0437 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0438.<br \/>  <a name=\"habracut\"><\/a>  <\/p>\n<h2>\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435<\/h2>\n<p>  \u041f\u043e\u0434 \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u0437\u043e\u043d\u043e\u0439 \u044f \u043f\u043e\u0434\u0440\u0430\u0437\u0443\u043c\u0435\u0432\u0430\u044e \u0441\u043e\u0432\u043e\u043a\u0443\u043f\u043d\u043e\u0441\u0442\u044c \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432 \u0438\u043b\u0438 IP \u0430\u0434\u0440\u0435\u0441\u043e\u0432, \u0434\u043b\u044f \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438. \u0412 \u043c\u043e\u0435\u043c \u0441\u043a\u0440\u0438\u043f\u0442\u0435 IP \u0430\u0434\u0440\u0435\u0441\u0430 \u0437\u043e\u043d\u044b \u0437\u0430\u043a\u0440\u0435\u043f\u043b\u0435\u043d\u044b \u0437\u0430 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u043c. \u0422\u043e \u0435\u0441\u0442\u044c, \u0435\u0441\u043b\u0438 \u043c\u044b \u043e\u0436\u0438\u0434\u0430\u0435\u043c \u00ab\u0434\u043e\u0432\u0435\u0440\u0435\u043d\u043d\u044b\u0435\u00bb IP \u0430\u0434\u0440\u0435\u0441\u0430 \u0438\u0437 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0435\u0442\u0438, \u0442\u043e \u0431\u0443\u0434\u0435\u0442 \u0441\u0442\u0440\u0430\u043d\u043d\u043e, \u0435\u0441\u043b\u0438 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f \u043f\u0440\u0438\u043b\u0435\u0442\u044f\u0442 \u043a \u043d\u0430\u043c \u043e\u0442 \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u0430.<\/p>\n<h2>\u041a\u0430\u043a \u043e\u043d\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442<\/h2>\n<p>  \u0412\u0441\u0435 \u0432\u0435\u0440\u0442\u0438\u0442\u0441\u044f \u0432\u043e\u043a\u0440\u0443\u0433 \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u044f \u0437\u043e\u043d, \u0433\u0434\u0435 \u043c\u044b \u0437\u0430\u0434\u0430\u0435\u043c \u043a\u0430\u043a \u043e\u043d\u0438 \u043c\u0435\u0436\u0434\u0443 \u0441\u043e\u0431\u043e\u0439 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0443\u044e\u0442.<br \/>  \u0412 \u043c\u043e\u0435\u0439 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438, \u0435\u0441\u043b\u0438 \u043d\u0435 \u0437\u0430\u0434\u0430\u043d\u044b \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u0430, \u0432\u0435\u0441\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u0431\u0443\u0434\u0435\u0442 \u0441\u0431\u0440\u043e\u0448\u0435\u043d \u0441 \u043f\u0440\u0430\u0432\u0438\u043b\u043e\u043c DROP, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0437\u0430\u0434\u0430\u0432\u0430\u0442\u044c \u043f\u0440\u0430\u0432\u0438\u043b\u0430 ACCEPT \u0438 REJECT.<br \/>  \u0414\u0430\u043b\u0435\u0435 \u0441\u043a\u0440\u0438\u043f\u0442 \u0432 \u0446\u0438\u043a\u043b\u0435 \u043f\u0440\u043e\u0445\u043e\u0434\u0438\u0442 \u043f\u043e \u0432\u0441\u0435\u043c \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u044f\u043c \u0437\u043e\u043d \u0438 \u0441\u043e\u0437\u0434\u0430\u0435\u0442:  <\/p>\n<ul>\n<li>\u0421\u043f\u0438\u0441\u043a\u0438 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432 IF-&lt;\u0438\u043c\u044f \u0437\u043e\u043d\u044b&gt;<\/li>\n<li>\u0421\u043f\u0438\u0441\u043a\u0438 \u0430\u0434\u0440\u0435\u0441\u043e\u0432 IP-&lt;\u0438\u043c\u044f \u0437\u043e\u043d\u044b&gt;<\/li>\n<li>\u0417\u0430\u0434\u0430\u0435\u0442 \u0434\u0435\u0444\u043e\u043b\u0442\u043e\u0432\u0443\u044e \u0438 \u043d\u0435\u043c\u043d\u043e\u0433\u043e \u043c\u043d\u043e\u0439 \u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0443\u044e \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044e filter, mangle \u0438 raw<\/li>\n<\/ul>\n<p>  IP \u0437\u043e\u043d\u0430 \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u043e\u0442 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043d\u043e\u0439 \u043e\u0442\u043b\u0438\u0447\u0430\u0435\u0442\u0441\u044f \u0442\u0435\u043c, \u0447\u0442\u043e \u0435\u0451 \u0438\u043c\u0435\u043d\u0438 \u043d\u0435\u0442 \u0432 \u0440\u0430\u0437\u0434\u0435\u043b\u0435 \u0434\u043b\u044f \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432. \u0422\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c \u0441\u043a\u0440\u0438\u043f\u0442 \u0438 \u043f\u043e\u043d\u0438\u043c\u0430\u0435\u0442, \u0433\u0434\u0435 \u0443 \u043d\u0430\u0441 \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 ip, \u0430 \u0433\u0434\u0435 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441.<\/p>\n<h3>\u041f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0435<\/h3>\n<p>  <\/p>\n<ul>\n<li>gping \u2014 \u0420\u0430\u0437\u0440\u0435\u0448\u0438\u0442\u044c ping \u0432\u043e \u0432\u0441\u0435\u0445 \u043d\u0430\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f\u0445 \u0438 \u043d\u0430 \u043f\u0435\u0440\u0435\u0441\u044b\u043b\u043a\u0435. \u0418\u043d\u044b\u043c\u0438 \u0441\u043b\u043e\u0432\u0430\u043c\u0438, \u043f\u0438\u043d\u0433\u043e\u0432\u0430\u0442\u044c \u043c\u043e\u0436\u043d\u043e \u0431\u0443\u0434\u0435\u0442 \u0434\u0430\u0436\u0435 \u0442\u043e, \u0447\u0442\u043e \u0431\u044b\u043b\u043e \u0437\u0430\u043a\u0440\u044b\u0442\u043e \u0434\u0440\u0443\u0433\u0438\u043c\u0438 \u043f\u0440\u0430\u0432\u0438\u043b\u0430\u043c\u0438 \u0432 filter. \u0412\u043a\u043b\u044e\u0447\u0430\u0442\u044c \u043f\u043e \u0436\u0435\u043b\u0430\u043d\u0438\u044e \ud83d\ude09<\/li>\n<li>debug \u2014 \u0421\u0442\u0430\u0432\u0438\u0442 \u0432 \u0441\u0430\u043c\u043e\u0435 \u043d\u0430\u0447\u0430\u043b\u043e \u043a\u043e\u0440\u043d\u0435\u0432\u044b\u0445 \u0446\u0435\u043f\u043e\u0447\u0435\u043a ACCEPT \u043f\u0440\u0430\u0432\u0438\u043b\u043e, \u0447\u0442\u043e \u0434\u0435\u043b\u0430\u0435\u0442 \u0432\u0441\u0435 \u043e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0431\u0435\u0441\u043f\u043e\u043b\u0435\u0437\u043d\u044b\u043c\u0438. \u041e\u0447\u0435\u043d\u044c \u043f\u043e\u043b\u0435\u0437\u043d\u043e \u043d\u0430 \u044d\u0442\u0430\u043f\u0435 \u043e\u0442\u043b\u0430\u0434\u043a\u0438 \u043f\u0440\u0430\u0432\u0438\u043b. \u0414\u0435\u043b\u0430\u0435\u0442\u0435 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0443 \u043a\u0430\u043a \u0432\u044b \u0445\u043e\u0442\u0438\u0442\u0435, \u0432\u043a\u043b\u044e\u0447\u0430\u0435\u0442\u0435 Safe Mode, \u0430 \u043f\u043e\u0442\u043e\u043c \u044d\u0442\u0438 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u043e\u0442\u043a\u043b\u044e\u0447\u0430\u0435\u0442\u0435. \u0415\u0441\u043b\u0438 \u0440\u043e\u0443\u0442\u0435\u0440 \u0441\u0442\u0430\u043b \u043d\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d, \u0442\u043e \u0443\u0436\u0435 \u0447\u0435\u0440\u0435\u0437 10 \u0441\u0435\u043a \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0431\u0443\u0434\u0443\u0442 \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u044b \u043e\u043f\u044f\u0442\u044c \u0438 \u0432\u044b \u0441\u043c\u043e\u0436\u0435\u0442\u0435 \u043f\u043e\u0434\u0443\u043c\u0430\u0442\u044c, \u0430 \u0432 \u0447\u0435\u043c \u0432\u044b \u043e\u0448\u0438\u0431\u043b\u0438\u0441\u044c?<\/li>\n<\/ul>\n<p>  <\/p>\n<h3>\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0437\u043e\u043d<\/h3>\n<p>  \u0421\u0430\u043c\u043e \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0440\u0430\u0437\u0434\u0435\u043b\u0435\u043d\u043e \u043d\u0430 \u0434\u0432\u0430 \u0431\u043b\u043e\u043a\u0430: \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u044b \u0438 ip \u0430\u0434\u0440\u0435\u0441\u0430. \u0414\u043b\u044f \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432 \u0435\u0441\u0442\u044c \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0435 \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0435:  <\/p>\n<ul>\n<li>is_wan: \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0442\u0443\u043d\u0435\u043b\u0435\u0439 \u0438 DNS<\/li>\n<li>is_lan: \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0434\u043b\u044f \u043e\u0442\u0432\u0435\u0442\u0430 \u043d\u0430 DHCP \u0438 DNS<\/li>\n<li>mss: \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u043e\u0432\u043a\u0438 mss \u0434\u043b\u044f \u0442\u0443\u043d\u043d\u0435\u043b\u044c\u043d\u044b\u0445 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432, \u0435\u0441\u043b\u0438 \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u044b\u0435 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0432\u0430\u0441 \u043d\u0435 \u0443\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u044e\u0442<\/li>\n<\/ul>\n<p>  \u0422\u0430\u043a-\u0436\u0435 \u0435\u0441\u0442\u044c \u0434\u0432\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0435 \u0437\u043e\u043d\u044b: rt, \u044d\u0442\u043e \u0441\u0430\u043c \u0440\u043e\u0443\u0442\u0435\u0440, \u0438 all, \u043a\u0430\u043a \u043d\u0435 \u0442\u0440\u0443\u0434\u043d\u043e \u0434\u043e\u0433\u0430\u0434\u0430\u0442\u044c\u0441\u044f \u00ab\u043b\u044e\u0431\u043e\u0435 \u043d\u0430\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435\u00bb, all \u043d\u0435 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0443\u043a\u0430\u0437\u0430\u043d \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a\u0430 \u0442\u0440\u0430\u0444\u0438\u043a\u0430.<br \/>  \u041e\u0441\u043d\u043e\u0432\u043d\u043e\u0435 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0435 \u0441\u043a\u0440\u0438\u043f\u0442\u0430, \u044d\u0442\u043e \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u0435 \u0441\u0435\u0440\u0438\u0438 \u043f\u0440\u0430\u0432\u0438\u043b jump \u0441 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0435\u0439 \u043f\u043e \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a\u0443 \u0438 \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044e \u0442\u0440\u0430\u0444\u0438\u043a\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0442\u0435\u0440\u043c\u0438\u043d\u0438\u0440\u0443\u044e\u0442\u0441\u044f \u043f\u0440\u0430\u0432\u0438\u043b\u043e\u043c \u0441 ACCEPT \u0438\u043b\u0438 REJECT.<br \/>  \u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0437\u043e\u043d\u044b \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0440\u0435\u0434\u0443\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e, \u043a\u0430\u043a \u0432 \u043f\u0440\u0438\u043c\u0435\u0440\u0435 \u0434\u043b\u044f ISP \u0438 rt (\u0434\u043e\u043b\u0436\u043d\u043e \u0431\u044b\u0442\u044c \u0432\u0441\u0435\u0433\u0434\u0430).<br \/>  \u0415\u0441\u043b\u0438 \u0432\u044b \u0445\u043e\u0442\u0438\u0442\u0435 \u0442\u0435\u0440\u043c\u0438\u043d\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0446\u0435\u043f\u043e\u0447\u043a\u0443 \u0441\u0432\u043e\u0438\u043c \u043f\u0440\u0430\u0432\u0438\u043b\u043e\u043c, \u0442\u043e \u0432 \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0437\u043e\u043d\u044b \u043f\u0440\u043e\u0441\u0442\u043e \u0432\u043c\u0435\u0441\u0442\u043e accept \u0438\u043b\u0438 reject \u0432\u043f\u0438\u0448\u0438\u0442\u0435 custom (\u0438\u043b\u0438 \u0447\u0442\u043e \u0443\u0433\u043e\u0434\u043d\u043e), \u0442\u043e\u0433\u0434\u0430 \u0446\u0435\u043f\u043e\u0447\u043a\u0430 jump-\u043e\u0432 \u043d\u0435 \u0431\u0443\u0434\u0435\u0442 \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0430 \u043d\u0438\u043a\u0430\u043a\u0438\u043c \u043f\u0440\u0430\u0432\u0438\u043b\u043e\u043c, \u0430 \u0432\u044b \u0441\u043c\u043e\u0436\u0435\u0442\u0435 \u0441\u043e\u0437\u0434\u0430\u0442\u044c \u0435\u0433\u043e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e.<\/p>\n<h3>\u041f\u043e\u044f\u0441\u043d\u0435\u043d\u0438\u0435 \u043f\u0440\u0430\u0432\u0438\u043b \u0438\u0437 \u0441\u043a\u0440\u0438\u043f\u0442\u0430<\/h3>\n<p>  <\/p>\n<div class=\"spoiler\" role=\"button\" tabindex=\"0\">                         <b class=\"spoiler_title\">\u0417\u043e\u043d\u044b<\/b>                         <\/p>\n<div class=\"spoiler_text\">\n<pre><code class=\"bash\">:local gping 1 :local debug 0 :local zones { \t&quot;if&quot;={ \t\t&quot;ISP&quot;={ \t\t\t&quot;is_wan&quot;=1; \t\t}; \t\t&quot;LAN&quot;={ \t\t\t&quot;is_lan&quot;=1; \t\t\tpolicy={  \t\t\t\t&quot;all&quot;=&quot;accept&quot;; \t\t\t}; \t\t}; \t\t&quot;TUN&quot;={ \t\t\tmss=1400; \t\t}; \t\t&quot;rt&quot;={}; \t}; \t&quot;ip&quot;={ \t\t&quot;rt&quot;={ \t\t\tpolicy={ \t\t\t\t&quot;all&quot;=&quot;accept&quot;  \t\t\t}; \t\t}; \t\t&quot;TUN&quot;={ \t\t\t&quot;Staff&quot;={ \t\t\t\t&quot;Server&quot;=&quot;accept&quot;; \t\t\t}; \t\t\t&quot;Manager&quot;={ \t\t\t\t&quot;all&quot;=&quot;accept&quot;; \t\t\t}; \t\t}; \t\t&quot;ISP&quot;={ \t\t\t&quot;Trusted&quot;={ \t\t\t\t&quot;rt&quot;=&quot;accept&quot;; \t\t\t}; \t\t}; \t}; } <\/code><\/pre>\n<p>  <\/div>\n<\/p><\/div>\n<p>  \u0417\u0430\u0434\u0430\u043d\u043e 4-\u0435 \u0437\u043e\u043d\u044b \u0434\u043b\u044f \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432, \u043e\u0434\u043d\u0430 \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445, \u043e\u0431\u044f\u0437\u0430\u0442\u0435\u043b\u044c\u043d\u0430\u044f rt:  <\/p>\n<ul>\n<li>ISP \u2014 \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u0430, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0443\u043a\u0430\u0437\u0430\u043d\u043e \u0441\u043e\u0437\u0434\u0430\u0432\u0430\u0442\u044c \u0434\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0434\u043b\u044f \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432.<\/li>\n<li>LAN \u2014 \u0434\u043b\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0435\u0442\u0438, \u0435\u0439 \u0437\u0430\u0434\u0430\u043d\u044b \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0434\u043b\u044f lan \u0438 \u0435\u0441\u0442\u044c \u043e\u0431\u0449\u0435\u0435 \u0440\u0430\u0437\u0440\u0435\u0448\u0430\u044e\u0449\u0438\u0435 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0435 \u043d\u0430 \u043b\u044e\u0431\u044b\u0435 \u043d\u0430\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f.<\/li>\n<li>TUN \u2014 \u0434\u043b\u044f \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u043e \u0442\u0443\u043d\u0435\u043b\u0435\u0439, \u0443\u043a\u0430\u0437\u0430\u043d\u0430 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u043e\u0432\u043a\u0430 MSS.<\/li>\n<\/ul>\n<p>  B 3-\u0438 ip \u0437\u043e\u043d\u044b:  <\/p>\n<ul>\n<li>Staff \u0438 Manager \u043d\u0430 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430\u0445 TUN:<br \/> \n<ul>\n<li>Staff \u2014 \u0438\u043c\u0435\u0435\u0442 \u0434\u043e\u0441\u0442\u0443\u043f \u0442\u043e\u043b\u044c\u043a\u043e \u043a ip \u0437\u043e\u043d\u0435 Server<\/li>\n<li>Manager \u2014 \u043c\u043e\u0433\u0443\u0442 \u043a\u0443\u0434\u0430 \u0443\u0433\u043e\u0434\u043d\u043e<\/li>\n<\/ul>\n<p>  <\/li>\n<li>Trusted \u043d\u0430 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 ISP \u0438\u043c\u0435\u0435\u0442 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0440\u043e\u0443\u0442\u0435\u0440\u0443<\/li>\n<\/ul>\n<p>  <\/p>\n<div class=\"spoiler\" role=\"button\" tabindex=\"0\">                         <b class=\"spoiler_title\">gen-filter<\/b>                         <\/p>\n<div class=\"spoiler_text\">\n<pre><code class=\"bash\"># may\/01\/2020 10:00:00 by RouterOS 6.46.6 # RoS filter generator v 0.9.1  :local gping 0 :local debug 1 :local zones { \t&quot;if&quot;={ \t\t&quot;ISP&quot;={ \t\t\t&quot;is_wan&quot;=1; \t\t}; \t\t&quot;LAN&quot;={ \t\t\t&quot;is_lan&quot;=1; \t\t\tpolicy={  \t\t\t\t&quot;all&quot;=&quot;accept&quot;; \t\t\t}; \t\t}; \t\t&quot;TUN&quot;={ \t\t\tmss=1400; \t\t}; \t\t&quot;rt&quot;={}; \t}; \t&quot;ip&quot;={ \t\t&quot;rt&quot;={ \t\t\tpolicy={ \t\t\t\t&quot;all&quot;=&quot;accept&quot;  \t\t\t}; \t\t}; \t\t&quot;TUN&quot;={ \t\t\t&quot;Staff&quot;={ \t\t\t\t&quot;Server&quot;=&quot;accept&quot;; \t\t\t}; \t\t\t&quot;Manager&quot;={ \t\t\t\t&quot;all&quot;=&quot;accept&quot;; \t\t\t}; \t\t}; \t\t&quot;ISP&quot;={ \t\t\t&quot;Trusted&quot;={ \t\t\t\t&quot;rt&quot;=&quot;accept&quot;; \t\t\t}; \t\t}; \t}; } \/ip firewall raw add action=notrack chain=prerouting ipsec-policy=in,ipsec comment=&quot;Notrack ipsec&quot; add action=notrack chain=prerouting dst-address-type=multicast comment=&quot;Notrack multicast&quot; \/ip firewall filter :if ( ($debug)=0 ) do={ \tadd action=accept chain=forward comment=DEBUG!!! disabled=yes \tadd action=accept chain=input comment=DEBUG!!! disabled=yes \tadd action=accept chain=output comment=DEBUG!!! disabled=yes } else={ \tadd action=accept chain=forward comment=DEBUG!!! \tadd action=accept chain=input comment=DEBUG!!! \tadd action=accept chain=output comment=DEBUG!!! } add action=accept chain=input comment=&quot;defconf: accept to local loopback (for CAPsMAN)&quot; dst-address=127.0.0.1 dst-port=5246,5247 protocol=udp src-address-type=local add action=accept chain=input comment=&quot;defconf: accept established,related,untracked&quot; connection-state=established,related,untracked add action=drop chain=input comment=&quot;defconf: drop invalid&quot; connection-state=invalid add action=jump chain=input comment=&quot;defconf: new input&quot; jump-target=in-new add action=drop chain=input comment=&quot;defconf: drop all not allowed&quot; add action=accept chain=output comment=&quot;defconf: accept established,related,untracked&quot; connection-state=established,related,untracked add action=jump chain=output comment=&quot;defconf: new output&quot; jump-target=out-new add action=drop chain=output comment=&quot;defconf: drop all not allowed&quot; add action=accept chain=forward comment=&quot;defconf: accept in ipsec policy&quot; ipsec-policy=in,ipsec add action=accept chain=forward comment=&quot;defconf: accept out ipsec policy&quot; ipsec-policy=out,ipsec add action=fasttrack-connection chain=forward comment=&quot;defconf: fasttrack&quot; connection-mark=no-mark connection-state=established,related add action=accept chain=forward comment=&quot;defconf: accept established,related, untracked&quot; connection-state=established,related,untracked add action=drop chain=forward comment=&quot;defconf: drop invalid&quot; connection-state=invalid add action=jump chain=forward comment=&quot;defconf: new forward&quot; jump-target=fw-new add action=accept chain=new-FORWARD comment=&quot;defconf: Accept all forward DSTNATed&quot; connection-nat-state=dstnat add action=drop chain=forward comment=&quot;defconf: drop all not allowed for forward&quot; :if ( ($gping)=1 ) do={ \tadd action=accept chain=WAN2RT-STD-PROTO comment=ICMP protocol=icmp disabled=yes } else={ \tadd action=accept chain=WAN2RT-STD-PROTO comment=ICMP protocol=icmp } add action=accept chain=WAN2RT-STD-PROTO comment=GRE ipsec-policy=in,ipsec protocol=gre add action=accept chain=WAN2RT-STD-PROTO comment=IPSec protocol=ipsec-esp add action=accept chain=WAN2RT-STD-PROTO comment=IPSec protocol=ipsec-ah add action=accept chain=WAN2RT-STD-PROTO comment=&quot;IPSec encapsulated&quot; dst-port=500,4500 protocol=udp add action=accept chain=WAN2RT-STD-PROTO comment=L2TP dst-port=1701 ipsec-policy=in,ipsec protocol=udp add action=accept chain=WAN2RT-STD-PROTO comment=PPtP dst-port=1723 protocol=tcp add action=accept chain=LAN2RT-STD-PROTO comment=DNS dst-port=53 protocol=tcp add action=accept chain=LAN2RT-STD-PROTO comment=NTP,DNS,DHCP dst-port=53,123,67-68 protocol=udp add action=accept chain=LAN2RT-STD-PROTO comment=DHCP dst-address-type=broadcast dst-port=67-68 protocol=udp add action=accept chain=RT2WAN-STD-PROTO comment=DNS dst-port=53 protocol=tcp add action=accept chain=RT2WAN-STD-PROTO comment=NTP,DNS dst-port=53,123 protocol=udp add action=reject chain=RT2WAN-STD-PROTO comment=GRE ipsec-policy=out,none protocol=gre reject-with=icmp-admin-prohibited add action=reject chain=RT2WAN-STD-PROTO comment=L2TP dst-port=1701 ipsec-policy=out,none protocol=udp reject-with=icmp-admin-prohibited :if ( ($gping)=1 ) do={ \tadd action=accept chain=fw-new comment=ICMP protocol=icmp \tadd action=accept chain=in-new comment=ICMP protocol=icmp \tadd action=accept chain=out-new comment=ICMP protocol=icmp } else={ \tadd action=accept chain=fw-new comment=ICMP protocol=icmp disabled=yes \tadd action=accept chain=in-new comment=ICMP protocol=icmp disabled=yes \tadd action=accept chain=out-new comment=ICMP protocol=icmp disabled=yes } \/ip firewall filter :foreach zone,conf in=($zones-&gt;&quot;if&quot;) do={ \t:if ( ($zone)!=&quot;rt&quot; ) do={ \t\t:if ( [\/interface list print count-only where name=(&quot;IF-&quot;.$zone)] = 0) do={ \t\t\t\/interface list add name=(&quot;IF-&quot;.$zone) \t\t} \t\tadd action=jump chain=fw-new in-interface-list=(&quot;IF-&quot;.$zone) comment=(&quot;Fwd plc from if &quot;.$zone) jump-target=(&quot;fw-plc-s:&quot;.$zone) \t\tadd action=jump chain=in-new in-interface-list=(&quot;IF-&quot;.$zone) comment=(&quot;In plc for if &quot;.$zone) jump-target=(&quot;in-plc-s:&quot;.$zone) \t} else={ \t\tadd action=jump chain=out-new comment=(&quot;Out plc for rt&quot;) jump-target=&quot;out-plc-s:rt&quot; \t}\t } :foreach zone,conf in=($zones-&gt;&quot;if&quot;) do={ \t:if ( ($zone)!=&quot;rt&quot; &amp;&amp; ($zone)!=&quot;all&quot;) do={ \t\t:if ( ($conf-&gt;&quot;is_lan&quot;)=1 || ($conf-&gt;&quot;is_wan&quot;)=1 ) do={ \t\t\tadd action=jump chain=(&quot;in-plc-s:&quot;.$zone) comment=(&quot;In plc for if &quot;.$zone.&quot; to rt&quot;) jump-target=(&quot;in-plc-s:&quot;.$zone.&quot;&gt;rt&quot;) \t\t} \t\t:if ( ($conf-&gt;&quot;is_wan&quot;)=1) do={ \t\t\tadd action=jump chain=(&quot;in-plc-s:&quot;.$zone.&quot;&gt;rt&quot;) comment=(&quot;In Allow plc for STD WAN PROTO from&quot;.$zone) in-interface-list=(&quot;IF-&quot;.$zone) jump-target=WAN2RT-STD-PROTO \t\t\tadd action=jump chain=&quot;out-plc-s:rt&quot; out-interface-list=(&quot;IF-&quot;.$zone) comment=(&quot;Out Allow plc for STD WAN PROTO to &quot;.$zone) jump-target=RT2WAN-STD-PROTO \t\t}\t \t\t:if ( ($conf-&gt;&quot;is_lan&quot;)=1) do={ \t\t\tadd action=jump chain=(&quot;in-plc-s:&quot;.$zone.&quot;&gt;rt&quot;) in-interface-list=(&quot;IF-&quot;.$zone) comment=(&quot;In Allow plc for STD LAN PROTO from&quot;.$zone) jump-target=LAN2RT-STD-PROTO \t\t}\t \t\t:if ( [:len ($conf-&gt;&quot;mss&quot;)]!=0 ) do={ \t\t\t\/ip firewall mangle add action=change-mss chain=forward in-interface-list=(&quot;IF-&quot;.$zone) new-mss=($conf-&gt;&quot;mss&quot;) passthrough=yes protocol=tcp tcp-flags=syn tcp-mss=(($conf-&gt;&quot;mss&quot;+1).&quot;-65535&quot;) comment=(&quot;Fix mss on tunel &quot;.$zone) \t\t\t\/ip firewall mangle add action=change-mss chain=forward out-interface-list=(&quot;IF-&quot;.$zone) new-mss=($conf-&gt;&quot;mss&quot;) passthrough=yes protocol=tcp tcp-flags=syn tcp-mss=(($conf-&gt;&quot;mss&quot;+1).&quot;-65535&quot;) comment=(&quot;Fix mss on tunel &quot;.$zone) \t\t} \t\t:foreach src,val in=(($zones-&gt;&quot;ip&quot;)-&gt;$&quot;zone&quot;) do={ \t\t\t:foreach tgt,policy in=$val do={ \t\t\t\t:if ( ($tgt)!=&quot;rt&quot; &amp;&amp; ($tgt)!=&quot;all&quot;) do={ \t\t\t\t\t:if ( [:len (($zones-&gt;&quot;if&quot;)-&gt;$&quot;tgt&quot;)]=0 ) do={ \t\t\t\t\t\tadd action=jump chain=(&quot;fw-plc-s:&quot;.$zone) src-address-list=(&quot;IP-&quot;.$src) dst-address-list=(&quot;IP-&quot;.$tgt) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; &amp; ip &quot;.$src.&quot; to &quot;.$tgt) jump-target=(&quot;fw-plc-s:&quot;.$zone.&quot;&amp;&quot;.$src.&quot;&gt;&quot;.$tgt) \t\t\t\t\t} else={ \t\t\t\t\t\tadd action=jump chain=(&quot;fw-plc-s:&quot;.$zone) src-address-list=(&quot;IP-&quot;.$src) out-interface-list=(&quot;IF-&quot;.$tgt) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; &amp; ip &quot;.$src.&quot; to &quot;.$tgt) jump-target=(&quot;fw-plc-s:&quot;.$zone.&quot;&amp;&quot;.$src.&quot;&gt;&quot;.$tgt) \t\t\t\t\t} \t\t\t\t\t:if ( ($policy)=&quot;accept&quot;) do={ \t\t\t\t\t\tadd action=accept chain=(&quot;fw-plc-s:&quot;.$zone.&quot;&amp;&quot;.$src.&quot;&gt;&quot;.$tgt) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; &amp; ip &quot;.$src.&quot; Accept to &quot;.$tgt) \t\t\t\t\t} \t\t\t\t\t:if ( ($policy)=&quot;reject&quot;) do={ \t\t\t\t\t\tadd action=reject chain=(&quot;fw-plc-s:&quot;.$zone.&quot;&amp;&quot;.$src.&quot;&gt;&quot;.$tgt) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; &amp; ip &quot;.$src.&quot; Reject to &quot;.$tgt) \t\t\t\t\t} \t\t\t\t} \t\t\t\t:if ( ($tgt)=&quot;rt&quot; ) do={ \t\t\t\t\tadd action=jump chain=(&quot;in-plc-s:&quot;.$zone) src-address-list=(&quot;IP-&quot;.$src) comment=(&quot;In plc for if &quot;.$zone.&quot; &amp; ip &quot;.$src.&quot; to rt&quot;) jump-target=(&quot;in-plc-s:&quot;.$zone.&quot;&amp;&quot;.$src.&quot;&gt;rt&quot;) \t\t\t\t\t:if ( ($policy)=&quot;accept&quot;) do={ \t\t\t\t\t\tadd action=accept chain=(&quot;in-plc-s:&quot;.$zone.&quot;&amp;&quot;.$src.&quot;&gt;rt&quot;) comment=(&quot;In plc for if &quot;.$zone.&quot; &amp; ip &quot;.$src.&quot; Accept to rt&quot;) \t\t\t\t\t} \t\t\t\t\t:if ( ($policy)=&quot;reject&quot;) do={ \t\t\t\t\t\tadd action=reject chain=(&quot;in-plc-s:&quot;.$zone.&quot;&amp;&quot;.$src.&quot;&gt;rt&quot;) comment=(&quot;In plc for if &quot;.$zone.&quot; &amp; ip &quot;.$src.&quot; Accept to rt&quot;) \t\t\t\t\t} \t\t\t\t} \t\t\t\t:if ( ($tgt)=&quot;all&quot; ) do={ \t\t\t\t\tadd action=jump chain=(&quot;fw-plc-s:&quot;.$zone) src-address-list=(&quot;IP-&quot;.$src) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; &amp; ip &quot;.$src.&quot; to All&quot;) jump-target=(&quot;fw-plc-s:&quot;.$zone.&quot;&amp;&quot;.$src.&quot;&gt;all&quot;) \t\t\t\t\tadd action=jump chain=(&quot;in-plc-s:&quot;.$zone) src-address-list=(&quot;IP-&quot;.$src) comment=(&quot;In plc for if &quot;.$zone.&quot; &amp; ip &quot;.$src.&quot; to All&quot;) jump-target=(&quot;in-plc-s:&quot;.$zone.&quot;&amp;&quot;.$src.&quot;&gt;all&quot;) \t\t\t\t\t:if ( ($policy)=&quot;accept&quot;) do={ \t\t\t\t\t\tadd action=accept chain=(&quot;fw-plc-s:&quot;.$zone.&quot;&amp;&quot;.$src.&quot;&gt;all&quot;) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; &amp; ip &quot;.$src.&quot; Accept to All&quot;) \t\t\t\t\t\tadd action=accept chain=(&quot;in-plc-s:&quot;.$zone.&quot;&amp;&quot;.$src.&quot;&gt;all&quot;) comment=(&quot;In plc from if &quot;.$zone.&quot; &amp; ip &quot;.$src.&quot; Accept to All&quot;) \t\t\t\t\t} \t\t\t\t\t:if ( ($policy)=&quot;reject&quot;) do={ \t\t\t\t\t\tadd action=reject chain=(&quot;fw-plc-s:&quot;.$zone.&quot;&amp;&quot;.$src.&quot;&gt;all&quot;) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; &amp; ip &quot;.$src.&quot; Reject to All&quot;) \t\t\t\t\t\tadd action=reject chain=(&quot;in-plc-s:&quot;.$zone.&quot;&amp;&quot;.$src.&quot;&gt;all&quot;) comment=(&quot;In plc from if &quot;.$zone.&quot; &amp; ip &quot;.$src.&quot; Reject to All&quot;) \t\t\t\t\t} \t\t\t\t} \t\t\t} \t\t} \t\t:foreach tgt,policy in=($conf-&gt;&quot;policy&quot;) do={ \t\t\t:if ( ($tgt)!=&quot;rt&quot; &amp;&amp; ($tgt)!=&quot;all&quot;) do={ \t\t\t\t:if ( [:len (($zones-&gt;&quot;if&quot;)-&gt;$&quot;tgt&quot;)]=0 ) do={ \t\t\t\t\tadd action=jump chain=(&quot;fw-plc-s:&quot;.$zone) dst-address-list=(&quot;IP-&quot;.$tgt) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; to &quot;.$tgt) jump-target=(&quot;fw-plc-s:&quot;.$zone.&quot;&gt;&quot;.$tgt) \t\t\t\t} else={ \t\t\t\t\tadd action=jump chain=(&quot;fw-plc-s:&quot;.$zone) out-interface-list=(&quot;IF-&quot;.$tgt) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; to &quot;.$tgt) jump-target=(&quot;fw-plc-s:&quot;.$zone.&quot;&gt;&quot;.$tgt) \t\t\t\t} \t\t\t\t:if ( ($policy)=&quot;accept&quot;) do={ \t\t\t\t\tadd action=accept chain=(&quot;fw-plc-s:&quot;.$zone.&quot;&gt;&quot;.$tgt) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; Accept to &quot;.$tgt) \t\t\t\t} \t\t\t\t:if ( ($policy)=&quot;reject&quot;) do={ \t\t\t\t\tadd action=reject chain=(&quot;fw-plc-s:&quot;.$zone.&quot;&gt;&quot;.$tgt) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; Reject to &quot;.$tgt) \t\t\t\t} \t\t\t} \t\t\t:if ( ($tgt)=&quot;rt&quot; ) do={ \t\t\t\t:if ( ($conf-&gt;&quot;is_lan&quot;)!=1 &amp;&amp; ($conf-&gt;&quot;is_wan&quot;)!=1 ) do={ \t\t\t\t\tadd action=jump chain=(&quot;in-plc-s:&quot;.$zone) comment=(&quot;In plc for if &quot;.$zone.&quot; to rt&quot;) jump-target=(&quot;in-plc-s:&quot;.$zone.&quot;&gt;rt&quot;) \t\t\t\t} \t\t\t\t:if ( ($policy)=&quot;accept&quot;) do={ \t\t\t\t\tadd action=accept chain=(&quot;in-plc-s:&quot;.$zone.&quot;&gt;rt&quot;) comment=(&quot;In plc for if &quot;.$zone.&quot; Accept to rt&quot;) \t\t\t\t} \t\t\t\t:if ( ($policy)=&quot;reject&quot;) do={ \t\t\t\t\tadd action=reject chain=(&quot;in-plc-s:&quot;.$zone.&quot;&gt;rt&quot;) comment=(&quot;In plc for if &quot;.$zone.&quot; Reject to rt&quot;) \t\t\t\t} \t\t\t} \t\t\t:if ( ($tgt)=&quot;all&quot; ) do={ \t\t\t\tadd action=jump chain=(&quot;fw-plc-s:&quot;.$zone) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; to All&quot;) jump-target=(&quot;fw-plc-s:&quot;.$zone.&quot;&gt;all&quot;) \t\t\t\tadd action=jump chain=(&quot;in-plc-s:&quot;.$zone) comment=(&quot;In plc for if &quot;.$zone.&quot; to All&quot;) jump-target=(&quot;in-plc-s:&quot;.$zone.&quot;&gt;all&quot;) \t\t\t\t:if ( ($policy)=&quot;accept&quot;) do={ \t\t\t\t\tadd action=accept chain=(&quot;fw-plc-s:&quot;.$zone.&quot;&gt;all&quot;) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; Accept to All&quot;) \t\t\t\t\tadd action=accept chain=(&quot;in-plc-s:&quot;.$zone.&quot;&gt;all&quot;) comment=(&quot;In plc from if &quot;.$zone.&quot; Accept to All&quot;) \t\t\t\t} \t\t\t\t:if ( ($policy)=&quot;reject&quot;) do={ \t\t\t\t\tadd action=reject chain=(&quot;fw-plc-s:&quot;.$zone.&quot;&gt;all&quot;) comment=(&quot;Fwd plc from if &quot;.$zone.&quot; Reject to All&quot;) \t\t\t\t\tadd action=reject chain=(&quot;in-plc-s:&quot;.$zone.&quot;&gt;all&quot;) comment=(&quot;In plc from if &quot;.$zone.&quot; Reject to All&quot;) \t\t\t\t} \t\t\t} \t\t} \t} } <\/code><\/pre>\n<p>  <\/div>\n<\/p><\/div>\n<h3>\u0417\u0430\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435<\/h3>\n<p>  \u0414\u0430\u043d\u043d\u044b\u0439 \u0441\u043a\u0440\u0438\u043f\u0442 \u043c\u043d\u0435 \u043f\u043e\u043c\u043e\u0433 \u0441\u0438\u043b\u044c\u043d\u043e \u043e\u0431\u043b\u0435\u0433\u0447\u0438\u0442\u044c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 \u0441\u043b\u043e\u0436\u043d\u044b\u0445 \u043f\u043e\u043b\u0438\u0442\u0438\u043a, \u043e\u0434\u043d\u0430\u043a\u043e, \u043e\u0448\u0438\u0431\u043a\u0438 \u0432 \u043d\u0435\u043c \u0432\u0441\u0435-\u0436\u0435 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c. \u041f\u0435\u0440\u0435\u0434 \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u0435\u043c \u043f\u0440\u043e\u043a\u043e\u043d\u0441\u0443\u043b\u044c\u0442\u0438\u0440\u0443\u0439\u0442\u0435\u0441\u044c \u0441\u043e \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442\u043e\u043c. \u0412 \u0441\u043b\u0443\u0447\u0430\u0435 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u044f \u043f\u043e\u0431\u043e\u0447\u043d\u044b\u0445 \u044f\u0432\u043b\u0435\u043d\u0438\u0439, \u043f\u0438\u0448\u0438\u0442\u0435, \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u044f\u0442\u044c.<\/div>\n<p> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/post\/500148\/\"> https:\/\/habr.com\/ru\/post\/500148\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"\n<div class=\"post__text post__text-html post__text_v1\" id=\"post-content-body\" data-io-article-url=\"https:\/\/habr.com\/ru\/post\/500148\/\">\u041a\u0442\u043e \u0445\u043e\u0442\u044c \u0440\u0430\u0437 \u043f\u0438\u0441\u0430\u043b \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0443 \u0444\u0438\u043b\u044c\u0440\u0430\u0446\u0438\u0438 firewall \u0437\u043d\u0430\u0435\u0442, \u0447\u0442\u043e \u044d\u0442\u043e \u0434\u0435\u043b\u043e \u043d\u0435 \u043f\u0440\u043e\u0441\u0442\u043e\u0435 \u0438 \u0441\u043e\u043f\u0440\u044f\u0436\u0435\u043d\u043e \u0441 \u043a\u0443\u0447\u0435\u0439 \u043e\u0448\u0438\u0431\u043e\u043a, \u043a\u043e\u0433\u0434\u0430 \u043a\u043e\u043b\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0437\u043e\u043d \u0431\u043e\u043b\u044c\u0448\u0435 2-\u0445. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0443\u0442\u0430\u0446\u0438\u0438 \u0432\u0430\u043c \u043f\u043e\u043c\u043e\u0436\u0435\u0442 \u0441\u043a\u0440\u0438\u043f\u0442 \u0438\u0437 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0438.  <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-303140","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/303140","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=303140"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/303140\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=303140"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=303140"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=303140"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}