Visualizza received routes
ip route print where received-from=<peer_name>
ipv6 route print where received-from=<peer_name>
ip route print where received-from=PEER_GGAMAUR_V4_1
V7
/ip/route/print where gateway="185.54.80.1"
Visualizza GW per una route
ip route print where dst-address in <ip/sb>
ipv6 route print where dst-address in <ip/sb>
ip route print where dst-address in 130.59.138.0/24
Visualizza le routes inviate
routing bgp advertisements print <Nome del peer>
routing bgp advertisements print ROUTE-SERVER_V6-SWISS_IX.RS1
routing bgp advertisements print PEER_GGAMAUR_V4_1
V7
/routing/bgp/advertisements print where peer=PEER_MICROSOFT_V4-1 (ricordarsi di leggere il nome della sessione e non della connessione)
Visualizza una rotta a un IP
/ip route print where 159.148.147.204 in dst-address
Impostare in blocco l'affinity su tutti i peer ebgp
/routing/bgp/connection> set [find local.role=ebgp] input.affinity=main output.affinity=main
Filtro firewall port scanning
/ip firewall filter
add action=reject chain=input protocol=tcp reject-with=tcp-reset
src-address-list="port scanners"
add action=add-src-to-address-list address-list="port scanners"
address-list-timeout=2w chain=input
protocol=tcp psd=21,3s,3,1
add action=add-src-to-address-list address-list="port scanners"
address-list-timeout=2w chain=input
protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg
add action=add-src-to-address-list address-list="port scanners"
address-list-timeout=2w chain=input protocol=tcp
tcp-flags=fin,syn
add action=add-src-to-address-list address-list="port scanners"
address-list-timeout=2w chain=input protocol=tcp
tcp-flags=syn,rst
add action=add-src-to-address-list address-list="port scanners"
address-list-timeout=2w chain=input protocol=
tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack
add action=add-src-to-address-list address-list="port scanners"
address-list-timeout=2w chain=input protocol=tcp
tcp-flags=fin,syn,rst,psh,ack,urg
add action=add-src-to-address-list address-list="port scanners"
address-list-timeout=2w chain=input protocol=tcp
tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg
[admin@MINAP] > /routing bgp advertisements print where
0 peer=PEER_HE_V6-1 dst=2a02:4460::/32 afi=ipv6 nexthop=2001:7f8:c5::a520:2032:1 origin=0 as-path=sequence 202032 8224 communities=64555:10000
[admin@MINAP] > /routing bgp advertisements print where
0 peer=PEER_HE_V4-1 dst=185.54.80.0/22 afi=ip nexthop=185.1.114.53 origin=0 as-path=sequence 202032 13097 communities=64555:10000